Skip to content

[oblt-aw][agent-suggestions] Agent suggestions - 2026-04-05 #877

Description

@github-actions

Agent Suggestions

Date: 2026-04-05
Expires: 24h

1. gh-aw-adoption-doctor

Trigger: weekly schedule + workflow_dispatch (optionally slash command /aw audit-workflows for targeted checks)

Purpose: Detect and remediate downstream workflow integration drift for elastic/ai-github-actions/.github/workflows/gh-aw-*.lock.yml usage (permissions, required secrets, and trigger wiring), then open one concise remediation report with concrete patch guidance (or PR draft) per repository.

Proposed safe outputs: create-issue (summary + actionable checklist), create-pull-request (optional mechanical fixes), add-comment (manual run result/noop).

Current pain points and evidence:

Why not covered already:

  • Existing oblt-aw.yml only forwards local events for this repository; it does not inventory/validate downstream consumer repos for configuration drift.
  • Open local tracking items (#856, #528, #533) do not provide a recurring downstream adoption audit/remediation loop.

Expected benefits:

  • Reduces recurring manual AW migration/fix PRs across downstream repos.
  • Improves first-pass workflow correctness (permissions/secrets/trigger compatibility).
  • Shortens time from AW changes to safe downstream rollout and reduces broken-workflow noise.

Trade-offs and rollout considerations:

  • Requires a curated allowlist of downstream repos and minimal false-positive tuning.
  • Should start as report-only (issue/comment) for 1-2 weeks before enabling optional PR generation.
  • Needs clear guardrails for edit scope (workflow files only) and duplicate suppression per repo.

Duplicate Checks

Downstream Signals

Suggested Next Steps

  • Pilot gh-aw-adoption-doctor in report-only mode on 3 known downstream repos.
  • Define required checks (permissions, required secrets, trigger compatibility, workflow filename/version drift).
  • Measure false positives and remediation acceptance before enabling optional auto-PR mode.

Note

🔒 Integrity filter blocked 110 items

The following items were blocked because they don't meet the GitHub integrity level.

  • #526 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #464 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #512 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #471 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #262 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #527 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #230 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #144 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #229 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #155 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #704 search_issues: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #1 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #49648 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #3 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #49589 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • #17935 search_pull_requests: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
  • ... and 94 more items

To allow these resources, lower min-integrity in your GitHub frontmatter:

tools:
  github:
    min-integrity: approved  # merged | approved | unapproved | none

What is this? | From workflow: Observability Agentic Workflow Entrypoint

Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

  • expires on Apr 12, 2026, 6:36 AM UTC

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions