Skip to content

build(deps): bump github/gh-aw-actions/setup-cli from 0.89.17 to 0.89.21 - #1532

Merged
shanselman merged 3 commits into
mainfrom
dependabot/github_actions/github/gh-aw-actions/setup-cli-0.89.21
Sep 29, 2026
Merged

shanselman merged 3 commits into
mainfrom
dependabot/github_actions/github/gh-aw-actions/setup-cli-0.89.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps github/gh-aw-actions/setup-cli from 0.89.17 to 0.89.21.

Release notes

Sourced from github/gh-aw-actions/setup-cli's releases.

v0.89.21

Sync of actions from gh-aw at v0.89.21.

v0.89.20

Sync of actions from gh-aw at v0.89.20.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions) from 0.89.17 to 0.89.21.
- [Release notes](https://github.com/github/gh-aw-actions/releases)
- [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md)
- [Commits](github/gh-aw-actions@f3b81cd...924af5f)

---
updated-dependencies:
- dependency-name: github/gh-aw-actions/setup-cli
  dependency-version: 0.89.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 28, 2026
@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 28, 2026
@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 28, 2026, 9:04 PM ET / September 29, 2026, 01:04 UTC (Revision 6).

ClawSweeper review

What this changes

Updates the pinned GitHub Action that installs the gh-aw CLI for Copilot setup from v0.89.17 to v0.89.21.

Merge readiness

✅ Ready for maintainer review

This PR remains useful: current main still uses the older action pin. The changed Copilot setup step passed with the proposed pin, and no introduced defect is evident.

Priority: P3
Reviewed head: 70b48785c2ccbda524049af233cf5adabec730e8

Review scores

Measure Result What it means
Overall readiness 🦞 diamond lobster (5/6) The focused pin update has direct setup-job proof, upstream source inspection, and approval of the reviewed head.
Proof confidence 🦞 diamond lobster (5/6) ✨ media proof bonus Sufficient (linked_artifact): The changed owner is the Copilot setup workflow's pinned installer action. Its Ubuntu setup job completed the Install gh-aw extension step with the proposed pin, and that workflow file is identical at the reviewed head. No stored-data contract changes.
Patch quality 🦞 diamond lobster (5/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (linked_artifact): The changed owner is the Copilot setup workflow's pinned installer action. Its Ubuntu setup job completed the Install gh-aw extension step with the proposed pin, and that workflow file is identical at the reviewed head. No stored-data contract changes.
Evidence reviewed 7 items Introduced change: The introduced delta replaces one immutable setup action SHA and its version comment; the requested CLI version remains v0.72.1.
Current main: The current main workflow still pins v0.89.17, so it has not implemented this update.
Dependency contract: The target workflow directly executes this composite action. On its Ubuntu runner, the action selects the Bash installer.
Findings None None.
Security None None.

How this fits together

The Copilot setup workflow prepares an agent environment by checking out this repository and installing a specified gh-aw CLI version. The action pin selects the installer code used during that setup.

flowchart LR
  A[Copilot setup run] --> B[Repository checkout]
  B --> C[Pinned setup action]
  C --> D[Install specified gh-aw CLI]
  D --> E[Prepared agent environment]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Workflow scope 1 workflow, 1 pin replaced The successful setup job exercised the only changed workflow path.

Technical review

Best possible solution:

Keep the immutable upstream action pin and the explicit CLI version, then land the update when the repository's normal merge gate passes.

Do we have a high-confidence way to reproduce the issue?

Not applicable: this PR updates a dependency pin rather than reporting a bug. The affected setup step passed with the proposed pin.

Is this the best way to solve the issue?

Yes. Replacing the immutable action pin is the narrowest way to adopt this installer release while keeping the requested CLI version fixed.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 015897024b28.

Labels

Label changes:

No label changes.

Label justifications:

  • P3: This is a small dependency pin update with direct proof that the affected setup step succeeds.
  • rating: 🦞 diamond lobster: Overall readiness is 🦞 diamond lobster; proof is 🦞 diamond lobster and patch quality is 🦞 diamond lobster.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (linked_artifact): The changed owner is the Copilot setup workflow's pinned installer action. Its Ubuntu setup job completed the Install gh-aw extension step with the proposed pin, and that workflow file is identical at the reviewed head. No stored-data contract changes.
  • proof: sufficient: Contributor real behavior proof is sufficient. The changed owner is the Copilot setup workflow's pinned installer action. Its Ubuntu setup job completed the Install gh-aw extension step with the proposed pin, and that workflow file is identical at the reviewed head. No stored-data contract changes.

Evidence

What I checked:

Likely related people:

  • shanselman: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (5 earlier review cycles)
  • reviewed 2026-09-28T06:14:00.425Z sha 134622e :: needs maintainer review before merge. :: none
  • reviewed 2026-09-28T16:14:02.744Z sha 134622e :: needs maintainer review before merge. :: none
  • reviewed 2026-09-28T16:48:01.743Z sha 134622e :: needs maintainer review before merge. :: none
  • reviewed 2026-09-28T19:29:18.972Z sha f5a8f73 :: needs maintainer review before merge. :: none
  • reviewed 2026-09-28T19:43:56.507Z sha f5a8f73 :: needs maintainer review before merge. :: none

@shanselman shanselman added status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. and removed status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 28, 2026
@clawsweeper clawsweeper Bot added the status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. label Sep 28, 2026
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 28, 2026

@shanselman shanselman left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Validated exact head 134622e8e659fb940fbde7e85331b03720d045ed against 3331b5e388762412bc039c653adf88d7106fdf67.

  • Diff is one immutable action pin: github/gh-aw-actions/setup-cli v0.89.17 to v0.89.21.
  • Upstream v0.89.21 is an immutable release whose annotated tag resolves to 924af5fdc64061cfbf66fb584c8b07e2ac230c60; that commit has a valid GitHub signature and successful upstream checks.
  • setup-cli/action.yml is byte-identical across the two pins. The only setup-cli implementation change stages, verifies, and then atomically replaces the downloaded binary.
  • Exact-head copilot-setup-steps passed: https://github.com/openclaw/openclaw-windows-node/actions/runs/36385243642/job/108809138598
  • Isolated autoreview (python .agents\skills\autoreview\scripts\autoreview --mode branch --base origin/main --stream-engine-output) returned clean with 0.99 confidence and no actionable findings.

CI remains blocked by unrelated recovery E2E infrastructure/setup failures. Current main has the same Network recovery failure at the unchanged base SHA. A failed-jobs-only rerun again failed in the shared SetupEngine fixture before the network tests executed, while Revocation recovery was cancelled at its 30-minute timeout. No workflow edit was made or pushed.

@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. and removed rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. labels Sep 28, 2026
@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 28, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 98e80fd0-82bc-48ce-aa8b-3bab39e58fa5
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 28, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

Post-#1507 closeout: head f5a8f73 is locally green and all setup/recovery/UI/security/release jobs pass. Core failed three attempts on three unrelated flakes: MCP dispose ObjectDisposedException, migration-script 30-second timeouts, then NativeGatewayRuntime disposal ordering. Repository rules do not allow maintainer bypass of failing CI Gate. Pausing active landing until Core infrastructure is stable; no patch-specific defect was found.

@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 29, 2026
@shanselman
shanselman merged commit 0844c0f into main Sep 29, 2026
40 of 42 checks passed
@shanselman
shanselman deleted the dependabot/github_actions/github/gh-aw-actions/setup-cli-0.89.21 branch September 29, 2026 01:23
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. proof: sufficient Contributor real behavior proof is sufficient. rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant