build(deps): bump github/gh-aw-actions/setup-cli from 0.89.17 to 0.89.21 - #1532
shanselman merged 3 commits into
Conversation
Bumps [github/gh-aw-actions/setup-cli](https://github.com/github/gh-aw-actions) from 0.89.17 to 0.89.21. - [Release notes](https://github.com/github/gh-aw-actions/releases) - [Changelog](https://github.com/github/gh-aw-actions/blob/main/CHANGELOG.md) - [Commits](github/gh-aw-actions@f3b81cd...924af5f) --- updated-dependencies: - dependency-name: github/gh-aw-actions/setup-cli dependency-version: 0.89.21 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed September 28, 2026, 9:04 PM ET / September 29, 2026, 01:04 UTC (Revision 6). ClawSweeper reviewWhat this changesUpdates the pinned GitHub Action that installs the gh-aw CLI for Copilot setup from v0.89.17 to v0.89.21. Merge readiness✅ Ready for maintainer review This PR remains useful: current main still uses the older action pin. The changed Copilot setup step passed with the proposed pin, and no introduced defect is evident. Priority: P3 Review scores
Verification
How this fits togetherThe Copilot setup workflow prepares an agent environment by checking out this repository and installing a specified gh-aw CLI version. The action pin selects the installer code used during that setup. flowchart LR
A[Copilot setup run] --> B[Repository checkout]
B --> C[Pinned setup action]
C --> D[Install specified gh-aw CLI]
D --> E[Prepared agent environment]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep the immutable upstream action pin and the explicit CLI version, then land the update when the repository's normal merge gate passes. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR updates a dependency pin rather than reporting a bug. The affected setup step passed with the proposed pin. Is this the best way to solve the issue? Yes. Replacing the immutable action pin is the narrowest way to adopt this installer release while keeping the requested CLI version fixed. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 015897024b28. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (5 earlier review cycles)
|
shanselman
left a comment
There was a problem hiding this comment.
Validated exact head 134622e8e659fb940fbde7e85331b03720d045ed against 3331b5e388762412bc039c653adf88d7106fdf67.
- Diff is one immutable action pin:
github/gh-aw-actions/setup-cliv0.89.17 to v0.89.21. - Upstream
v0.89.21is an immutable release whose annotated tag resolves to924af5fdc64061cfbf66fb584c8b07e2ac230c60; that commit has a valid GitHub signature and successful upstream checks. setup-cli/action.ymlis byte-identical across the two pins. The onlysetup-cliimplementation change stages, verifies, and then atomically replaces the downloaded binary.- Exact-head
copilot-setup-stepspassed: https://github.com/openclaw/openclaw-windows-node/actions/runs/36385243642/job/108809138598 - Isolated autoreview (
python .agents\skills\autoreview\scripts\autoreview --mode branch --base origin/main --stream-engine-output) returned clean with 0.99 confidence and no actionable findings.
CI remains blocked by unrelated recovery E2E infrastructure/setup failures. Current main has the same Network recovery failure at the unchanged base SHA. A failed-jobs-only rerun again failed in the shared SetupEngine fixture before the network tests executed, while Revocation recovery was cancelled at its 30-minute timeout. No workflow edit was made or pushed.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 98e80fd0-82bc-48ce-aa8b-3bab39e58fa5
|
Post-#1507 closeout: head f5a8f73 is locally green and all setup/recovery/UI/security/release jobs pass. Core failed three attempts on three unrelated flakes: MCP dispose ObjectDisposedException, migration-script 30-second timeouts, then NativeGatewayRuntime disposal ordering. Repository rules do not allow maintainer bypass of failing CI Gate. Pausing active landing until Core infrastructure is stable; no patch-specific defect was found. |
…ns/setup-cli-0.89.21
Bumps github/gh-aw-actions/setup-cli from 0.89.17 to 0.89.21.
Release notes
Sourced from github/gh-aw-actions/setup-cli's releases.
Commits
924af5fchore: sync actions from gh-aw@v0.89.21 (#250)925900cchore: sync actions from gh-aw@v0.89.20 (#249)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)