Bump gh-aw-firewall to v0.28.1 - #52607
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Bumps the default AWF release from v0.27.44 to v0.28.1 and regenerates dependent pins and workflows.
Changes:
- Updates
DefaultFirewallVersion. - Adds v0.28.1 container digests to pin caches.
- Regenerates workflow locks and adds a patch changeset.
Show a summary per file
| File | Description |
|---|---|
pkg/constants/version_constants.go |
Updates the default AWF version. |
pkg/actionpins/data/action_pins.json |
Adds v0.28.1 image pins. |
pkg/workflow/data/action_pins.json |
Adds embedded v0.28.1 pins. |
.github/aw/actions-lock.json |
Adds compiler action pins. |
.github/workflows/smoke-crush.lock.yml |
Regenerates Crush smoke workflow. |
.github/workflows/smoke-ci.lock.yml |
Regenerates CI smoke workflow. |
.github/workflows/notion-issue-summary.lock.yml |
Regenerates Notion workflow. |
.github/workflows/hippo-embed.lock.yml |
Regenerates Hippo workflow. |
.github/workflows/firewall.lock.yml |
Regenerates firewall test workflow. |
.github/workflows/example-permissions-warning.lock.yml |
Regenerates permissions example. |
.github/workflows/daily-arxiv-researcher.lock.yml |
Regenerates research workflow. |
.github/workflows/codex-github-remote-mcp-test.lock.yml |
Regenerates Codex MCP test. |
.changeset/patch-bump-awf-v0-28-1.md |
Records the patch release change. |
Review details
- Files reviewed: 21/290 changed files
- Comments generated: 1
- Review effort level: Balanced
| @@ -64,7 +64,7 @@ const DefaultGitHubMCPServerVersion Version = "v1.9.0" | |||
| // | |||
| // The first recompile regenerates all lock files using the new version; the second recompile | |||
| // refreshes the container SHA pins that were resolved during the first pass. | |||
| const DefaultFirewallVersion Version = "v0.27.44" | |||
| const DefaultFirewallVersion Version = "v0.28.1" | |||
|
@copilot Please resolve the blocking review feedback on this PR, refresh the branch if needed, and run the Outstanding review items (newest first):
Failed checks from the compact candidate set:
Branch update was requested automatically for this run.
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed the blocking review feedback in commit |
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
|
@copilot Please resolve the blocking review feedback on this PR, refresh the branch if needed, and run the Outstanding review items (newest first):
Branch update was requested automatically for this run.
|
Blocking review feedback was addressed in |
|
@copilot resolve conflicts, merge main, and recompile workflows |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Done in |
Summary
DefaultFirewallVersionfromv0.27.44tov0.28.1v0.28.1AWF container digests from the release manifest to the embedded pin cachesUpstream review
v0.28.1completes the Cloud Hypervisor preview runtime by addingvirtiofsdsupport and otherwise contains refactoring and CI changes. The release addscloudHypervisor.sha256.virtiofsdto the AWF config schema and CLI mapping; gh-aw already emits the corresponding--cloud-hypervisor-virtiofsd-sha256argument. ExistingAWF*MinVersiongates remain correct, includingAWFCloudHypervisorMinVersion = v0.28.0, so no new gate is required.The broader
v0.27.44→v0.28.xconfig transition to unifiedenclavesand the Cloud Hypervisor runtime was also reviewed. Both integrations are already present on main.Validation
make buildmake recompilemake recompilemake agent-report-progressRun: https://github.com/github/gh-aw/actions/runs/31767348894> Generated by 👨🍳 PR Sous Chef · gpt54 · 23.3 AIC · ⌖ 5.78 AIC · ⊞ 8.5K · ◷