chore: sync actions from gh-aw@v0.90.1 - #254
Conversation
There was a problem hiding this comment.
Note
Copilot could not run the full agentic suite for this review because it was automatically requested on a bot-authored pull request. Request a review from Copilot under Reviewers to retry with the full agentic suite. Improved support for bot-authored pull requests is coming soon.
Copilot review overview
Review effort: Lite
Findings: 2
Open (7)
main()referencesgithub,context, andcore(also used in therequire.main === module… · New This filter only blocks (1) coverage files and (2) shard files that collide with existing trusted… · New Config key mismatch: the type definition added\"required-labels\"?: string[](kebab-case), but… · New Config key mismatch: the type definition added\"required-labels\"?: string[](kebab-case), but… · Newledger.reconstruct()is called once per append, which turns persistence into O(N * reconstruct)… · Newfinalize()can throw (e.g., FS errors writing the transactions artifact). As written, an… · New The destination directory is/tmp/gh-aw/usage/experiment(singular) while the source directory is… · New
What changed in this PR
Adds a Git-backed “ledger” facility to the workflow toolchain (append + audit + persistence + projection/replay), expands usage artifact capture for experiments/evals, and includes a few related improvements (model catalog lookup, required-label gating, misc outputs).
Changes:
- Introduce ledger storage primitives (shards/coverage), MCP server tools, transaction normalization, and persistence/projection scripts.
- Extend repo-memory push flow (retry auth changes, ledger compaction summary, artifact filtering) and usage artifact collection (experiments/evals evidence).
- Improve tool schema generation, safe-output handler wiring, and some compatibility/version bumps.
| File | Description |
|---|---|
| setup/sh/install_copilot_cli.sh | Bumps default Copilot CLI version. |
| setup/sh/collect_usage_artifact_files.sh | Copies additional evals + experiment state files into usage artifacts. |
| setup/setup.sh | Allows new ledger-related CJS files for safe-outputs packaging. |
| setup/js/upload_assets.cjs | Simplifies and improves job summary output for staged vs pushed assets. |
| setup/js/types/safe-outputs-config.d.ts | Adds required-labels option for assign-to-agent config typing. |
| setup/js/safe_outputs_tools.json | Adds ledger_append tool metadata/schema. |
| setup/js/safe_output_handler_manager.cjs | Registers ledger handlers and triggers finalize step for ledger_append batching. |
| setup/js/push_repo_memory.cjs | Adds ledger artifact filtering, compaction support, and richer summary; adjusts git auth strategy and return value. |
| setup/js/push_ledger_changes.cjs | New: validates and persists ledger transactions into per-ledger branches. |
| setup/js/merge_ledger_transactions.cjs | New: merges redacted ledger mutation audit entries into safe-output JSONL. |
| setup/js/mcp_scripts_validation.cjs | Hardens schema validation against prototype/inherited keys. |
| setup/js/ledger_transactions.cjs | New: normalize/validate ledger append requests, temp IDs, deterministic IDs. |
| setup/js/ledger_store.cjs | New: ledger storage format, hashing/canonical JSON, compaction, query/projection. |
| setup/js/ledger_replay_worker.cjs | New: sandboxed replay worker for derived-table generation. |
| setup/js/ledger_replay.cjs | New: runs replay worker and materializes validated output into SQLite. |
| setup/js/ledger_mutation.cjs | New: log-only safe-output handler for redacted ledger mutation audit entries. |
| setup/js/ledger_mcp_server.cjs | New: MCP server exposing ledger append/query/get/status with redacted errors. |
| setup/js/ledger_append.cjs | New: safe-output handler for batching/validating appends into a validated artifact. |
| setup/js/generate_usage_activity_summary.cjs | Adds ledger+threat-detection usage outputs and ledger compaction parsing. |
| setup/js/generate_safe_outputs_tools.cjs | Supports per-tool item schema injection (notably add_labels). |
| setup/js/generate_aw_info.cjs | Emits aw_context as an output for downstream expression usage. |
| setup/js/create_prompt.cjs | Adds ability to splice in a ledger replay prompt file into generated prompts. |
| setup/js/create_ledger_projection.cjs | New: fetches ledger branches, validates records, creates SQLite projections and replay guidance. |
| setup/js/copilot_harness.cjs | Uses shared model-catalog lookup and defaults GPT models to responses wire API. |
| setup/js/constants.cjs | Adds constant for ledger transaction log path. |
| setup/js/awf_reflect.cjs | Enhances catalog lookup (query stripping, -utility fallback precedence). |
| setup/js/assign_to_agent.cjs | Adds required-label enforcement via shared filter helper. |
| .github/aw/compat.json | Updates max-agent compatibility to 1.0.89. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| async function main(options = {}) { | ||
| const artifact = options.artifact || readTransactions(options.file); | ||
| const ledgerConfigs = options.ledgerConfigs || readLedgerConfig(options.config); | ||
| validateTransactions(artifact, ledgerConfigs); | ||
| const result = { version: 1, ledgers: {} }; | ||
| for (const config of ledgerConfigs) { | ||
| const appends = artifact.ledgers[config.name]?.appends || []; | ||
| const persisted = appends.length | ||
| ? await (options.persistLedger || persistLedgerAppends)({ | ||
| appends, | ||
| config, | ||
| githubClient: options.githubClient || github, | ||
| owner: options.owner || context.repo.owner, | ||
| repo: options.repo || context.repo.repo, | ||
| token: options.token || process.env.GH_TOKEN, | ||
| serverHost: options.serverHost || new URL(process.env.GITHUB_SERVER_URL || "https://github.com").host, | ||
| workspaceDir: options.workspaceDir || process.env.GITHUB_WORKSPACE || process.cwd(), |
| function isUntrustedLedgerArtifact(relativePath, trustedSegments) { | ||
| const normalizedPath = relativePath.replace(/\\/g, "/"); | ||
| if (normalizedPath.startsWith("ledger/coverage/")) return true; | ||
| const match = /^ledger\/shards\/([0-9a-f-]{36})\.jsonl$/.exec(normalizedPath); | ||
| return Boolean(match && trustedSegments.has(match[1])); | ||
| } |
| .map(a => a.trim()) | ||
| .filter(Boolean) | ||
| : null; | ||
| const requiredLabels = Array.isArray(config.required_labels) ? config.required_labels : []; |
| return { success: true }; | ||
| } | ||
|
|
||
| const filterResult = await checkRequiredFilter(githubClient, { owner: effectiveOwner, repo: effectiveRepo }, number, requiredLabels, "", "assign_to_agent"); |
| let persisted = 0; | ||
| let alreadyPresent = 0; | ||
| for (const append of appends) { | ||
| const exists = ledger.reconstruct().records.some(record => record.payload?.id === append.record.id); | ||
| if (exists) { | ||
| alreadyPresent++; | ||
| continue; | ||
| } | ||
| ledger.append("ledger_append", append.record); |
| const processingResult = await processMessages(messageHandlers, allMessages, logCreatedItem); | ||
| const ledgerAppendHandler = messageHandlers.get("ledger_append"); | ||
| if (ledgerAppendHandler && "finalize" in ledgerAppendHandler && typeof ledgerAppendHandler.finalize === "function") { | ||
| ledgerAppendHandler.finalize(); |
| cp /tmp/gh-aw/evals/evals_token_usage.jsonl /tmp/gh-aw/usage/evals/token_usage.jsonl | ||
| fi | ||
| for file in state.jsonl state.json assignments.json; do | ||
| if [ -f "/tmp/gh-aw/experiments/$file" ]; then mkdir -p /tmp/gh-aw/usage/experiment && cp "/tmp/gh-aw/experiments/$file" "/tmp/gh-aw/usage/experiment/$file" || true; fi |



Automated sync of actions from gh-aw at
v0.90.1.