You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[ca] CLI version checker: update CLI/MCP defaults for 2026-10-09 #67125
CLI Version Checker found stable upstream updates for agentic CLI/MCP defaults in github/gh-aw during run §37889306696.
Prepared local updates:
pkg/constants/version_constants.go
pkg/constants/version_constants_test.go
actions/setup/sh/install_copilot_cli.sh
.github/aw/compat.json
generated .github/workflows/*.lock.yml files were refreshed by make recompile as required, but should not be committed directly unless the repository policy for this update permits regenerated locks.
Risk: Medium. The update touches MCP startup/discovery, managed settings, assisted permissions, and model selection.
Breaking changes: None called out in the release notes.
Features:
Adds Claude Haiku 5.5 to model selection and --model completions.
Shows update guidance when managed settings request a newer CLI version without blocking normal prompts.
Fixes:
copilot mcp add recovers cleanly after interrupted MCP config initialization.
MCP enable/disable works before server discovery without starting MCP servers.
Clicking a Sessions sidebar row reliably switches sessions during split-view reconciliation.
Security/Policy:
Assisted permissions send visible shell code to the permission judge instead of requiring unnecessary manual approval.
Startup bypass-permission flags suppressed by managed settings now produce a policy warning.
Managed policy can disable Assisted Permissions and keep sessions in Manual Approval mode.
README review: README still documents npm, Homebrew, WinGet and install-script installation, PAT auth, default model behavior, experimental mode, MCP support, and LSP configuration.
CLI help comparison: no substantive main/config help changes vs cached 1.0.93 output; copilot environment --help remains invalid.
OpenAI Codex 0.159.3 → 0.162.0
Source: npm metadata for @openai/codex and GitHub releases.
Risk: Low/Medium. No public release notes were available through the repository instructions; upgrade was based on npm metadata and cached help output.
Breaking changes: None identified.
CLI help comparison: 1.1.0 help is already cached from the previous run and remains the latest observed output.
Safe dependency refreshes and dual-published image signatures in v1.14.0.
Impact on gh-aw:
Verify generated workflows and MCP clients that assume v1 output shapes. Tool consumers that do not advertise MCP 2026-07-28 should not receive incompatible typed outputs, per release notes.
GitHub MCP Server container digest for v2.0.2 was resolved as sha256:ffced0d76e77428532a2ced185516992d77fd146d69eec2f244e6237d1a97796, but the existing action-pins data still contains ghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6 after recompile. Follow-up may be needed if action pin data should be updated for the new default server image.
Validation
make fmt: passed.
make recompile: passed in the foreground; 333/333 workflow files compiled with existing warnings.
make agent-report-progress: partially passed; build, sync checks, action shell lint, schema freshness, custom Go linters, and impacted Go tests for ./pkg/constants passed. The target failed because golangci-lint is not installed in this runner (make deps-dev would be required to install it).
Next actions
Review the v2 GitHub MCP Server compatibility impact, especially typed output behavior for older MCP clients.
Decide whether regenerated .lock.yml files should be committed for this constants update, noting the workflow instruction not to commit lock files directly.
Install golangci-lint (or run in the standard dev image) and rerun make agent-report-progress.
Revisit Syft and Grype after their latest releases pass the 3-day cooldown.
Overview
CLI Version Checker found stable upstream updates for agentic CLI/MCP defaults in github/gh-aw during run §37889306696.
Prepared local updates:
pkg/constants/version_constants.gopkg/constants/version_constants_test.goactions/setup/sh/install_copilot_cli.sh.github/aw/compat.json.github/workflows/*.lock.ymlfiles were refreshed bymake recompileas required, but should not be committed directly unless the repository policy for this update permits regenerated locks.Version updates detected
DefaultClaudeCodeVersionDefaultCopilotVersion, setup fallback, compat max-agentDefaultCodexVersionDefaultPiVersionDefaultGitHubMCPServerVersionRelease analysis
Claude Code 2.1.288 → 2.1.295
@anthropic-ai/claude-code--helpchanges vs cached 2.1.293 output.GitHub Copilot CLI 1.0.90 → 1.0.94
@github/copilotand GitHub release notes.--modelcompletions.copilot mcp addrecovers cleanly after interrupted MCP config initialization.copilot environment --helpremains invalid.OpenAI Codex 0.159.3 → 0.162.0
@openai/codexand GitHub releases.apply_patchpreserves CRLF line endings: Make apply_patch preserve line endings unconditionally openai/codex#51203Pi 1.0.0 → 1.1.0
@earendil-works/pi-coding-agent.GitHub MCP Server v1.12.2 → v2.0.2
fix(go)!: fix(go)!: migrate to the v2 module path github-mcp-server#3445Docker image checks
sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667sha256:172463611795f43b77302cdfbd7b3f81295492a7330e0820cfe41c3674920237sha256:a2eb396d886c053073405c7a980f2139ba2248ec172243cfa3841e57196e8101sha256:722a8e0999b583c1540fe2974e691032b2d9d21b9256a17965132b6bfd0081b0sha256:2df426ef96d21f1622e05b21329f26bd263fc46110609cefb6afe43457613ac0latestdigest unchangedsha256:5ab5eb7da0ed5e606b07c1723fc8b275e925189f70ac259b26b7329cb5f8f44dGitHub MCP Server container digest for v2.0.2 was resolved as
sha256:ffced0d76e77428532a2ced185516992d77fd146d69eec2f244e6237d1a97796, but the existing action-pins data still containsghcr.io/github/github-mcp-server:v1.12.2@sha256:508a0857ec762b1ab1cece29193345b501fab1dd9d1228a7b617062954cecac6after recompile. Follow-up may be needed if action pin data should be updated for the new default server image.Validation
make fmt: passed.make recompile: passed in the foreground; 333/333 workflow files compiled with existing warnings.make agent-report-progress: partially passed; build, sync checks, action shell lint, schema freshness, custom Go linters, and impacted Go tests for./pkg/constantspassed. The target failed becausegolangci-lintis not installed in this runner (make deps-devwould be required to install it).Next actions
.lock.ymlfiles should be committed for this constants update, noting the workflow instruction not to commit lock files directly.golangci-lint(or run in the standard dev image) and rerunmake agent-report-progress.References: