From 604b4198ec452cf805e0f88d517cf175ff6f1b89 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Fri, 11 Sep 2026 23:57:14 +0000 Subject: [PATCH 1/5] Initial plan From 3e862fc3c8eee108cf3688abd07a960eb4dd02b3 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sat, 12 Sep 2026 00:16:28 +0000 Subject: [PATCH 2/5] Prove zero usage before agent execution Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 29 ++++++++++++- .github/workflows/ace-editor.lock.yml | 13 ++++++ .github/workflows/agent-job-health.lock.yml | 29 ++++++++++++- .../agent-performance-analyzer.lock.yml | 29 ++++++++++++- .../workflows/agent-persona-explorer.lock.yml | 29 ++++++++++++- .../workflows/agentic-token-audit.lock.yml | 29 ++++++++++++- .../agentic-token-optimizer.lock.yml | 13 ++++++ .../agentic-token-trend-audit.lock.yml | 29 ++++++++++++- .github/workflows/ai-moderator.lock.yml | 13 ++++++ .../workflows/api-consumption-report.lock.yml | 29 ++++++++++++- .github/workflows/approach-validator.lock.yml | 29 ++++++++++++- .github/workflows/archie.lock.yml | 29 ++++++++++++- .../workflows/architecture-guardian.lock.yml | 29 ++++++++++++- ...rchivx-agentic-workflows-analyzer.lock.yml | 29 ++++++++++++- .github/workflows/artifacts-summary.lock.yml | 29 ++++++++++++- .github/workflows/audit-workflows.lock.yml | 29 ++++++++++++- .github/workflows/auto-triage-issues.lock.yml | 29 ++++++++++++- .github/workflows/avenger.lock.yml | 29 ++++++++++++- .../aw-failure-investigator.lock.yml | 29 ++++++++++++- .github/workflows/blog-auditor.lock.yml | 29 ++++++++++++- .github/workflows/bot-detection.lock.yml | 13 ++++++ .../breaking-change-checker.lock.yml | 29 ++++++++++++- .github/workflows/changeset.lock.yml | 29 ++++++++++++- .../workflows/chaos-pr-bundle-fuzzer.lock.yml | 29 ++++++++++++- .github/workflows/ci-coach.lock.yml | 29 ++++++++++++- .github/workflows/ci-doctor.lock.yml | 29 ++++++++++++- .../claude-code-user-docs-review.lock.yml | 29 ++++++++++++- .../cli-consistency-checker.lock.yml | 29 ++++++++++++- .../workflows/cli-version-checker.lock.yml | 29 ++++++++++++- .github/workflows/cloclo.lock.yml | 29 ++++++++++++- .../workflows/code-scanning-fixer.lock.yml | 29 ++++++++++++- .github/workflows/code-simplifier.lock.yml | 29 ++++++++++++- .../codex-github-remote-mcp-test.lock.yml | 13 ++++++ .../commit-changes-analyzer.lock.yml | 29 ++++++++++++- .../constraint-solving-potd.lock.yml | 29 ++++++++++++- .github/workflows/contribution-check.lock.yml | 29 ++++++++++++- .../workflows/copilot-agent-analysis.lock.yml | 29 ++++++++++++- .../copilot-centralization-drilldown.lock.yml | 29 ++++++++++++- .../copilot-centralization-optimizer.lock.yml | 29 ++++++++++++- .../copilot-cli-deep-research.lock.yml | 29 ++++++++++++- .github/workflows/copilot-opt.lock.yml | 29 ++++++++++++- .../copilot-pr-merged-report.lock.yml | 29 ++++++++++++- .../copilot-pr-nlp-analysis.lock.yml | 29 ++++++++++++- .../copilot-pr-prompt-analysis.lock.yml | 29 ++++++++++++- .../copilot-session-insights.lock.yml | 29 ++++++++++++- .github/workflows/craft.lock.yml | 29 ++++++++++++- ...daily-action-setup-security-audit.lock.yml | 29 ++++++++++++- ...aily-agent-of-the-day-blog-writer.lock.yml | 29 ++++++++++++- .../daily-agentrx-trace-optimizer.lock.yml | 29 ++++++++++++- .../daily-ambient-context-optimizer.lock.yml | 29 ++++++++++++- .../daily-architecture-diagram.lock.yml | 29 ++++++++++++- .../workflows/daily-arxiv-researcher.lock.yml | 29 ++++++++++++- .../daily-assign-issue-to-user.lock.yml | 29 ++++++++++++- ...strostylelite-markdown-spellcheck.lock.yml | 29 ++++++++++++- ...daily-aw-cross-repo-compile-check.lock.yml | 29 ++++++++++++- ...daily-awf-spec-compiler-surfacing.lock.yml | 29 ++++++++++++- .../workflows/daily-byok-ollama-test.lock.yml | 29 ++++++++++++- .../daily-cache-strategy-analyzer.lock.yml | 29 ++++++++++++- .../daily-caveman-optimizer.lock.yml | 29 ++++++++++++- .github/workflows/daily-choice-test.lock.yml | 29 ++++++++++++- .../workflows/daily-cli-performance.lock.yml | 29 ++++++++++++- .../workflows/daily-cli-tools-tester.lock.yml | 29 ++++++++++++- .../workflows/daily-code-debt-aider.lock.yml | 29 ++++++++++++- .github/workflows/daily-code-metrics.lock.yml | 29 ++++++++++++- .../daily-community-attribution.lock.yml | 29 ++++++++++++- .../workflows/daily-compiler-quality.lock.yml | 29 ++++++++++++- ...ly-compiler-threat-spec-optimizer.lock.yml | 29 ++++++++++++- .../daily-credit-limit-test.lock.yml | 29 ++++++++++++- .github/workflows/daily-doc-healer.lock.yml | 29 ++++++++++++- .github/workflows/daily-doc-updater.lock.yml | 29 ++++++++++++- .../daily-documentation-diagram.lock.yml | 29 ++++++++++++- .../daily-elixir-credo-snippet-audit.lock.yml | 29 ++++++++++++- .github/workflows/daily-evals-report.lock.yml | 29 ++++++++++++- .../daily-experiment-report.lock.yml | 29 ++++++++++++- .github/workflows/daily-fact.lock.yml | 29 ++++++++++++- .github/workflows/daily-file-diet.lock.yml | 29 ++++++++++++- .../workflows/daily-firewall-report.lock.yml | 29 ++++++++++++- .../daily-formal-spec-verifier.lock.yml | 29 ++++++++++++- .../workflows/daily-function-namer.lock.yml | 29 ++++++++++++- .../workflows/daily-geo-optimizer.lock.yml | 29 ++++++++++++- .../daily-github-docs-seo-optimizer.lock.yml | 29 ++++++++++++- .../daily-go-test-parallelizer.lock.yml | 29 ++++++++++++- .../daily-go-test-stubs-aider.lock.yml | 29 ++++++++++++- .github/workflows/daily-grader-audit.lock.yml | 29 ++++++++++++- .../daily-graft-intelligence.lock.yml | 29 ++++++++++++- ...daily-harness-experiment-proposer.lock.yml | 13 ++++++ .github/workflows/daily-hippo-learn.lock.yml | 29 ++++++++++++- .../workflows/daily-issues-report.lock.yml | 29 ++++++++++++- .../daily-malicious-code-scan.lock.yml | 13 ++++++ .../daily-max-ai-credits-test.lock.yml | 29 ++++++++++++- .../daily-mcp-concurrency-analysis.lock.yml | 29 ++++++++++++- .../workflows/daily-model-inventory.lock.yml | 29 ++++++++++++- .../workflows/daily-model-resolution.lock.yml | 29 ++++++++++++- .../daily-multi-device-docs-tester.lock.yml | 29 ++++++++++++- .github/workflows/daily-news.lock.yml | 29 ++++++++++++- .../daily-observability-report.lock.yml | 29 ++++++++++++- .../daily-performance-summary.lock.yml | 29 ++++++++++++- .../workflows/daily-pr-review-cursor.lock.yml | 29 ++++++++++++- .../daily-regression-audit-kiro.lock.yml | 29 ++++++++++++- .github/workflows/daily-regulatory.lock.yml | 29 ++++++++++++- .../daily-reliability-review.lock.yml | 29 ++++++++++++- .../daily-rendering-scripts-verifier.lock.yml | 29 ++++++++++++- .../workflows/daily-repo-chronicle.lock.yml | 29 ++++++++++++- .../daily-safe-output-integrator.lock.yml | 29 ++++++++++++- .../daily-safe-output-optimizer.lock.yml | 29 ++++++++++++- .../daily-safe-outputs-conformance.lock.yml | 29 ++++++++++++- .../daily-safeoutputs-git-simulator.lock.yml | 29 ++++++++++++- .../daily-schema-audit-cursor.lock.yml | 29 ++++++++++++- .../workflows/daily-secrets-analysis.lock.yml | 29 ++++++++++++- .../daily-security-observability.lock.yml | 29 ++++++++++++- .../daily-security-red-team.lock.yml | 29 ++++++++++++- .github/workflows/daily-semgrep-scan.lock.yml | 29 ++++++++++++- .../daily-spdd-spec-planner.lock.yml | 29 ++++++++++++- .../daily-spec-coverage-kiro.lock.yml | 29 ++++++++++++- .../daily-spending-forecast.lock.yml | 29 ++++++++++++- .../workflows/daily-squid-image-scan.lock.yml | 29 ++++++++++++- .github/workflows/daily-storify.lock.yml | 29 ++++++++++++- .../daily-syntax-error-quality.lock.yml | 29 ++++++++++++- .../daily-team-evolution-insights.lock.yml | 29 ++++++++++++- .github/workflows/daily-team-status.lock.yml | 29 ++++++++++++- .../daily-testify-uber-super-expert.lock.yml | 29 ++++++++++++- .../daily-token-consumption-report.lock.yml | 29 ++++++++++++- ...ily-trajectory-grader-implementer.lock.yml | 29 ++++++++++++- .../workflows/daily-vulnhunter-scan.lock.yml | 29 ++++++++++++- .../daily-windows-defender-scan.lock.yml | 29 ++++++++++++- ...dows-terminal-integration-builder.lock.yml | 29 ++++++++++++- .../workflows/daily-workflow-updater.lock.yml | 29 ++++++++++++- .../workflows/daily-yamllint-fixer.lock.yml | 29 ++++++++++++- .../dataflow-pr-discussion-dataset.lock.yml | 29 ++++++++++++- .github/workflows/dead-code-remover.lock.yml | 29 ++++++++++++- .github/workflows/deep-report.lock.yml | 29 ++++++++++++- .../workflows/deepsec-security-scan.lock.yml | 29 ++++++++++++- .github/workflows/delight.lock.yml | 29 ++++++++++++- .github/workflows/dependabot-burner.lock.yml | 29 ++++++++++++- .../workflows/dependabot-go-checker.lock.yml | 29 ++++++++++++- .../deployment-incident-monitor.lock.yml | 29 ++++++++++++- .../workflows/design-decision-gate.lock.yml | 29 ++++++++++++- .../workflows/designer-drift-audit.lock.yml | 29 ++++++++++++- .../detection-analysis-report.lock.yml | 29 ++++++++++++- .github/workflows/dev-hawk.lock.yml | 29 ++++++++++++- .github/workflows/dev.lock.yml | 29 ++++++++++++- .../developer-docs-consolidator.lock.yml | 29 ++++++++++++- .github/workflows/dictation-prompt.lock.yml | 29 ++++++++++++- .github/workflows/docs-noob-tester.lock.yml | 29 ++++++++++++- .github/workflows/draft-pr-cleanup.lock.yml | 29 ++++++++++++- .../duplicate-code-detector.lock.yml | 29 ++++++++++++- .github/workflows/eslint-miner.lock.yml | 29 ++++++++++++- .github/workflows/eslint-monster.lock.yml | 29 ++++++++++++- .github/workflows/eslint-refiner.lock.yml | 29 ++++++++++++- .github/workflows/evoskill-evolver.lock.yml | 29 ++++++++++++- .../example-failure-category-filter.lock.yml | 29 ++++++++++++- .../example-permissions-warning.lock.yml | 13 ++++++ .../example-workflow-analyzer.lock.yml | 29 ++++++++++++- .github/workflows/feature-grower.lock.yml | 29 ++++++++++++- .github/workflows/firewall-escape.lock.yml | 29 ++++++++++++- .github/workflows/firewall.lock.yml | 13 ++++++ .../workflows/front-page-copy-guard.lock.yml | 29 ++++++++++++- .../workflows/functional-pragmatist.lock.yml | 29 ++++++++++++- .../github-mcp-structural-analysis.lock.yml | 29 ++++++++++++- .../github-mcp-tools-report.lock.yml | 29 ++++++++++++- .../github-remote-mcp-auth-test.lock.yml | 29 ++++++++++++- .../workflows/glossary-maintainer.lock.yml | 29 ++++++++++++- .github/workflows/go-fan.lock.yml | 29 ++++++++++++- .github/workflows/go-logger.lock.yml | 29 ++++++++++++- .../workflows/go-pattern-detector.lock.yml | 29 ++++++++++++- .github/workflows/gpclean.lock.yml | 29 ++++++++++++- .github/workflows/grumpy-reviewer.lock.yml | 29 ++++++++++++- .github/workflows/hippo-embed.lock.yml | 13 ++++++ .github/workflows/hourly-ci-cleaner.lock.yml | 29 ++++++++++++- .../impeccable-skills-reviewer.lock.yml | 29 ++++++++++++- .../workflows/instructions-janitor.lock.yml | 29 ++++++++++++- .github/workflows/issue-arborist.lock.yml | 29 ++++++++++++- .github/workflows/issue-monster.lock.yml | 29 ++++++++++++- .github/workflows/issue-triage-agent.lock.yml | 29 ++++++++++++- .github/workflows/jsweep.lock.yml | 29 ++++++++++++- .../workflows/layout-spec-maintainer.lock.yml | 29 ++++++++++++- .github/workflows/lint-monster.lock.yml | 29 ++++++++++++- .github/workflows/linter-miner.lock.yml | 29 ++++++++++++- .github/workflows/lockfile-stats.lock.yml | 29 ++++++++++++- .../mattpocock-skills-reviewer.lock.yml | 29 ++++++++++++- .github/workflows/mcp-inspector.lock.yml | 29 ++++++++++++- .github/workflows/mergefest.lock.yml | 29 ++++++++++++- .github/workflows/metrics-collector.lock.yml | 29 ++++++++++++- .github/workflows/necromancer.lock.yml | 29 ++++++++++++- .../workflows/notion-issue-summary.lock.yml | 13 ++++++ .../objective-impact-report.lock.yml | 29 ++++++++++++- .github/workflows/org-health-report.lock.yml | 29 ++++++++++++- .github/workflows/outcome-collector.lock.yml | 29 ++++++++++++- .github/workflows/pdf-summary.lock.yml | 29 ++++++++++++- .github/workflows/plan.lock.yml | 29 ++++++++++++- .github/workflows/poem-bot.lock.yml | 29 ++++++++++++- .github/workflows/ponytail-reviewer.lock.yml | 29 ++++++++++++- .github/workflows/portfolio-analyst.lock.yml | 29 ++++++++++++- .../pr-code-quality-reviewer.lock.yml | 29 ++++++++++++- .../workflows/pr-description-caveman.lock.yml | 29 ++++++++++++- .../workflows/pr-nitpick-reviewer.lock.yml | 29 ++++++++++++- .github/workflows/pr-sous-chef.lock.yml | 29 ++++++++++++- .github/workflows/pr-triage-agent.lock.yml | 29 ++++++++++++- .../prompt-clustering-analysis.lock.yml | 29 ++++++++++++- .github/workflows/purelock.lock.yml | 29 ++++++++++++- .github/workflows/python-data-charts.lock.yml | 29 ++++++++++++- .github/workflows/q.lock.yml | 29 ++++++++++++- .../workflows/refactoring-cadence.lock.yml | 29 ++++++++++++- .github/workflows/refiner.lock.yml | 29 ++++++++++++- .github/workflows/release.lock.yml | 13 ++++++ .../workflows/repo-audit-analyzer.lock.yml | 29 ++++++++++++- .github/workflows/repo-tree-map.lock.yml | 29 ++++++++++++- .../repository-quality-improver.lock.yml | 29 ++++++++++++- .github/workflows/research.lock.yml | 29 ++++++++++++- .github/workflows/ruflo-backed-task.lock.yml | 29 ++++++++++++- .github/workflows/safe-output-health.lock.yml | 29 ++++++++++++- .../schema-consistency-checker.lock.yml | 29 ++++++++++++- .../schema-feature-coverage.lock.yml | 29 ++++++++++++- .github/workflows/scout.lock.yml | 29 ++++++++++++- .../workflows/security-compliance.lock.yml | 29 ++++++++++++- .github/workflows/security-review.lock.yml | 29 ++++++++++++- .../semantic-function-refactor.lock.yml | 29 ++++++++++++- .github/workflows/sergo.lock.yml | 29 ++++++++++++- .../sighthound-security-scan.lock.yml | 29 ++++++++++++- .github/workflows/skillet.lock.yml | 29 ++++++++++++- .../workflows/slide-deck-maintainer.lock.yml | 29 ++++++++++++- .../workflows/smoke-agent-all-merged.lock.yml | 29 ++++++++++++- .../workflows/smoke-agent-all-none.lock.yml | 29 ++++++++++++- .../smoke-agent-public-approved.lock.yml | 29 ++++++++++++- .../smoke-agent-public-none.lock.yml | 29 ++++++++++++- .../smoke-agent-scoped-approved.lock.yml | 29 ++++++++++++- .github/workflows/smoke-aider.lock.yml | 29 ++++++++++++- .../workflows/smoke-call-workflow.lock.yml | 29 ++++++++++++- .../smoke-checkout-pr-dispatch.lock.yml | 29 ++++++++++++- .github/workflows/smoke-ci.lock.yml | 7 ++++ .../smoke-claude-on-copilot.lock.yml | 29 ++++++++++++- .github/workflows/smoke-claude.lock.yml | 29 ++++++++++++- .github/workflows/smoke-codex.lock.yml | 29 ++++++++++++- .../smoke-copilot-aoai-apikey.lock.yml | 29 ++++++++++++- .../smoke-copilot-aoai-entra.lock.yml | 29 ++++++++++++- .github/workflows/smoke-copilot-arm.lock.yml | 29 ++++++++++++- .github/workflows/smoke-copilot-auto.lock.yml | 29 ++++++++++++- .github/workflows/smoke-copilot-mai.lock.yml | 29 ++++++++++++- .github/workflows/smoke-copilot-sdk.lock.yml | 29 ++++++++++++- .../workflows/smoke-copilot-small.lock.yml | 29 ++++++++++++- .../smoke-copilot-sub-agents.lock.yml | 29 ++++++++++++- .github/workflows/smoke-copilot.lock.yml | 29 ++++++++++++- .../smoke-create-cross-repo-pr.lock.yml | 29 ++++++++++++- .github/workflows/smoke-crush.lock.yml | 29 ++++++++++++- .github/workflows/smoke-cursor.lock.yml | 29 ++++++++++++- .../workflows/smoke-deepseek-harness.lock.yml | 29 ++++++++++++- .github/workflows/smoke-drive.lock.yml | 29 ++++++++++++- .github/workflows/smoke-gemini.lock.yml | 29 ++++++++++++- .../workflows/smoke-github-claude.lock.yml | 29 ++++++++++++- .github/workflows/smoke-goose.lock.yml | 29 ++++++++++++- .github/workflows/smoke-issues.lock.yml | 29 ++++++++++++- .github/workflows/smoke-kiro.lock.yml | 29 ++++++++++++- .github/workflows/smoke-multi-pr.lock.yml | 29 ++++++++++++- .github/workflows/smoke-opencode.lock.yml | 29 ++++++++++++- .../workflows/smoke-otel-backends.lock.yml | 29 ++++++++++++- .github/workflows/smoke-pi.lock.yml | 29 ++++++++++++- .github/workflows/smoke-project.lock.yml | 29 ++++++++++++- .github/workflows/smoke-pydantic.lock.yml | 29 ++++++++++++- .../workflows/smoke-service-ports.lock.yml | 29 ++++++++++++- .github/workflows/smoke-temporary-id.lock.yml | 29 ++++++++++++- .github/workflows/smoke-test-tools.lock.yml | 29 ++++++++++++- .../smoke-update-cross-repo-pr.lock.yml | 29 ++++++++++++- .../smoke-workflow-call-with-inputs.lock.yml | 29 ++++++++++++- .../workflows/smoke-workflow-call.lock.yml | 29 ++++++++++++- .github/workflows/spec-enforcer.lock.yml | 29 ++++++++++++- .github/workflows/spec-extractor.lock.yml | 29 ++++++++++++- .github/workflows/spec-librarian.lock.yml | 29 ++++++++++++- .github/workflows/squad-game-planner.lock.yml | 29 ++++++++++++- .../workflows/squad-implement-worker.lock.yml | 29 ++++++++++++- .github/workflows/squad-plan.lock.yml | 29 ++++++++++++- .github/workflows/squad.lock.yml | 29 ++++++++++++- .github/workflows/stale-pr-cleanup.lock.yml | 29 ++++++++++++- .../workflows/stale-repo-identifier.lock.yml | 29 ++++++++++++- .../workflows/static-analysis-report.lock.yml | 29 ++++++++++++- .../workflows/step-name-alignment.lock.yml | 29 ++++++++++++- .github/workflows/sub-issue-closer.lock.yml | 29 ++++++++++++- .github/workflows/super-linter.lock.yml | 29 ++++++++++++- .../workflows/technical-doc-writer.lock.yml | 29 ++++++++++++- .github/workflows/terminal-stylist.lock.yml | 29 ++++++++++++- .../workflows/test-quality-sentinel.lock.yml | 29 ++++++++++++- .github/workflows/tidy.lock.yml | 29 ++++++++++++- .github/workflows/typist.lock.yml | 29 ++++++++++++- .../workflows/ubuntu-image-analyzer.lock.yml | 29 ++++++++++++- .../uk-ai-operational-resilience.lock.yml | 29 ++++++++++++- .github/workflows/unbloat-docs.lock.yml | 29 ++++++++++++- .github/workflows/update-astro.lock.yml | 29 ++++++++++++- .github/workflows/video-analyzer.lock.yml | 29 ++++++++++++- .../visual-regression-checker.lock.yml | 29 ++++++++++++- .../weekly-blog-post-writer.lock.yml | 29 ++++++++++++- .../weekly-editors-health-check.lock.yml | 29 ++++++++++++- .../workflows/weekly-issue-summary.lock.yml | 29 ++++++++++++- .../weekly-network-domains-audit.lock.yml | 29 ++++++++++++- .../weekly-safe-outputs-spec-review.lock.yml | 29 ++++++++++++- .github/workflows/windows-grower.lock.yml | 29 ++++++++++++- .github/workflows/windows.lock.yml | 31 +++++++++++++- .github/workflows/workflow-generator.lock.yml | 29 ++++++++++++- .../workflow-health-manager.lock.yml | 29 ++++++++++++- .../workflows/workflow-normalizer.lock.yml | 29 ++++++++++++- .../workflow-skill-extractor.lock.yml | 29 ++++++++++++- .../js/check_daily_aic_workflow_guardrail.cjs | 4 +- .../setup/js/daily_aic_component_coverage.cjs | 18 +++++++- .../js/daily_aic_component_coverage.test.cjs | 41 +++++++++++++++++++ .../setup/sh/collect_usage_artifact_files.sh | 2 + pkg/workflow/compiler_yaml_ai_execution.go | 32 +++++++++++++++ pkg/workflow/compiler_yaml_main_job.go | 4 ++ pkg/workflow/compiler_yaml_post_agent.go | 1 + .../daily_aic_workflow_guardrail_test.go | 40 ++++++++++++++++++ pkg/workflow/threat_detection_external.go | 3 +- pkg/workflow/threat_detection_steps.go | 8 +++- pkg/workflow/threat_detection_steps_test.go | 8 ++++ 310 files changed, 8327 insertions(+), 293 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index 0f37759c87b..22a763ea536 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -495,6 +495,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -972,6 +978,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1251,6 +1263,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1619,6 +1632,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1709,6 +1728,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1790,12 +1816,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ace-editor.lock.yml b/.github/workflows/ace-editor.lock.yml index 1ea6f42edbf..4799c439a5c 100644 --- a/.github/workflows/ace-editor.lock.yml +++ b/.github/workflows/ace-editor.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -892,6 +898,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1139,6 +1151,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 18613c7228e..3c16b2db5ed 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -498,6 +498,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1006,6 +1012,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1386,6 +1398,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1756,6 +1769,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1822,6 +1841,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1907,12 +1933,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index 59f74270a65..0b03a572fdb 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1071,6 +1077,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1394,6 +1406,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1768,6 +1781,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1837,6 +1856,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1936,12 +1962,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index b26ce6a6a47..0d1b07ff042 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -537,6 +537,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1078,6 +1084,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 180 @@ -1357,6 +1369,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1725,6 +1738,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1794,6 +1813,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1892,12 +1918,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/agentic-token-audit.lock.yml b/.github/workflows/agentic-token-audit.lock.yml index 00e7369e9e0..a23a0137808 100644 --- a/.github/workflows/agentic-token-audit.lock.yml +++ b/.github/workflows/agentic-token-audit.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -983,6 +989,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1286,6 +1298,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1656,6 +1669,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1725,6 +1744,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1823,12 +1849,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/agentic-token-optimizer.lock.yml b/.github/workflows/agentic-token-optimizer.lock.yml index f1ba5790b4b..199bcc85fb6 100644 --- a/.github/workflows/agentic-token-optimizer.lock.yml +++ b/.github/workflows/agentic-token-optimizer.lock.yml @@ -477,6 +477,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -892,6 +898,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1184,6 +1196,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index 2c86d398771..d95552ff97b 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1045,6 +1051,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 25 @@ -1318,6 +1330,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1682,6 +1695,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1772,6 +1791,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1853,12 +1879,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index 6ef975c5678..43ee0d2f97a 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -542,6 +542,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory @@ -920,6 +926,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 @@ -1188,6 +1200,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 244f98fa5b8..eb8c6c8d72f 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -501,6 +501,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1068,6 +1074,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1356,6 +1368,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1727,6 +1740,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1817,6 +1836,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1898,12 +1924,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index 4de5387eec6..eb629ed00c8 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -580,6 +580,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1004,6 +1010,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1372,6 +1384,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1754,6 +1767,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1820,6 +1839,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1905,12 +1931,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index f0fc70ef094..910ee36ac1a 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -540,6 +540,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -969,6 +975,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1257,6 +1269,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1640,6 +1653,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1709,6 +1728,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1808,12 +1834,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 137e43d66ee..97799426784 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -876,6 +882,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1187,6 +1199,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1552,6 +1565,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1621,6 +1640,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1720,12 +1746,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index 3b695911c27..fbcebc92b98 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -546,6 +546,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1076,6 +1082,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1413,6 +1425,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1804,6 +1817,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1870,6 +1889,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1955,12 +1981,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index 952cac9d6ad..bf41bc824e2 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -921,6 +927,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1182,6 +1194,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1543,6 +1556,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1633,6 +1652,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1714,12 +1740,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index a1762942d8b..c2337050ee4 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -564,6 +564,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1151,6 +1157,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1470,6 +1482,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1853,6 +1866,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1943,6 +1962,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2024,12 +2050,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index 0295fdde1ea..7430b89bd75 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -502,6 +502,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1016,6 +1022,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1277,6 +1289,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1641,6 +1654,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1731,6 +1750,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1812,12 +1838,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index 82f6a2b68b8..9a9dbae94f5 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -522,6 +522,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1019,6 +1025,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1280,6 +1292,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1727,6 +1740,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1817,6 +1836,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1898,12 +1924,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index 34dd40ef33f..8aed16d1388 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -539,6 +539,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1112,6 +1118,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1452,6 +1464,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1822,6 +1835,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1888,6 +1907,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1973,12 +1999,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 80ad79f1c04..86f03b8e1e2 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -927,6 +933,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1286,6 +1298,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1659,6 +1672,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1725,6 +1744,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1810,12 +1836,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/bot-detection.lock.yml b/.github/workflows/bot-detection.lock.yml index 1bef407fba2..4a65275dcbf 100644 --- a/.github/workflows/bot-detection.lock.yml +++ b/.github/workflows/bot-detection.lock.yml @@ -500,6 +500,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1011,6 +1017,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1272,6 +1284,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index d7f7075e63f..3b94d8a1741 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -525,6 +525,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -911,6 +917,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1227,6 +1239,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1599,6 +1612,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1668,6 +1687,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1767,12 +1793,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index 870586d45c1..2b89d5096e5 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -538,6 +538,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1021,6 +1027,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1282,6 +1294,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1643,6 +1656,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1733,6 +1752,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1814,12 +1840,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index b125e06d6a1..fb722fc14e4 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -979,6 +985,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1258,6 +1270,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1610,6 +1623,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1700,6 +1719,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,12 +1807,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index cf376494a9e..85ad76df8e7 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -557,6 +557,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1005,6 +1011,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1315,6 +1327,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1717,6 +1730,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1786,6 +1805,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1885,12 +1911,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index 0e05bf19686..1665c997f3b 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -580,6 +580,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1079,6 +1085,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1412,6 +1424,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1803,6 +1816,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1869,6 +1888,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1954,12 +1980,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index 60cd4d69427..b0999a22879 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -866,6 +872,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1247,6 +1259,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1618,6 +1631,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1684,6 +1703,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1769,12 +1795,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index 84b5f46aa10..68c87b2f953 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -863,6 +869,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1159,6 +1171,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1517,6 +1530,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1586,6 +1605,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1685,12 +1711,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index a90671563f0..7e3031b8c6a 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -864,6 +870,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 @@ -1133,6 +1145,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1484,6 +1497,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1553,6 +1572,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1652,12 +1678,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index 492cba8edf9..deb2f18b23e 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -633,6 +633,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1309,6 +1315,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1591,6 +1603,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2004,6 +2017,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2094,6 +2113,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2175,12 +2201,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index bbf750a8111..cd82468235a 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -515,6 +515,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -994,6 +1000,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1336,6 +1348,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1725,6 +1738,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1794,6 +1813,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1893,12 +1919,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index 2859495b60b..3c9afba4c17 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -508,6 +508,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -929,6 +935,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1213,6 +1225,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1606,6 +1619,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1675,6 +1694,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1773,12 +1799,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/codex-github-remote-mcp-test.lock.yml b/.github/workflows/codex-github-remote-mcp-test.lock.yml index d8ff033e9c9..75131e1025f 100644 --- a/.github/workflows/codex-github-remote-mcp-test.lock.yml +++ b/.github/workflows/codex-github-remote-mcp-test.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -846,6 +852,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1090,6 +1102,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 8366f78c4d7..5125e3d5455 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -474,6 +474,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -917,6 +923,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1144,6 +1156,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1501,6 +1514,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1591,6 +1610,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1672,12 +1698,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index ecdc82c1adb..85abf01c93e 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -472,6 +472,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -842,6 +848,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1116,6 +1128,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1478,6 +1491,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1547,6 +1566,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1645,12 +1671,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index 05c6544a1a6..391001a63e2 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1003,6 +1009,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1289,6 +1301,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1648,6 +1661,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1717,6 +1736,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1815,12 +1841,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index b0b2ebb949c..38e146c1cb3 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -545,6 +545,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -967,6 +973,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1330,6 +1342,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1703,6 +1716,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1769,6 +1788,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1854,12 +1880,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-centralization-drilldown.lock.yml b/.github/workflows/copilot-centralization-drilldown.lock.yml index 822a0d0817a..55a43712998 100644 --- a/.github/workflows/copilot-centralization-drilldown.lock.yml +++ b/.github/workflows/copilot-centralization-drilldown.lock.yml @@ -461,6 +461,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -929,6 +935,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1151,6 +1163,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1505,6 +1518,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1595,6 +1614,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1676,12 +1702,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-centralization-optimizer.lock.yml b/.github/workflows/copilot-centralization-optimizer.lock.yml index 7a9a7acf1c7..c92ea61cf28 100644 --- a/.github/workflows/copilot-centralization-optimizer.lock.yml +++ b/.github/workflows/copilot-centralization-optimizer.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -973,6 +979,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1227,6 +1239,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1586,6 +1599,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1676,6 +1695,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1757,12 +1783,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index ca9dd6c3212..c60a72d5e33 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -870,6 +876,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1175,6 +1187,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1535,6 +1548,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1604,6 +1623,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1703,12 +1729,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index b6c06cba011..0d112c986a5 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -485,6 +485,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -897,6 +903,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1216,6 +1228,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1576,6 +1589,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1645,6 +1664,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1743,12 +1769,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 76373bdcbe1..bb507a8d786 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -465,6 +465,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -824,6 +830,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1104,6 +1116,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1466,6 +1479,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1535,6 +1554,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1634,12 +1660,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index c19213b1c5c..cb99576f8d0 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -500,6 +500,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -967,6 +973,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1292,6 +1304,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1660,6 +1673,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1729,6 +1748,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1828,12 +1854,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 054540a725d..9482ed58134 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -493,6 +493,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -913,6 +919,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1226,6 +1238,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1593,6 +1606,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1662,6 +1681,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1761,12 +1787,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 6eba6010fb5..6bae3a8e147 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -517,6 +517,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -959,6 +965,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1333,6 +1345,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1700,6 +1713,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1766,6 +1785,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1851,12 +1877,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index 7e9da483d67..eb866440108 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -526,6 +526,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -931,6 +937,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1206,6 +1218,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1589,6 +1602,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1658,6 +1677,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1757,12 +1783,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-action-setup-security-audit.lock.yml b/.github/workflows/daily-action-setup-security-audit.lock.yml index 15e437b54fc..e0779f6be93 100644 --- a/.github/workflows/daily-action-setup-security-audit.lock.yml +++ b/.github/workflows/daily-action-setup-security-audit.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -876,6 +882,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1158,6 +1170,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1524,6 +1537,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1593,6 +1612,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1691,12 +1717,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index f87c31f9092..91ba1fc3e04 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -515,6 +515,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1031,6 +1037,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1322,6 +1334,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1720,6 +1733,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1789,6 +1808,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1887,12 +1913,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index 6827b5beeaf..dc71f47d910 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1051,6 +1057,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1382,6 +1394,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1756,6 +1769,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1822,6 +1841,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1907,12 +1933,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index f442466830c..959ef20defb 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -941,6 +947,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1206,6 +1218,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1567,6 +1580,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1636,6 +1655,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1735,12 +1761,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 23e55978fa5..d7e96c856c8 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -541,6 +541,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1099,6 +1105,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1342,6 +1354,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1737,6 +1750,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1827,6 +1846,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1908,12 +1934,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-arxiv-researcher.lock.yml b/.github/workflows/daily-arxiv-researcher.lock.yml index bd99fe1566b..fbc88fdf54d 100644 --- a/.github/workflows/daily-arxiv-researcher.lock.yml +++ b/.github/workflows/daily-arxiv-researcher.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -924,6 +930,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1272,6 +1284,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1626,6 +1639,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1695,6 +1714,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1794,12 +1820,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index 987a6090d66..fe0808d1cb9 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -458,6 +458,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -887,6 +893,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1151,6 +1163,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1507,6 +1520,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1576,6 +1595,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1675,12 +1701,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index 572c7867287..4d402faaf5d 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -949,6 +955,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1255,6 +1267,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1651,6 +1664,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1717,6 +1736,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1802,12 +1828,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index 8969d33dbad..72950078acc 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -887,6 +893,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1216,6 +1228,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1581,6 +1594,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1647,6 +1666,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1732,12 +1758,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index c12b9db207c..3739a29ce28 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -954,6 +960,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1212,6 +1224,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1577,6 +1590,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1667,6 +1686,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1748,12 +1774,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index fd82bfb2050..837497d045b 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -460,6 +460,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -876,6 +882,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1137,6 +1149,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1479,6 +1492,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1548,6 +1567,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1647,12 +1673,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index ee6ca14aaf8..2569ea35293 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -536,6 +536,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1117,6 +1123,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 60 @@ -1363,6 +1375,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1737,6 +1750,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1827,6 +1846,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1908,12 +1934,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index c8fdc2adbc0..d7cfb20e895 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -543,6 +543,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -968,6 +974,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1297,6 +1309,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1696,6 +1709,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1762,6 +1781,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1848,12 +1874,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index 40768186c2d..c449e02b1d1 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -465,6 +465,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -845,6 +851,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1152,6 +1164,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1500,6 +1513,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1566,6 +1585,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,12 +1677,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 8f3919ccbd6..aee596ff39b 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -525,6 +525,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1226,6 +1232,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1495,6 +1507,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1866,6 +1879,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1956,6 +1975,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2037,12 +2063,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index e606bdeb711..b197b4393f8 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -477,6 +477,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1030,6 +1036,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 60 @@ -1253,6 +1265,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1610,6 +1623,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1700,6 +1719,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,12 +1807,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-code-debt-aider.lock.yml b/.github/workflows/daily-code-debt-aider.lock.yml index fa558df1d5e..0f5210cc196 100644 --- a/.github/workflows/daily-code-debt-aider.lock.yml +++ b/.github/workflows/daily-code-debt-aider.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -874,6 +880,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -1122,6 +1134,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1483,6 +1496,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1552,6 +1571,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,12 +1677,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index c3234ab584b..0bca82779cf 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -537,6 +537,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -990,6 +996,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1306,6 +1318,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1687,6 +1700,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1756,6 +1775,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1855,12 +1881,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index 51243746255..93a6b3a9b24 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -547,6 +547,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1034,6 +1040,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1337,6 +1349,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1733,6 +1746,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1802,6 +1821,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1900,12 +1926,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 7e318f35f03..d9f8393a658 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -528,6 +528,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -961,6 +967,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1272,6 +1284,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1647,6 +1660,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1716,6 +1735,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1815,12 +1841,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index aabdf2cc10c..c721709dc24 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -926,6 +932,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1221,6 +1233,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1614,6 +1627,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1683,6 +1702,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,12 +1807,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index c641c24576e..bee03f8ce15 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -444,6 +444,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -816,6 +822,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 @@ -1034,6 +1046,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1366,6 +1379,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1435,6 +1454,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1534,12 +1560,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index a5b8b829222..f9a8033ca74 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -549,6 +549,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1041,6 +1047,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1401,6 +1413,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1803,6 +1816,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1869,6 +1888,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1955,12 +1981,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index 25c06c41192..0e4db8a34f0 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -550,6 +550,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1051,6 +1057,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1296,6 +1308,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1697,6 +1710,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1787,6 +1806,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1868,12 +1894,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-documentation-diagram.lock.yml b/.github/workflows/daily-documentation-diagram.lock.yml index cc1823925ab..c6e0199585d 100644 --- a/.github/workflows/daily-documentation-diagram.lock.yml +++ b/.github/workflows/daily-documentation-diagram.lock.yml @@ -522,6 +522,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1001,6 +1007,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1268,6 +1280,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1658,6 +1671,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1748,6 +1767,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1829,12 +1855,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index da2911f2c0e..afdeff9570e 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -490,6 +490,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -912,6 +918,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1218,6 +1230,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1606,6 +1619,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1757,12 +1783,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index ebdc69e7f16..219b2fded06 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -479,6 +479,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1042,6 +1048,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1269,6 +1281,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1632,6 +1645,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1722,6 +1741,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1803,12 +1829,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 835974a4c72..478b7710a68 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -483,6 +483,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -959,6 +965,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1264,6 +1276,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1628,6 +1641,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1697,6 +1716,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1796,12 +1822,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index 02e1e1286a8..0429cc53ab9 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -537,6 +537,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1066,6 +1072,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1311,6 +1323,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1684,6 +1697,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1774,6 +1793,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1855,12 +1881,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 5aa0e6290d9..c7e1fee0b31 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -483,6 +483,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -909,6 +915,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1238,6 +1250,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1603,6 +1616,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1771,12 +1797,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-firewall-report.lock.yml b/.github/workflows/daily-firewall-report.lock.yml index fefe7d0b093..f518ab3fd74 100644 --- a/.github/workflows/daily-firewall-report.lock.yml +++ b/.github/workflows/daily-firewall-report.lock.yml @@ -486,6 +486,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -949,6 +955,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1245,6 +1257,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1615,6 +1628,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1684,6 +1703,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1782,12 +1808,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 12c8374339d..5ab50802f1a 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -494,6 +494,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -905,6 +911,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1249,6 +1261,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1606,6 +1619,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1675,6 +1694,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1774,12 +1800,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index a5a19ada398..0d8facc6839 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -482,6 +482,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -935,6 +941,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1175,6 +1187,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1532,6 +1545,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1601,6 +1620,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1699,12 +1725,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index dd53fd0af8e..976c5ad90a0 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -473,6 +473,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -879,6 +885,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1169,6 +1181,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1534,6 +1547,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1603,6 +1622,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1702,12 +1728,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml index 2027c0a6162..c9ff478f594 100644 --- a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml +++ b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml @@ -432,6 +432,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -786,6 +792,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1048,6 +1060,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1403,6 +1416,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1456,6 +1475,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1599,12 +1625,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-go-test-parallelizer.lock.yml b/.github/workflows/daily-go-test-parallelizer.lock.yml index d7859cc3edc..1282e0ddc41 100644 --- a/.github/workflows/daily-go-test-parallelizer.lock.yml +++ b/.github/workflows/daily-go-test-parallelizer.lock.yml @@ -494,6 +494,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -962,6 +968,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1232,6 +1244,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1617,6 +1630,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1707,6 +1726,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1788,12 +1814,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-go-test-stubs-aider.lock.yml b/.github/workflows/daily-go-test-stubs-aider.lock.yml index 483ba9a7f96..50c2cf595e0 100644 --- a/.github/workflows/daily-go-test-stubs-aider.lock.yml +++ b/.github/workflows/daily-go-test-stubs-aider.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -874,6 +880,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -1122,6 +1134,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1483,6 +1496,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1552,6 +1571,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,12 +1677,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-grader-audit.lock.yml b/.github/workflows/daily-grader-audit.lock.yml index b0e6772a7a4..85b1e9618e0 100644 --- a/.github/workflows/daily-grader-audit.lock.yml +++ b/.github/workflows/daily-grader-audit.lock.yml @@ -467,6 +467,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -887,6 +893,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1229,6 +1241,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1586,6 +1599,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1652,6 +1671,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1737,12 +1763,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 896d31eeebf..fb424f892fd 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -465,6 +465,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -887,6 +893,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1185,6 +1197,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1546,6 +1559,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1615,6 +1634,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1714,12 +1740,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-harness-experiment-proposer.lock.yml b/.github/workflows/daily-harness-experiment-proposer.lock.yml index c81db2a8f0d..7621f1067dc 100644 --- a/.github/workflows/daily-harness-experiment-proposer.lock.yml +++ b/.github/workflows/daily-harness-experiment-proposer.lock.yml @@ -490,6 +490,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -930,6 +936,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1267,6 +1279,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index 9295e81d1bc..dc5bfeceffe 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1014,6 +1020,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1265,6 +1277,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1624,6 +1637,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1693,6 +1712,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1792,12 +1818,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 18ae3382402..9c8972d20dc 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -545,6 +545,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1137,6 +1143,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1441,6 +1453,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1820,6 +1833,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1889,6 +1908,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1987,12 +2013,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 82225c9aaf5..35fba5054b4 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -465,6 +465,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -881,6 +887,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1145,6 +1157,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index 4a7a2112581..abab38d3e02 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -400,6 +400,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -855,6 +861,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1075,6 +1087,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1414,6 +1427,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1504,6 +1523,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1585,12 +1611,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index a7ed6603ebc..678ac2f31f3 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -947,6 +953,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1264,6 +1276,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1632,6 +1645,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1701,6 +1720,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1800,12 +1826,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 3efcb5b777f..f7560c1a748 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -470,6 +470,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -887,6 +893,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1152,6 +1164,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1822,6 +1835,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1891,6 +1910,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1990,12 +2016,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 79507f35a86..31bc8d0660c 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -908,6 +914,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1182,6 +1194,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1531,6 +1544,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1600,6 +1619,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1698,12 +1724,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 952a56f82ff..fed17a282bc 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -476,6 +476,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -954,6 +960,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1186,6 +1198,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1539,6 +1552,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1608,6 +1627,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1706,12 +1732,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 12854e389aa..21c56638bc3 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -546,6 +546,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1092,6 +1098,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1385,6 +1397,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1756,6 +1769,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1825,6 +1844,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1924,12 +1950,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index bdce73016c4..e22196b9a0e 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -969,6 +975,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1202,6 +1214,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1565,6 +1578,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1655,6 +1674,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1736,12 +1762,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 6178688a308..2aa6fe519fb 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -485,6 +485,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1559,6 +1565,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 40 @@ -1822,6 +1834,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2181,6 +2194,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2250,6 +2269,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2348,12 +2374,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-pr-review-cursor.lock.yml b/.github/workflows/daily-pr-review-cursor.lock.yml index 71a05ba5b0f..a5f2b3e9d1c 100644 --- a/.github/workflows/daily-pr-review-cursor.lock.yml +++ b/.github/workflows/daily-pr-review-cursor.lock.yml @@ -468,6 +468,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -844,6 +850,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1129,6 +1141,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1479,6 +1492,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1548,6 +1567,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1646,12 +1672,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-regression-audit-kiro.lock.yml b/.github/workflows/daily-regression-audit-kiro.lock.yml index 31af2f3b98a..d1183e6bfe2 100644 --- a/.github/workflows/daily-regression-audit-kiro.lock.yml +++ b/.github/workflows/daily-regression-audit-kiro.lock.yml @@ -469,6 +469,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -854,6 +860,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1134,6 +1146,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1484,6 +1497,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1553,6 +1572,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,12 +1677,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 0726c35222f..904beb34531 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -477,6 +477,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1593,6 +1599,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1828,6 +1840,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2192,6 +2205,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2282,6 +2301,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2363,12 +2389,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index 881cd3838ac..fd6814b3aee 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -462,6 +462,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -842,6 +848,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -1180,6 +1192,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1526,6 +1539,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1595,6 +1614,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1693,12 +1719,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 12c93c1dd71..222b80eb716 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -566,6 +566,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1061,6 +1067,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1468,6 +1480,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1873,6 +1886,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1939,6 +1958,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2024,12 +2050,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index fba5600ae34..0f9195e9ebc 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -895,6 +901,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 @@ -1147,6 +1159,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1506,6 +1519,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1575,6 +1594,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1674,12 +1700,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index dd2305f0fbf..99b541bd4e7 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -486,6 +486,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -907,6 +913,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1181,6 +1193,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1572,6 +1585,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1641,6 +1660,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1740,12 +1766,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index 20c50cd4a30..fd435ce5c32 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -543,6 +543,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1048,6 +1054,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1395,6 +1407,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1763,6 +1776,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1829,6 +1848,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1914,12 +1940,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index e9bdd8d85a1..99e47b48d01 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -869,6 +875,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1177,6 +1189,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1540,6 +1553,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1606,6 +1625,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1691,12 +1717,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml index 48c8bcf41a8..ffade3a85fc 100644 --- a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml +++ b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml @@ -495,6 +495,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -978,6 +984,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1316,6 +1328,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1703,6 +1716,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1769,6 +1788,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1854,12 +1880,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-schema-audit-cursor.lock.yml b/.github/workflows/daily-schema-audit-cursor.lock.yml index 9d47624fcc5..8411da184a5 100644 --- a/.github/workflows/daily-schema-audit-cursor.lock.yml +++ b/.github/workflows/daily-schema-audit-cursor.lock.yml @@ -467,6 +467,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -852,6 +858,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1132,6 +1144,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1482,6 +1495,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1551,6 +1570,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1649,12 +1675,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index a0593b1f0da..de655ff1fc4 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -464,6 +464,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -825,6 +831,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1099,6 +1111,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1463,6 +1476,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1532,6 +1551,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1631,12 +1657,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index ab126348535..032aa320ab3 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -502,6 +502,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1018,6 +1024,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1322,6 +1334,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1692,6 +1705,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1761,6 +1780,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1859,12 +1885,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index 428002c173c..b9b83c062dc 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -506,6 +506,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -911,6 +917,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -1247,6 +1259,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1603,6 +1616,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1771,12 +1797,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-semgrep-scan.lock.yml b/.github/workflows/daily-semgrep-scan.lock.yml index 5f4baa8541a..8f4b72668c0 100644 --- a/.github/workflows/daily-semgrep-scan.lock.yml +++ b/.github/workflows/daily-semgrep-scan.lock.yml @@ -512,6 +512,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -967,6 +973,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1194,6 +1206,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1558,6 +1571,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1648,6 +1667,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1729,12 +1755,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 76df7fad852..af72e8fa51e 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -871,6 +877,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1185,6 +1197,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1550,6 +1563,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1619,6 +1638,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1718,12 +1744,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-spec-coverage-kiro.lock.yml b/.github/workflows/daily-spec-coverage-kiro.lock.yml index 600c8fcf63d..4d7ced16707 100644 --- a/.github/workflows/daily-spec-coverage-kiro.lock.yml +++ b/.github/workflows/daily-spec-coverage-kiro.lock.yml @@ -468,6 +468,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -853,6 +859,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1132,6 +1144,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1482,6 +1495,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1551,6 +1570,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1649,12 +1675,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-spending-forecast.lock.yml b/.github/workflows/daily-spending-forecast.lock.yml index e4311481faf..b619df06ed0 100644 --- a/.github/workflows/daily-spending-forecast.lock.yml +++ b/.github/workflows/daily-spending-forecast.lock.yml @@ -482,6 +482,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1082,6 +1088,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1349,6 +1361,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1709,6 +1722,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1799,6 +1818,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1880,12 +1906,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-squid-image-scan.lock.yml b/.github/workflows/daily-squid-image-scan.lock.yml index 331ab1e54f3..d023d8abd74 100644 --- a/.github/workflows/daily-squid-image-scan.lock.yml +++ b/.github/workflows/daily-squid-image-scan.lock.yml @@ -449,6 +449,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -990,6 +996,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1268,6 +1280,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1623,6 +1636,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1692,6 +1711,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1791,12 +1817,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-storify.lock.yml b/.github/workflows/daily-storify.lock.yml index 144ead85d14..ab6cbd398a3 100644 --- a/.github/workflows/daily-storify.lock.yml +++ b/.github/workflows/daily-storify.lock.yml @@ -494,6 +494,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1029,6 +1035,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1314,6 +1326,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1686,6 +1699,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1776,6 +1795,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1857,12 +1883,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-syntax-error-quality.lock.yml b/.github/workflows/daily-syntax-error-quality.lock.yml index 3fd6c4134df..369a6363761 100644 --- a/.github/workflows/daily-syntax-error-quality.lock.yml +++ b/.github/workflows/daily-syntax-error-quality.lock.yml @@ -462,6 +462,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -861,6 +867,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1125,6 +1137,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1486,6 +1499,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1555,6 +1574,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1654,12 +1680,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 3aca28a7ec8..68113f8797e 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -462,6 +462,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -906,6 +912,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1314,6 +1326,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1650,6 +1663,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1719,6 +1738,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1818,12 +1844,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-team-status.lock.yml b/.github/workflows/daily-team-status.lock.yml index d674681ea85..525cb0ae148 100644 --- a/.github/workflows/daily-team-status.lock.yml +++ b/.github/workflows/daily-team-status.lock.yml @@ -464,6 +464,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -852,6 +858,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1132,6 +1144,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1485,6 +1498,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1554,6 +1573,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1652,12 +1678,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index c532019a580..de4a6e1464b 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -495,6 +495,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -929,6 +935,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1264,6 +1276,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1617,6 +1630,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1686,6 +1705,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1785,12 +1811,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 7127c93c91e..d2ee026c295 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -459,6 +459,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -945,6 +951,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1358,6 +1370,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1707,6 +1720,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1776,6 +1795,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1875,12 +1901,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-trajectory-grader-implementer.lock.yml b/.github/workflows/daily-trajectory-grader-implementer.lock.yml index fd9847c9f1b..34d7f3c47de 100644 --- a/.github/workflows/daily-trajectory-grader-implementer.lock.yml +++ b/.github/workflows/daily-trajectory-grader-implementer.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -888,6 +894,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1211,6 +1223,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1591,6 +1604,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1660,6 +1679,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1758,12 +1784,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index c9f6f43a4fc..1d618b68d77 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -470,6 +470,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -863,6 +869,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1169,6 +1181,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1524,6 +1537,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1590,6 +1609,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1675,12 +1701,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-windows-defender-scan.lock.yml b/.github/workflows/daily-windows-defender-scan.lock.yml index 58a31c88ce3..c78d9a268e0 100644 --- a/.github/workflows/daily-windows-defender-scan.lock.yml +++ b/.github/workflows/daily-windows-defender-scan.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -967,6 +973,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1202,6 +1214,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1995,6 +2008,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2085,6 +2104,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2166,12 +2192,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml index 69e4528a690..239e58f36e7 100644 --- a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml +++ b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml @@ -456,6 +456,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -885,6 +891,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1120,6 +1132,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1474,6 +1487,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1564,6 +1583,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1645,12 +1671,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-workflow-updater.lock.yml b/.github/workflows/daily-workflow-updater.lock.yml index 66573aa608e..7864ebfe831 100644 --- a/.github/workflows/daily-workflow-updater.lock.yml +++ b/.github/workflows/daily-workflow-updater.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -873,6 +879,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1147,6 +1159,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1535,6 +1548,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1604,6 +1623,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1703,12 +1729,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/daily-yamllint-fixer.lock.yml b/.github/workflows/daily-yamllint-fixer.lock.yml index 6d9ba362881..6356f77c317 100644 --- a/.github/workflows/daily-yamllint-fixer.lock.yml +++ b/.github/workflows/daily-yamllint-fixer.lock.yml @@ -499,6 +499,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -901,6 +907,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1209,6 +1221,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1592,6 +1605,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1658,6 +1677,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1743,12 +1769,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index c40c8356e60..fd60710997c 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -536,6 +536,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) @@ -1227,6 +1233,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1544,6 +1556,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1923,6 +1936,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1992,6 +2011,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2090,12 +2116,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index f10f9c73b86..cdd068597ea 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -508,6 +508,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -941,6 +947,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1223,6 +1235,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1596,6 +1609,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1665,6 +1684,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1764,12 +1790,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index 7cdcd886960..61edcb004a5 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -561,6 +561,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1637,6 +1643,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -2024,6 +2036,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2406,6 +2419,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2472,6 +2491,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2557,12 +2583,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/deepsec-security-scan.lock.yml b/.github/workflows/deepsec-security-scan.lock.yml index 7ebdcca2aa2..827865a2cad 100644 --- a/.github/workflows/deepsec-security-scan.lock.yml +++ b/.github/workflows/deepsec-security-scan.lock.yml @@ -499,6 +499,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory @@ -898,6 +904,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1205,6 +1217,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1559,6 +1572,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1625,6 +1644,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1710,12 +1736,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index 7a16e91b166..ae911087497 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -479,6 +479,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -902,6 +908,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1233,6 +1245,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1603,6 +1616,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1771,12 +1797,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index a40aaa6f429..f2ba272c4f9 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -565,6 +565,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1025,6 +1031,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1315,6 +1327,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1721,6 +1734,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1790,6 +1809,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1888,12 +1914,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dependabot-go-checker.lock.yml b/.github/workflows/dependabot-go-checker.lock.yml index aa89ae5972b..e07c2a5d3ab 100644 --- a/.github/workflows/dependabot-go-checker.lock.yml +++ b/.github/workflows/dependabot-go-checker.lock.yml @@ -518,6 +518,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1024,6 +1030,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1251,6 +1263,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1612,6 +1625,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1702,6 +1721,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1783,12 +1809,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index 338327e351f..226c0857f90 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -482,6 +482,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -854,6 +860,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1128,6 +1140,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1484,6 +1497,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1553,6 +1572,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,12 +1677,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index d794b21ed7c..5ad70b578ca 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -557,6 +557,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -976,6 +982,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 @@ -1199,6 +1211,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1571,6 +1584,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1640,6 +1659,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1738,12 +1764,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/designer-drift-audit.lock.yml b/.github/workflows/designer-drift-audit.lock.yml index 2e2f5b2f1e4..65766d9e88a 100644 --- a/.github/workflows/designer-drift-audit.lock.yml +++ b/.github/workflows/designer-drift-audit.lock.yml @@ -460,6 +460,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -896,6 +902,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1133,6 +1145,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1474,6 +1487,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1564,6 +1583,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1645,12 +1671,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index c42d59c7ceb..f199de52b7e 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -493,6 +493,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -998,6 +1004,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1337,6 +1349,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1705,6 +1718,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1771,6 +1790,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1856,12 +1882,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dev-hawk.lock.yml b/.github/workflows/dev-hawk.lock.yml index 0a3a623c431..eaffcbc738d 100644 --- a/.github/workflows/dev-hawk.lock.yml +++ b/.github/workflows/dev-hawk.lock.yml @@ -503,6 +503,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -953,6 +959,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1233,6 +1245,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1590,6 +1603,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1659,6 +1678,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1758,12 +1784,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dev.lock.yml b/.github/workflows/dev.lock.yml index 41de3e3738f..3c3e31d9cbe 100644 --- a/.github/workflows/dev.lock.yml +++ b/.github/workflows/dev.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -987,6 +993,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1215,6 +1227,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1591,6 +1604,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1681,6 +1700,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1762,12 +1788,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index 9eb73d696d7..cb5e6ddddfa 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -523,6 +523,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1017,6 +1023,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1396,6 +1408,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1790,6 +1803,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1856,6 +1875,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1941,12 +1967,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/dictation-prompt.lock.yml b/.github/workflows/dictation-prompt.lock.yml index 9fe0317a11a..f79f63b391a 100644 --- a/.github/workflows/dictation-prompt.lock.yml +++ b/.github/workflows/dictation-prompt.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -874,6 +880,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1148,6 +1160,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1530,6 +1543,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1599,6 +1618,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1698,12 +1724,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index f6258d21b15..5e08ddee968 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -469,6 +469,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -886,6 +892,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1169,6 +1181,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1528,6 +1541,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1597,6 +1616,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1696,12 +1722,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/draft-pr-cleanup.lock.yml b/.github/workflows/draft-pr-cleanup.lock.yml index 1912d74c7b0..b57ed9a9069 100644 --- a/.github/workflows/draft-pr-cleanup.lock.yml +++ b/.github/workflows/draft-pr-cleanup.lock.yml @@ -459,6 +459,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -884,6 +890,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1163,6 +1175,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1520,6 +1533,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1589,6 +1608,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1688,12 +1714,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 266ef8c4605..887ac12ccde 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -875,6 +881,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 @@ -1094,6 +1106,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1438,6 +1451,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1507,6 +1526,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1606,12 +1632,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/eslint-miner.lock.yml b/.github/workflows/eslint-miner.lock.yml index 0e47382509d..12482a78857 100644 --- a/.github/workflows/eslint-miner.lock.yml +++ b/.github/workflows/eslint-miner.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -909,6 +915,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1201,6 +1213,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1593,6 +1606,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1662,6 +1681,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1761,12 +1787,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index 42d6eacf566..b5043e98b18 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1097,6 +1103,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1324,6 +1336,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1689,6 +1702,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1779,6 +1798,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1860,12 +1886,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index 5f680aced64..341a4131827 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -483,6 +483,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -901,6 +907,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1258,6 +1270,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1626,6 +1639,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1692,6 +1711,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1777,12 +1803,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/evoskill-evolver.lock.yml b/.github/workflows/evoskill-evolver.lock.yml index 72934db7680..aa59bebebaa 100644 --- a/.github/workflows/evoskill-evolver.lock.yml +++ b/.github/workflows/evoskill-evolver.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -897,6 +903,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1211,6 +1223,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1603,6 +1616,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1771,12 +1797,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/example-failure-category-filter.lock.yml b/.github/workflows/example-failure-category-filter.lock.yml index 647d0d25a6f..3712fe7dc43 100644 --- a/.github/workflows/example-failure-category-filter.lock.yml +++ b/.github/workflows/example-failure-category-filter.lock.yml @@ -454,6 +454,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -909,6 +915,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1136,6 +1148,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1478,6 +1491,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1568,6 +1587,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1649,12 +1675,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/example-permissions-warning.lock.yml b/.github/workflows/example-permissions-warning.lock.yml index 39bcce72361..2b94c90a047 100644 --- a/.github/workflows/example-permissions-warning.lock.yml +++ b/.github/workflows/example-permissions-warning.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -847,6 +853,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1062,6 +1074,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index dfa56d4f2ed..8cf216ad43e 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -475,6 +475,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -912,6 +918,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1219,6 +1231,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1563,6 +1576,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1629,6 +1648,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1714,12 +1740,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/feature-grower.lock.yml b/.github/workflows/feature-grower.lock.yml index fd4fcdf01ae..ceec98db5a1 100644 --- a/.github/workflows/feature-grower.lock.yml +++ b/.github/workflows/feature-grower.lock.yml @@ -464,6 +464,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -941,6 +947,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1184,6 +1196,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1529,6 +1542,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1619,6 +1638,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1700,12 +1726,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/firewall-escape.lock.yml b/.github/workflows/firewall-escape.lock.yml index 663ae3f6088..520e0b63c47 100644 --- a/.github/workflows/firewall-escape.lock.yml +++ b/.github/workflows/firewall-escape.lock.yml @@ -514,6 +514,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -911,6 +917,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1219,6 +1231,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1580,6 +1593,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1649,6 +1668,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1748,12 +1774,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/firewall.lock.yml b/.github/workflows/firewall.lock.yml index 3c97b1d41c6..9f799184591 100644 --- a/.github/workflows/firewall.lock.yml +++ b/.github/workflows/firewall.lock.yml @@ -459,6 +459,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -772,6 +778,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1025,6 +1037,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/front-page-copy-guard.lock.yml b/.github/workflows/front-page-copy-guard.lock.yml index e16a5d55784..cf2697d8cb0 100644 --- a/.github/workflows/front-page-copy-guard.lock.yml +++ b/.github/workflows/front-page-copy-guard.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -912,6 +918,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1147,6 +1159,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1489,6 +1502,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1579,6 +1598,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1660,12 +1686,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/functional-pragmatist.lock.yml b/.github/workflows/functional-pragmatist.lock.yml index dce34f499ab..4089de019de 100644 --- a/.github/workflows/functional-pragmatist.lock.yml +++ b/.github/workflows/functional-pragmatist.lock.yml @@ -492,6 +492,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -967,6 +973,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1194,6 +1206,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1582,6 +1595,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1753,12 +1779,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 32329ed0a41..a1259dae074 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -495,6 +495,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1193,6 +1199,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1546,6 +1558,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1896,6 +1909,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1962,6 +1981,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2047,12 +2073,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 0a538cefe8c..152e6879f0a 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -504,6 +504,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -957,6 +963,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1285,6 +1297,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1661,6 +1674,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1727,6 +1746,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1812,12 +1838,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 8b97691f7b1..1fd32e3dc37 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -908,6 +914,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1133,6 +1145,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1478,6 +1491,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1568,6 +1587,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1649,12 +1675,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index 5fe436fa217..5b472175f21 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -524,6 +524,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1024,6 +1030,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1312,6 +1324,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1705,6 +1718,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1774,6 +1793,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1872,12 +1898,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index fba9a16cd7b..a76b70675ba 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -492,6 +492,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -935,6 +941,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1298,6 +1310,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1649,6 +1662,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1715,6 +1734,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1800,12 +1826,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/go-logger.lock.yml b/.github/workflows/go-logger.lock.yml index 9776013d0f8..ae93cd6ecd1 100644 --- a/.github/workflows/go-logger.lock.yml +++ b/.github/workflows/go-logger.lock.yml @@ -505,6 +505,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -931,6 +937,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1295,6 +1307,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1681,6 +1694,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1747,6 +1766,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1832,12 +1858,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/go-pattern-detector.lock.yml b/.github/workflows/go-pattern-detector.lock.yml index d539e8b87ab..1d1bb8c46eb 100644 --- a/.github/workflows/go-pattern-detector.lock.yml +++ b/.github/workflows/go-pattern-detector.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -890,6 +896,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1197,6 +1209,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1582,6 +1595,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1648,6 +1667,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1733,12 +1759,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/gpclean.lock.yml b/.github/workflows/gpclean.lock.yml index ee5e78c238b..0f2b30a3213 100644 --- a/.github/workflows/gpclean.lock.yml +++ b/.github/workflows/gpclean.lock.yml @@ -529,6 +529,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1005,6 +1011,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1250,6 +1262,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1615,6 +1628,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1705,6 +1724,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1786,12 +1812,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index 383743c0980..62d55943c05 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -535,6 +535,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1058,6 +1064,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1290,6 +1302,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1659,6 +1672,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1749,6 +1768,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1830,12 +1856,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/hippo-embed.lock.yml b/.github/workflows/hippo-embed.lock.yml index 68dbaab3761..7d1fd22037f 100644 --- a/.github/workflows/hippo-embed.lock.yml +++ b/.github/workflows/hippo-embed.lock.yml @@ -465,6 +465,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) @@ -909,6 +915,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 60 @@ -1135,6 +1147,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/hourly-ci-cleaner.lock.yml b/.github/workflows/hourly-ci-cleaner.lock.yml index 3a7b82c8ed0..118db5fdee1 100644 --- a/.github/workflows/hourly-ci-cleaner.lock.yml +++ b/.github/workflows/hourly-ci-cleaner.lock.yml @@ -509,6 +509,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -935,6 +941,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1243,6 +1255,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1688,6 +1701,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1754,6 +1773,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1839,12 +1865,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index ec9178a52ef..bc49d1dac4c 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -540,6 +540,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1056,6 +1062,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1321,6 +1333,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1671,6 +1684,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1740,6 +1759,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1839,12 +1865,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/instructions-janitor.lock.yml b/.github/workflows/instructions-janitor.lock.yml index 213f4134522..bab620d4251 100644 --- a/.github/workflows/instructions-janitor.lock.yml +++ b/.github/workflows/instructions-janitor.lock.yml @@ -499,6 +499,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -924,6 +930,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1284,6 +1296,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1657,6 +1670,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1723,6 +1742,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1808,12 +1834,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/issue-arborist.lock.yml b/.github/workflows/issue-arborist.lock.yml index d402841743d..43e812d11da 100644 --- a/.github/workflows/issue-arborist.lock.yml +++ b/.github/workflows/issue-arborist.lock.yml @@ -514,6 +514,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1079,6 +1085,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1306,6 +1318,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1673,6 +1686,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1763,6 +1782,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1844,12 +1870,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index cfd997defa4..43cce76869b 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -973,6 +973,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1399,6 +1405,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1618,6 +1630,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1968,6 +1981,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2037,6 +2056,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2136,12 +2162,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/issue-triage-agent.lock.yml b/.github/workflows/issue-triage-agent.lock.yml index 5e5ad72c3c6..2ddb8bde116 100644 --- a/.github/workflows/issue-triage-agent.lock.yml +++ b/.github/workflows/issue-triage-agent.lock.yml @@ -458,6 +458,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1103,6 +1109,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1328,6 +1340,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1684,6 +1697,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1774,6 +1793,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1855,12 +1881,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/jsweep.lock.yml b/.github/workflows/jsweep.lock.yml index 4c484ca0399..84db655c3b6 100644 --- a/.github/workflows/jsweep.lock.yml +++ b/.github/workflows/jsweep.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -915,6 +921,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1197,6 +1209,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1554,6 +1567,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1623,6 +1642,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1721,12 +1747,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/layout-spec-maintainer.lock.yml b/.github/workflows/layout-spec-maintainer.lock.yml index 3fe8cf437cb..7022d9e503f 100644 --- a/.github/workflows/layout-spec-maintainer.lock.yml +++ b/.github/workflows/layout-spec-maintainer.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -891,6 +897,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1201,6 +1213,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1578,6 +1591,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1647,6 +1666,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1745,12 +1771,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/lint-monster.lock.yml b/.github/workflows/lint-monster.lock.yml index 2e4e9d40fcf..d868622dbf0 100644 --- a/.github/workflows/lint-monster.lock.yml +++ b/.github/workflows/lint-monster.lock.yml @@ -470,6 +470,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1091,6 +1097,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1318,6 +1330,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1670,6 +1683,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1760,6 +1779,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1841,12 +1867,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index 58e97000d41..5e3125df9ad 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -505,6 +505,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -972,6 +978,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1255,6 +1267,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1634,6 +1647,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1703,6 +1722,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1802,12 +1828,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 991d48a7fe8..245a33403a6 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -479,6 +479,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -872,6 +878,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1200,6 +1212,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1548,6 +1561,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1614,6 +1633,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1699,12 +1725,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 7cacb9d55c6..f67e7952385 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -642,6 +642,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1158,6 +1164,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1424,6 +1436,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1797,6 +1810,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1866,6 +1885,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1965,12 +1991,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 91866e286fd..95b456aff9a 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -517,6 +517,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1186,6 +1192,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1509,6 +1521,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1860,6 +1873,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1929,6 +1948,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2027,12 +2053,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/mergefest.lock.yml b/.github/workflows/mergefest.lock.yml index ce05ca15ea5..f9222ccd747 100644 --- a/.github/workflows/mergefest.lock.yml +++ b/.github/workflows/mergefest.lock.yml @@ -527,6 +527,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -885,6 +891,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1198,6 +1210,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1567,6 +1580,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1636,6 +1655,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1734,12 +1760,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/metrics-collector.lock.yml b/.github/workflows/metrics-collector.lock.yml index 6a45fbf62af..7e2cd8408df 100644 --- a/.github/workflows/metrics-collector.lock.yml +++ b/.github/workflows/metrics-collector.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1033,6 +1039,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1278,6 +1290,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1624,6 +1637,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1714,6 +1733,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1795,12 +1821,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/necromancer.lock.yml b/.github/workflows/necromancer.lock.yml index 53698294738..8d05e041896 100644 --- a/.github/workflows/necromancer.lock.yml +++ b/.github/workflows/necromancer.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -929,6 +935,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 25 @@ -1149,6 +1161,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1521,6 +1534,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1590,6 +1609,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1689,12 +1715,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/notion-issue-summary.lock.yml b/.github/workflows/notion-issue-summary.lock.yml index 74c89d9f828..6ddaf8ec90d 100644 --- a/.github/workflows/notion-issue-summary.lock.yml +++ b/.github/workflows/notion-issue-summary.lock.yml @@ -473,6 +473,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -854,6 +860,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 @@ -1069,6 +1081,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/objective-impact-report.lock.yml b/.github/workflows/objective-impact-report.lock.yml index 2a936102819..9c05a67b9aa 100644 --- a/.github/workflows/objective-impact-report.lock.yml +++ b/.github/workflows/objective-impact-report.lock.yml @@ -460,6 +460,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -906,6 +912,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1194,6 +1206,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1537,6 +1550,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1606,6 +1625,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1704,12 +1730,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/org-health-report.lock.yml b/.github/workflows/org-health-report.lock.yml index 5479e132878..7fb81eb3f51 100644 --- a/.github/workflows/org-health-report.lock.yml +++ b/.github/workflows/org-health-report.lock.yml @@ -490,6 +490,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -931,6 +937,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1244,6 +1256,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1597,6 +1610,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1666,6 +1685,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1764,12 +1790,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/outcome-collector.lock.yml b/.github/workflows/outcome-collector.lock.yml index df0c74de645..bda286da12e 100644 --- a/.github/workflows/outcome-collector.lock.yml +++ b/.github/workflows/outcome-collector.lock.yml @@ -479,6 +479,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -936,6 +942,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1190,6 +1202,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1542,6 +1555,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1632,6 +1651,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1713,12 +1739,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pdf-summary.lock.yml b/.github/workflows/pdf-summary.lock.yml index 31e9ee7f3d8..076fc3af820 100644 --- a/.github/workflows/pdf-summary.lock.yml +++ b/.github/workflows/pdf-summary.lock.yml @@ -563,6 +563,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1064,6 +1070,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1309,6 +1321,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1682,6 +1695,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1772,6 +1791,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1853,12 +1879,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/plan.lock.yml b/.github/workflows/plan.lock.yml index 03518e46b73..01351201264 100644 --- a/.github/workflows/plan.lock.yml +++ b/.github/workflows/plan.lock.yml @@ -579,6 +579,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1002,6 +1008,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1282,6 +1294,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1670,6 +1683,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1739,6 +1758,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1837,12 +1863,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/poem-bot.lock.yml b/.github/workflows/poem-bot.lock.yml index 41e7699d241..f3dcafe2d33 100644 --- a/.github/workflows/poem-bot.lock.yml +++ b/.github/workflows/poem-bot.lock.yml @@ -553,6 +553,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1353,6 +1359,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1610,6 +1622,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1997,6 +2010,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2087,6 +2106,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2168,12 +2194,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index d1f7faa8ad8..42b0e93c96f 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -573,6 +573,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1114,6 +1120,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1350,6 +1362,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1720,6 +1733,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1810,6 +1829,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1891,12 +1917,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 6375d683cd1..4b65f06bd76 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -490,6 +490,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1009,6 +1015,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1372,6 +1384,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1727,6 +1740,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1793,6 +1812,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1878,12 +1904,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index af275cb958e..5bd19b349c6 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -542,6 +542,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1068,6 +1074,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1354,6 +1366,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1738,6 +1751,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1807,6 +1826,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1906,12 +1932,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index 804bf51e79d..5f69969ed30 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -873,6 +879,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1164,6 +1176,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1508,6 +1521,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1577,6 +1596,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1675,12 +1701,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index ad83a7205b0..f94a70501c9 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -537,6 +537,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1025,6 +1031,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1295,6 +1307,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1669,6 +1682,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1738,6 +1757,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1836,12 +1862,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index 0c22e2d6ffd..5db3e5fc96d 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -579,6 +579,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1403,6 +1409,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 25 @@ -1662,6 +1674,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2083,6 +2096,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2152,6 +2171,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2251,12 +2277,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 306b195efe8..d65940bc07b 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -486,6 +486,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1331,6 +1337,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1622,6 +1634,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1988,6 +2001,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2057,6 +2076,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2155,12 +2181,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index fe5f843d14d..150f4dce5d7 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -501,6 +501,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1027,6 +1033,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1368,6 +1380,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1717,6 +1730,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1783,6 +1802,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1868,12 +1894,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index ae0386e9511..f49cf5a3468 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -510,6 +510,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1093,6 +1099,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 35 @@ -1362,6 +1374,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1749,6 +1762,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1839,6 +1858,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1920,12 +1946,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index f6ce2bea6e1..652476c7094 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1073,6 +1079,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1338,6 +1350,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1687,6 +1700,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1777,6 +1796,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1858,12 +1884,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index 7be9e6ec28e..6c751fdf7f9 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -587,6 +587,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1108,6 +1114,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1383,6 +1395,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1780,6 +1793,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1849,6 +1868,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1947,12 +1973,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index 2d75dec66c0..b86272760b5 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -472,6 +472,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -858,6 +864,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 @@ -1095,6 +1107,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1437,6 +1450,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1506,6 +1525,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1605,12 +1631,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index 3b5734a564e..04aa94b62c8 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1102,6 +1108,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1357,6 +1369,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1745,6 +1758,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1814,6 +1833,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1912,12 +1938,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/release.lock.yml b/.github/workflows/release.lock.yml index 9b5c057ecd1..6272341abf5 100644 --- a/.github/workflows/release.lock.yml +++ b/.github/workflows/release.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -872,6 +878,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1150,6 +1162,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index 8dded878d9a..b43ade637f8 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -948,6 +954,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1193,6 +1205,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1556,6 +1569,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1646,6 +1665,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1727,12 +1753,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/repo-tree-map.lock.yml b/.github/workflows/repo-tree-map.lock.yml index cf261887dbf..f2306150f02 100644 --- a/.github/workflows/repo-tree-map.lock.yml +++ b/.github/workflows/repo-tree-map.lock.yml @@ -449,6 +449,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -808,6 +814,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 @@ -1027,6 +1039,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1361,6 +1374,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1430,6 +1449,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1529,12 +1555,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index f3605f7dab9..f02834290b9 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -867,6 +873,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1150,6 +1162,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1500,6 +1513,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1569,6 +1588,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1667,12 +1693,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/research.lock.yml b/.github/workflows/research.lock.yml index 0ccb0cee98e..a42cb741da0 100644 --- a/.github/workflows/research.lock.yml +++ b/.github/workflows/research.lock.yml @@ -457,6 +457,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -838,6 +844,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 @@ -1058,6 +1070,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1405,6 +1418,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1474,6 +1493,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1573,12 +1599,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ruflo-backed-task.lock.yml b/.github/workflows/ruflo-backed-task.lock.yml index ab3211f61b4..62c54de7094 100644 --- a/.github/workflows/ruflo-backed-task.lock.yml +++ b/.github/workflows/ruflo-backed-task.lock.yml @@ -551,6 +551,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1061,6 +1067,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1380,6 +1392,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1773,6 +1786,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1839,6 +1858,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1924,12 +1950,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index edbbe398bc6..20343572f0e 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -488,6 +488,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -954,6 +960,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1301,6 +1313,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1649,6 +1662,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1715,6 +1734,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1800,12 +1826,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index 24091120208..866283f0496 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -482,6 +482,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -945,6 +951,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1186,6 +1198,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1534,6 +1547,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1624,6 +1643,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1705,12 +1731,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/schema-feature-coverage.lock.yml b/.github/workflows/schema-feature-coverage.lock.yml index f626dc97477..8fe9a4124aa 100644 --- a/.github/workflows/schema-feature-coverage.lock.yml +++ b/.github/workflows/schema-feature-coverage.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -946,6 +952,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1172,6 +1184,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1517,6 +1530,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1607,6 +1626,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1688,12 +1714,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/scout.lock.yml b/.github/workflows/scout.lock.yml index 225af3ac9f3..89c04edfcda 100644 --- a/.github/workflows/scout.lock.yml +++ b/.github/workflows/scout.lock.yml @@ -576,6 +576,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1046,6 +1052,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1405,6 +1417,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1777,6 +1790,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1843,6 +1862,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1928,12 +1954,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/security-compliance.lock.yml b/.github/workflows/security-compliance.lock.yml index 2b9503a204c..fdc2b6dcfdf 100644 --- a/.github/workflows/security-compliance.lock.yml +++ b/.github/workflows/security-compliance.lock.yml @@ -497,6 +497,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -887,6 +893,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1183,6 +1195,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1531,6 +1544,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1600,6 +1619,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1698,12 +1724,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index f90b55bb15d..83020d8a7ec 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -535,6 +535,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1337,6 +1343,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1568,6 +1580,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1950,6 +1963,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2040,6 +2059,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2121,12 +2147,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index e5a0d63bf18..9d18b9d9a7c 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -477,6 +477,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -941,6 +947,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1270,6 +1282,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1611,6 +1624,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1677,6 +1696,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1762,12 +1788,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 8e07f1e929a..9b2f42d5ca7 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -492,6 +492,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -949,6 +955,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1312,6 +1324,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1667,6 +1680,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1733,6 +1752,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1818,12 +1844,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/sighthound-security-scan.lock.yml b/.github/workflows/sighthound-security-scan.lock.yml index 716dd16220f..44213ee13e4 100644 --- a/.github/workflows/sighthound-security-scan.lock.yml +++ b/.github/workflows/sighthound-security-scan.lock.yml @@ -458,6 +458,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -919,6 +925,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} @@ -1144,6 +1156,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1486,6 +1499,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1576,6 +1595,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1657,12 +1683,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index 93ef936b5fb..c34dce6a717 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -550,6 +550,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1060,6 +1066,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1296,6 +1308,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1666,6 +1679,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1756,6 +1775,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1837,12 +1863,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 0655bd4c145..c758b74faea 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -524,6 +524,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -988,6 +994,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1309,6 +1321,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1690,6 +1703,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1759,6 +1778,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1857,12 +1883,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-agent-all-merged.lock.yml b/.github/workflows/smoke-agent-all-merged.lock.yml index a80fa67e48d..e1c5a6dfe43 100644 --- a/.github/workflows/smoke-agent-all-merged.lock.yml +++ b/.github/workflows/smoke-agent-all-merged.lock.yml @@ -536,6 +536,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -936,6 +942,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1243,6 +1255,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1611,6 +1624,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1664,6 +1683,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1799,12 +1825,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-agent-all-none.lock.yml b/.github/workflows/smoke-agent-all-none.lock.yml index 6dac3051842..bc98b2d5840 100644 --- a/.github/workflows/smoke-agent-all-none.lock.yml +++ b/.github/workflows/smoke-agent-all-none.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -934,6 +940,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1238,6 +1250,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1606,6 +1619,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1659,6 +1678,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1794,12 +1820,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-agent-public-approved.lock.yml b/.github/workflows/smoke-agent-public-approved.lock.yml index 2a416f164fe..d942713114c 100644 --- a/.github/workflows/smoke-agent-public-approved.lock.yml +++ b/.github/workflows/smoke-agent-public-approved.lock.yml @@ -539,6 +539,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -985,6 +991,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1292,6 +1304,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1663,6 +1676,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1716,6 +1735,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1851,12 +1877,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-agent-public-none.lock.yml b/.github/workflows/smoke-agent-public-none.lock.yml index f178dbb2167..86ec59fb9d0 100644 --- a/.github/workflows/smoke-agent-public-none.lock.yml +++ b/.github/workflows/smoke-agent-public-none.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -934,6 +940,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1238,6 +1250,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1606,6 +1619,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1659,6 +1678,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1794,12 +1820,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-agent-scoped-approved.lock.yml b/.github/workflows/smoke-agent-scoped-approved.lock.yml index 5b2b0eefd61..a28ec44b4c8 100644 --- a/.github/workflows/smoke-agent-scoped-approved.lock.yml +++ b/.github/workflows/smoke-agent-scoped-approved.lock.yml @@ -541,6 +541,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -972,6 +978,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1303,6 +1315,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1671,6 +1684,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1724,6 +1743,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1859,12 +1885,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-aider.lock.yml b/.github/workflows/smoke-aider.lock.yml index d5e6e8510fb..3f94bca1411 100644 --- a/.github/workflows/smoke-aider.lock.yml +++ b/.github/workflows/smoke-aider.lock.yml @@ -524,6 +524,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -963,6 +969,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -1212,6 +1224,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1564,6 +1577,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1617,6 +1636,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1759,12 +1785,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-call-workflow.lock.yml b/.github/workflows/smoke-call-workflow.lock.yml index c0a91aa599a..286b10da50f 100644 --- a/.github/workflows/smoke-call-workflow.lock.yml +++ b/.github/workflows/smoke-call-workflow.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -990,6 +996,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1218,6 +1230,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1607,6 +1620,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1658,6 +1677,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1868,12 +1894,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml index 90297fb7127..ffbeb84798e 100644 --- a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml +++ b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml @@ -541,6 +541,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -927,6 +933,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1205,6 +1217,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1573,6 +1586,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1626,6 +1645,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1768,12 +1794,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-ci.lock.yml b/.github/workflows/smoke-ci.lock.yml index 8624166123e..8246497f988 100644 --- a/.github/workflows/smoke-ci.lock.yml +++ b/.github/workflows/smoke-ci.lock.yml @@ -529,6 +529,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1451,6 +1457,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/.github/workflows/smoke-claude-on-copilot.lock.yml b/.github/workflows/smoke-claude-on-copilot.lock.yml index f8425cd24d3..5a97ea8aa64 100644 --- a/.github/workflows/smoke-claude-on-copilot.lock.yml +++ b/.github/workflows/smoke-claude-on-copilot.lock.yml @@ -526,6 +526,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -900,6 +906,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1210,6 +1222,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1574,6 +1587,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1640,6 +1659,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1726,12 +1752,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml index a458ad5223b..fe86fc01c8d 100644 --- a/.github/workflows/smoke-claude.lock.yml +++ b/.github/workflows/smoke-claude.lock.yml @@ -577,6 +577,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1590,6 +1596,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1948,6 +1960,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2392,6 +2405,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2445,6 +2464,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2580,12 +2606,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index 2c897cffb57..c65e601c7cf 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -571,6 +571,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1341,6 +1347,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 @@ -1603,6 +1615,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2072,6 +2085,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2123,6 +2142,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2333,12 +2359,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index 2b43a4c8adb..6ab1c156dfc 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -639,6 +639,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -2201,6 +2207,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2513,6 +2525,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2980,6 +2993,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -3033,6 +3052,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3177,12 +3203,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index f4424e010b1..1ec9483025b 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -646,6 +646,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - id: azure-oidc @@ -2217,6 +2223,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2531,6 +2543,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -3001,6 +3014,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -3054,6 +3073,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3201,12 +3227,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index 3286c8e8750..cb2cb6aa86e 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -573,6 +573,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1965,6 +1971,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2264,6 +2276,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2709,6 +2722,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2762,6 +2781,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2904,12 +2930,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-auto.lock.yml b/.github/workflows/smoke-copilot-auto.lock.yml index 369d16713ca..a4cc4eebca4 100644 --- a/.github/workflows/smoke-copilot-auto.lock.yml +++ b/.github/workflows/smoke-copilot-auto.lock.yml @@ -516,6 +516,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -890,6 +896,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1156,6 +1168,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1521,6 +1534,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1574,6 +1593,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1717,12 +1743,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-mai.lock.yml b/.github/workflows/smoke-copilot-mai.lock.yml index da964f52057..ee7256f3857 100644 --- a/.github/workflows/smoke-copilot-mai.lock.yml +++ b/.github/workflows/smoke-copilot-mai.lock.yml @@ -552,6 +552,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -965,6 +971,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1232,6 +1244,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1598,6 +1611,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1651,6 +1670,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1793,12 +1819,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-sdk.lock.yml b/.github/workflows/smoke-copilot-sdk.lock.yml index f0d85330c8a..db86a0019db 100644 --- a/.github/workflows/smoke-copilot-sdk.lock.yml +++ b/.github/workflows/smoke-copilot-sdk.lock.yml @@ -549,6 +549,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -936,6 +942,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1202,6 +1214,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1567,6 +1580,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1620,6 +1639,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1762,12 +1788,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-small.lock.yml b/.github/workflows/smoke-copilot-small.lock.yml index 8e6836db20e..72d70502431 100644 --- a/.github/workflows/smoke-copilot-small.lock.yml +++ b/.github/workflows/smoke-copilot-small.lock.yml @@ -552,6 +552,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -963,6 +969,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1228,6 +1240,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1593,6 +1606,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1646,6 +1665,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1788,12 +1814,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot-sub-agents.lock.yml b/.github/workflows/smoke-copilot-sub-agents.lock.yml index 30e0f6f4ec3..f3a71f72d10 100644 --- a/.github/workflows/smoke-copilot-sub-agents.lock.yml +++ b/.github/workflows/smoke-copilot-sub-agents.lock.yml @@ -503,6 +503,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -890,6 +896,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1154,6 +1166,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1516,6 +1529,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1569,6 +1588,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1712,12 +1738,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index d389a31d4fd..15a6a1b0ef8 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -647,6 +647,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -2224,6 +2230,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2544,6 +2556,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -3013,6 +3026,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -3066,6 +3085,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3208,12 +3234,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-create-cross-repo-pr.lock.yml b/.github/workflows/smoke-create-cross-repo-pr.lock.yml index ece620e7ba8..6a4052bd2db 100644 --- a/.github/workflows/smoke-create-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-create-cross-repo-pr.lock.yml @@ -537,6 +537,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1044,6 +1050,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1301,6 +1313,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1671,6 +1684,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1724,6 +1743,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1867,12 +1893,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 2ed9061f1f8..8318e86d538 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1020,6 +1026,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Crush Config run: | umask 077 @@ -1488,6 +1500,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1907,6 +1920,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1960,6 +1979,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2102,12 +2128,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index ec318ea1fe8..27c0d2826ad 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -538,6 +538,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1018,6 +1024,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Cursor harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1369,6 +1381,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1786,6 +1799,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1839,6 +1858,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1981,12 +2007,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index be97b30cc23..a1c57c778b1 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -534,6 +534,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -965,6 +971,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write DeepSeek Harness harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1278,6 +1290,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1697,6 +1710,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1750,6 +1769,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1892,12 +1918,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-drive.lock.yml b/.github/workflows/smoke-drive.lock.yml index 5c026d3cbc3..8fa4d9b3f90 100644 --- a/.github/workflows/smoke-drive.lock.yml +++ b/.github/workflows/smoke-drive.lock.yml @@ -541,6 +541,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1083,6 +1089,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1344,6 +1356,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1709,6 +1722,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1760,6 +1779,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1970,12 +1996,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index 9445ab2bd04..b00193b03e0 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -596,6 +596,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1079,6 +1085,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Gemini Config run: | mkdir -p "$GITHUB_WORKSPACE/.gemini" @@ -1330,6 +1342,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/gemini-client-error-*.json /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1778,6 +1791,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1847,6 +1866,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1945,12 +1971,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-github-claude.lock.yml b/.github/workflows/smoke-github-claude.lock.yml index 7405277e035..0ebb63c8eae 100644 --- a/.github/workflows/smoke-github-claude.lock.yml +++ b/.github/workflows/smoke-github-claude.lock.yml @@ -526,6 +526,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -900,6 +906,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1210,6 +1222,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1574,6 +1587,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1640,6 +1659,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1726,12 +1752,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 47d8ecc65f7..5fa07774bf4 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -533,6 +533,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1047,6 +1053,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1460,6 +1472,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1879,6 +1892,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1932,6 +1951,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2074,12 +2100,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-issues.lock.yml b/.github/workflows/smoke-issues.lock.yml index 3e74bd95200..9230ff03b18 100644 --- a/.github/workflows/smoke-issues.lock.yml +++ b/.github/workflows/smoke-issues.lock.yml @@ -478,6 +478,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -870,6 +876,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1130,6 +1142,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1473,6 +1486,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1542,6 +1561,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1640,12 +1666,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index a22d2016347..c43bd72b193 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -538,6 +538,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1018,6 +1024,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Kiro harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1278,6 +1290,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1695,6 +1708,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1748,6 +1767,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1890,12 +1916,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-multi-pr.lock.yml b/.github/workflows/smoke-multi-pr.lock.yml index 130e514dd79..944dbdf9243 100644 --- a/.github/workflows/smoke-multi-pr.lock.yml +++ b/.github/workflows/smoke-multi-pr.lock.yml @@ -535,6 +535,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -982,6 +988,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1264,6 +1276,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1635,6 +1648,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1688,6 +1707,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1830,12 +1856,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 1f304e06b6a..dfb221d0992 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -540,6 +540,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -976,6 +982,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -1314,6 +1326,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1733,6 +1746,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1786,6 +1805,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1927,12 +1953,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-otel-backends.lock.yml b/.github/workflows/smoke-otel-backends.lock.yml index 6eda8dc492d..dcd49d58aa9 100644 --- a/.github/workflows/smoke-otel-backends.lock.yml +++ b/.github/workflows/smoke-otel-backends.lock.yml @@ -575,6 +575,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1151,6 +1157,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1397,6 +1409,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1760,6 +1773,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1811,6 +1830,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2021,12 +2047,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index dab753b9c6d..def1e8eb7fa 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -551,6 +551,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1001,6 +1007,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 @@ -1242,6 +1254,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1602,6 +1615,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1655,6 +1674,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1797,12 +1823,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-project.lock.yml b/.github/workflows/smoke-project.lock.yml index 5ab217e7a21..7cd0626494e 100644 --- a/.github/workflows/smoke-project.lock.yml +++ b/.github/workflows/smoke-project.lock.yml @@ -604,6 +604,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1236,6 +1242,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1493,6 +1505,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1975,6 +1988,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2028,6 +2047,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2170,12 +2196,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-pydantic.lock.yml b/.github/workflows/smoke-pydantic.lock.yml index 053fd114495..6bd5dd84133 100644 --- a/.github/workflows/smoke-pydantic.lock.yml +++ b/.github/workflows/smoke-pydantic.lock.yml @@ -524,6 +524,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1027,6 +1033,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Pydantic AI harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1611,6 +1623,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-logs/ /tmp/gh-aw/agent_usage.json /tmp/gh-aw/agent-stdio.log @@ -1962,6 +1975,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2015,6 +2034,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2156,12 +2182,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-service-ports.lock.yml b/.github/workflows/smoke-service-ports.lock.yml index 59b92b41acc..7fc9c284612 100644 --- a/.github/workflows/smoke-service-ports.lock.yml +++ b/.github/workflows/smoke-service-ports.lock.yml @@ -520,6 +520,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -892,6 +898,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 @@ -1112,6 +1124,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1535,6 +1548,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1588,6 +1607,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1731,12 +1757,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-temporary-id.lock.yml b/.github/workflows/smoke-temporary-id.lock.yml index 70793db6748..c39722ef510 100644 --- a/.github/workflows/smoke-temporary-id.lock.yml +++ b/.github/workflows/smoke-temporary-id.lock.yml @@ -565,6 +565,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -996,6 +1002,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 @@ -1216,6 +1228,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1659,6 +1672,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1712,6 +1731,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1855,12 +1881,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-test-tools.lock.yml b/.github/workflows/smoke-test-tools.lock.yml index ee6288361d7..af5a9af9274 100644 --- a/.github/workflows/smoke-test-tools.lock.yml +++ b/.github/workflows/smoke-test-tools.lock.yml @@ -527,6 +527,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -946,6 +952,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 @@ -1174,6 +1186,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1597,6 +1610,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1650,6 +1669,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1793,12 +1819,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-update-cross-repo-pr.lock.yml b/.github/workflows/smoke-update-cross-repo-pr.lock.yml index a772b1bc0ac..1ebd8d3356a 100644 --- a/.github/workflows/smoke-update-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-update-cross-repo-pr.lock.yml @@ -548,6 +548,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1041,6 +1047,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1316,6 +1328,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1690,6 +1703,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1743,6 +1762,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1886,12 +1912,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml index aabef69dfe1..3c95db02e4b 100644 --- a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml +++ b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml @@ -566,6 +566,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -950,6 +956,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1211,6 +1223,7 @@ jobs: name: ${{ needs.activation.outputs.artifact_prefix }}agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1556,6 +1569,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1609,6 +1628,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1751,12 +1777,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ needs.agent.outputs.artifact_prefix }}detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/smoke-workflow-call.lock.yml b/.github/workflows/smoke-workflow-call.lock.yml index 5a9dcd69279..e7fbfbeb7cd 100644 --- a/.github/workflows/smoke-workflow-call.lock.yml +++ b/.github/workflows/smoke-workflow-call.lock.yml @@ -556,6 +556,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -942,6 +948,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1219,6 +1231,7 @@ jobs: name: ${{ needs.activation.outputs.artifact_prefix }}agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1566,6 +1579,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1619,6 +1638,13 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1761,12 +1787,13 @@ jobs: const { main } = require(path.join(actionsDir, 'parse_token_usage.cjs')); await main(); - name: Upload threat detection log - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ needs.agent.outputs.artifact_prefix }}detection path: | /tmp/gh-aw/threat-detection/detection.log + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/spec-enforcer.lock.yml b/.github/workflows/spec-enforcer.lock.yml index 2e064eb439b..2e3af3f91f5 100644 --- a/.github/workflows/spec-enforcer.lock.yml +++ b/.github/workflows/spec-enforcer.lock.yml @@ -517,6 +517,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1033,6 +1039,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1287,6 +1299,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1680,6 +1693,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1770,6 +1789,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1851,12 +1877,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 30d6a4051ef..41de4af049a 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -503,6 +503,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -954,6 +960,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1276,6 +1288,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1655,6 +1668,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1724,6 +1743,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1823,12 +1849,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index ae7c48ad8ce..6eeab0260ea 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -481,6 +481,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -893,6 +899,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1203,6 +1215,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1552,6 +1565,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1621,6 +1640,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1720,12 +1746,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/squad-game-planner.lock.yml b/.github/workflows/squad-game-planner.lock.yml index 46416d83f98..2569548cf54 100644 --- a/.github/workflows/squad-game-planner.lock.yml +++ b/.github/workflows/squad-game-planner.lock.yml @@ -498,6 +498,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -898,6 +904,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1163,6 +1175,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1505,6 +1518,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1574,6 +1593,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1673,12 +1699,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/squad-implement-worker.lock.yml b/.github/workflows/squad-implement-worker.lock.yml index 150400efd89..44d1fae49ab 100644 --- a/.github/workflows/squad-implement-worker.lock.yml +++ b/.github/workflows/squad-implement-worker.lock.yml @@ -536,6 +536,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1050,6 +1056,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1315,6 +1327,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1669,6 +1682,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1738,6 +1757,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1837,12 +1863,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/squad-plan.lock.yml b/.github/workflows/squad-plan.lock.yml index 59bcd7ecdc0..bb9f82cb61f 100644 --- a/.github/workflows/squad-plan.lock.yml +++ b/.github/workflows/squad-plan.lock.yml @@ -558,6 +558,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -955,6 +961,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1221,6 +1233,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1585,6 +1598,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1654,6 +1673,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1753,12 +1779,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/squad.lock.yml b/.github/workflows/squad.lock.yml index 3a59d98f118..a914ece613b 100644 --- a/.github/workflows/squad.lock.yml +++ b/.github/workflows/squad.lock.yml @@ -586,6 +586,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -1586,6 +1592,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1852,6 +1864,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -2228,6 +2241,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -2297,6 +2316,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2396,12 +2422,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/stale-pr-cleanup.lock.yml b/.github/workflows/stale-pr-cleanup.lock.yml index 91d785dc574..6e04339ec57 100644 --- a/.github/workflows/stale-pr-cleanup.lock.yml +++ b/.github/workflows/stale-pr-cleanup.lock.yml @@ -460,6 +460,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -883,6 +889,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1157,6 +1169,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1514,6 +1527,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1583,6 +1602,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1682,12 +1708,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index 79032d6a2bf..bb34cbfa04e 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1081,6 +1087,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 @@ -1340,6 +1352,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1694,6 +1707,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1763,6 +1782,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1862,12 +1888,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/static-analysis-report.lock.yml b/.github/workflows/static-analysis-report.lock.yml index 8f5598eb579..443e0f9e6d2 100644 --- a/.github/workflows/static-analysis-report.lock.yml +++ b/.github/workflows/static-analysis-report.lock.yml @@ -490,6 +490,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1018,6 +1024,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1348,6 +1360,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1694,6 +1707,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1760,6 +1779,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1845,12 +1871,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/step-name-alignment.lock.yml b/.github/workflows/step-name-alignment.lock.yml index 7a8081a7be6..0a6be0829de 100644 --- a/.github/workflows/step-name-alignment.lock.yml +++ b/.github/workflows/step-name-alignment.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -868,6 +874,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1226,6 +1238,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1571,6 +1584,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1637,6 +1656,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1722,12 +1748,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/sub-issue-closer.lock.yml b/.github/workflows/sub-issue-closer.lock.yml index d839ea97dcf..e9bda2254ad 100644 --- a/.github/workflows/sub-issue-closer.lock.yml +++ b/.github/workflows/sub-issue-closer.lock.yml @@ -449,6 +449,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -874,6 +880,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 @@ -1093,6 +1105,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1438,6 +1451,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1507,6 +1526,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1606,12 +1632,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/super-linter.lock.yml b/.github/workflows/super-linter.lock.yml index d68123f6ec2..0a339e57e02 100644 --- a/.github/workflows/super-linter.lock.yml +++ b/.github/workflows/super-linter.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -863,6 +869,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 @@ -1100,6 +1112,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1436,6 +1449,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1505,6 +1524,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1604,12 +1630,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/technical-doc-writer.lock.yml b/.github/workflows/technical-doc-writer.lock.yml index 10292e429b5..938d3fd3989 100644 --- a/.github/workflows/technical-doc-writer.lock.yml +++ b/.github/workflows/technical-doc-writer.lock.yml @@ -521,6 +521,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1035,6 +1041,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1342,6 +1354,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1736,6 +1749,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1805,6 +1824,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1903,12 +1929,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index f66fcbaf844..187819e1951 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -457,6 +457,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -855,6 +861,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 @@ -1074,6 +1086,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1408,6 +1421,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1477,6 +1496,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1576,12 +1602,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index 68cee19196e..f8042314dc2 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -580,6 +580,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -995,6 +1001,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1284,6 +1296,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1671,6 +1684,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1740,6 +1759,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1840,12 +1866,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/tidy.lock.yml b/.github/workflows/tidy.lock.yml index d39b190811e..7668c19561a 100644 --- a/.github/workflows/tidy.lock.yml +++ b/.github/workflows/tidy.lock.yml @@ -548,6 +548,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -990,6 +996,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1274,6 +1286,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1681,6 +1694,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1750,6 +1769,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1848,12 +1874,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index c1f865bf710..cb4dc356950 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -522,6 +522,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -938,6 +944,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1267,6 +1279,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1631,6 +1644,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1697,6 +1716,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1782,12 +1808,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index 3efd438e09c..4bcca9e9128 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -500,6 +500,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -891,6 +897,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1185,6 +1197,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1562,6 +1575,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1631,6 +1650,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1729,12 +1755,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index 099e4105add..45b96ef2817 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -480,6 +480,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -884,6 +890,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1170,6 +1182,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1522,6 +1535,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1591,6 +1610,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1689,12 +1715,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index 9fddf02809a..8b0bd07d743 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -560,6 +560,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory @@ -1027,6 +1033,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1268,6 +1280,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1668,6 +1681,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1737,6 +1756,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1835,12 +1861,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/update-astro.lock.yml b/.github/workflows/update-astro.lock.yml index 0ee8e35e3af..7768a789d3b 100644 --- a/.github/workflows/update-astro.lock.yml +++ b/.github/workflows/update-astro.lock.yml @@ -511,6 +511,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -991,6 +997,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 @@ -1218,6 +1230,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1639,6 +1652,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1729,6 +1748,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1810,12 +1836,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/video-analyzer.lock.yml b/.github/workflows/video-analyzer.lock.yml index 1560cdeb1c7..4f62724202a 100644 --- a/.github/workflows/video-analyzer.lock.yml +++ b/.github/workflows/video-analyzer.lock.yml @@ -454,6 +454,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -832,6 +838,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 @@ -1051,6 +1063,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1382,6 +1395,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1451,6 +1470,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1550,12 +1576,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/visual-regression-checker.lock.yml b/.github/workflows/visual-regression-checker.lock.yml index 12ad356ed99..68476a312d1 100644 --- a/.github/workflows/visual-regression-checker.lock.yml +++ b/.github/workflows/visual-regression-checker.lock.yml @@ -489,6 +489,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory @@ -914,6 +920,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1194,6 +1206,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1538,6 +1551,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1607,6 +1626,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1705,12 +1731,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/weekly-blog-post-writer.lock.yml b/.github/workflows/weekly-blog-post-writer.lock.yml index 1bba57511f5..56a467cf6be 100644 --- a/.github/workflows/weekly-blog-post-writer.lock.yml +++ b/.github/workflows/weekly-blog-post-writer.lock.yml @@ -557,6 +557,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1084,6 +1090,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1364,6 +1376,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1768,6 +1781,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1837,6 +1856,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1935,12 +1961,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/weekly-editors-health-check.lock.yml b/.github/workflows/weekly-editors-health-check.lock.yml index f9bf6af7a43..524222c2f09 100644 --- a/.github/workflows/weekly-editors-health-check.lock.yml +++ b/.github/workflows/weekly-editors-health-check.lock.yml @@ -491,6 +491,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -927,6 +933,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1225,6 +1237,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1603,6 +1616,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1672,6 +1691,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1770,12 +1796,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index e8133b08f34..2a0572b3ded 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -470,6 +470,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -871,6 +877,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 @@ -1120,6 +1132,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1466,6 +1479,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1535,6 +1554,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1634,12 +1660,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/weekly-network-domains-audit.lock.yml b/.github/workflows/weekly-network-domains-audit.lock.yml index fc6c7da0a0d..c238b30b43b 100644 --- a/.github/workflows/weekly-network-domains-audit.lock.yml +++ b/.github/workflows/weekly-network-domains-audit.lock.yml @@ -450,6 +450,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -838,6 +844,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 @@ -1075,6 +1087,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1416,6 +1429,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1485,6 +1504,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1584,12 +1610,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml index da8e96054d5..73c9892a58e 100644 --- a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml +++ b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml @@ -471,6 +471,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -871,6 +877,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 @@ -1090,6 +1102,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1456,6 +1469,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1525,6 +1544,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1624,12 +1650,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/windows-grower.lock.yml b/.github/workflows/windows-grower.lock.yml index 1fff5327a98..0398873e788 100644 --- a/.github/workflows/windows-grower.lock.yml +++ b/.github/workflows/windows-grower.lock.yml @@ -470,6 +470,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -915,6 +921,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 @@ -1167,6 +1179,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1514,6 +1527,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1604,6 +1623,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1685,12 +1711,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/windows.lock.yml b/.github/workflows/windows.lock.yml index f3449fb32bb..0fb60096b92 100644 --- a/.github/workflows/windows.lock.yml +++ b/.github/workflows/windows.lock.yml @@ -576,6 +576,13 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + shell: bash + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers shell: bash run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" @@ -1032,6 +1039,13 @@ jobs: continue-on-error: true shell: bash run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + shell: bash + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1269,6 +1283,7 @@ jobs: name: ${{ needs.activation.outputs.artifact_prefix }}agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1635,6 +1650,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1725,6 +1746,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1806,12 +1834,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: ${{ needs.agent.outputs.artifact_prefix }}detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/workflow-generator.lock.yml b/.github/workflows/workflow-generator.lock.yml index a6b8a93617b..21675652fd8 100644 --- a/.github/workflows/workflow-generator.lock.yml +++ b/.github/workflows/workflow-generator.lock.yml @@ -512,6 +512,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -948,6 +954,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1213,6 +1225,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1561,6 +1574,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1630,6 +1649,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1728,12 +1754,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/workflow-health-manager.lock.yml b/.github/workflows/workflow-health-manager.lock.yml index 3be2448954f..5e77727de43 100644 --- a/.github/workflows/workflow-health-manager.lock.yml +++ b/.github/workflows/workflow-health-manager.lock.yml @@ -482,6 +482,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -974,6 +980,12 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1266,6 +1278,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1615,6 +1628,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1684,6 +1703,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1782,12 +1808,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/workflow-normalizer.lock.yml b/.github/workflows/workflow-normalizer.lock.yml index 56dd0b79de2..db0433eb18b 100644 --- a/.github/workflows/workflow-normalizer.lock.yml +++ b/.github/workflows/workflow-normalizer.lock.yml @@ -476,6 +476,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -1028,6 +1034,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 @@ -1272,6 +1284,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1623,6 +1636,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1713,6 +1732,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1794,12 +1820,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/.github/workflows/workflow-skill-extractor.lock.yml b/.github/workflows/workflow-skill-extractor.lock.yml index 0f7fa69cdd4..880db7ff98e 100644 --- a/.github/workflows/workflow-skill-extractor.lock.yml +++ b/.github/workflows/workflow-skill-extractor.lock.yml @@ -466,6 +466,12 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -883,6 +889,12 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" + - name: Mark agent execution started + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1160,6 +1172,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ @@ -1506,6 +1519,12 @@ jobs: with: persist-credentials: false # --- Threat Detection --- + - name: Initialize detection execution evidence + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Clean stale firewall files from agent artifact run: | rm -rf /tmp/gh-aw/sandbox/firewall/logs @@ -1575,6 +1594,13 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 + - name: Mark detection execution started + if: always() && steps.detection_guard.outputs.run_detection == 'true' + run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1673,12 +1699,13 @@ jobs: if [ -d /tmp/gh-aw/sandbox/firewall/logs ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/logs && cp -r /tmp/gh-aw/sandbox/firewall/logs/. /tmp/gh-aw/threat-detection/sandbox/firewall/logs/; fi if [ -d /tmp/gh-aw/sandbox/firewall/audit ]; then mkdir -p /tmp/gh-aw/threat-detection/sandbox/firewall/audit && cp -r /tmp/gh-aw/sandbox/firewall/audit/. /tmp/gh-aw/threat-detection/sandbox/firewall/audit/; fi - name: Upload threat detection artifact - if: always() && steps.detection_guard.outputs.run_detection == 'true' + if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: detection path: | /tmp/gh-aw/threat-detection/detection_result.json + /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/threat-detection/sandbox/firewall/logs/ /tmp/gh-aw/threat-detection/sandbox/firewall/audit/ if-no-files-found: ignore diff --git a/actions/setup/js/check_daily_aic_workflow_guardrail.cjs b/actions/setup/js/check_daily_aic_workflow_guardrail.cjs index f04672bdb2a..cc39cb8748e 100644 --- a/actions/setup/js/check_daily_aic_workflow_guardrail.cjs +++ b/actions/setup/js/check_daily_aic_workflow_guardrail.cjs @@ -295,7 +295,7 @@ async function getRunAIC(artifactClient, runId, token, owner, repo, run, inspect }); const usageJSONLFiles = findJSONLFiles(download.downloadPath || downloadRoot); - if (run && usageJSONLFiles.length === 0) { + if (run && !components && usageJSONLFiles.length === 0) { throw new Error(`Usage artifact contains no accounting records for run ${runId}`); } logDailyGuardrail("Downloaded guardrail artifact", { @@ -305,7 +305,7 @@ async function getRunAIC(artifactClient, runId, token, owner, repo, run, inspect downloadPath: download.downloadPath || downloadRoot, usageJSONLFiles, }); - const aic = components ? sumCoveredComponents(download.downloadPath || downloadRoot, components, artifact.createdAt.getTime(), artifacts, artifact.name, run.run_attempt) : sumAICFromUsageJSONLFiles(usageJSONLFiles); + const aic = components ? sumCoveredComponents(download.downloadPath || downloadRoot, components, artifact.createdAt.getTime(), artifacts, artifact.name, run.run_attempt, run.id) : sumAICFromUsageJSONLFiles(usageJSONLFiles); logDailyGuardrail("Computed run AIC from artifact", { runId, artifactId: artifact.id, diff --git a/actions/setup/js/daily_aic_component_coverage.cjs b/actions/setup/js/daily_aic_component_coverage.cjs index 75a3c7b37fa..f199ee0ed5f 100644 --- a/actions/setup/js/daily_aic_component_coverage.cjs +++ b/actions/setup/js/daily_aic_component_coverage.cjs @@ -53,7 +53,18 @@ function allBillableJobsSkipped(components) { return [...components.values()].every(job => job.conclusion === "skipped"); } -function sumCoveredComponents(directory, components, artifactCreatedAt, artifacts, usageArtifactName, attempt) { +function provesExecutionNotStarted(directory, name, runId, runAttempt) { + const evidenceFile = path.join(directory, name, "execution.json"); + if (!fs.existsSync(evidenceFile)) return false; + try { + const evidence = JSON.parse(fs.readFileSync(evidenceFile, "utf8")); + return evidence?.version === 1 && evidence.component === name && evidence.run_id === runId && evidence.run_attempt === runAttempt && evidence.state === "not_started"; + } catch { + return false; + } +} + +function sumCoveredComponents(directory, components, artifactCreatedAt, artifacts, usageArtifactName, attempt, runId) { let total = 0; for (const [name, job] of components) { if (job.conclusion === "skipped") continue; @@ -76,7 +87,10 @@ function sumCoveredComponents(directory, components, artifactCreatedAt, artifact } const candidates = COMPONENT_FILES[name].map(parts => path.join(directory, ...parts)); const selected = candidates.find(file => fs.existsSync(file) && fs.readFileSync(file, "utf8").trim()); - if (!selected) throw new Error(`Missing accounting for executed ${name} component`); + if (!selected) { + if (provesExecutionNotStarted(directory, name, runId, job.run_attempt)) continue; + throw new Error(`Missing accounting for executed ${name} component`); + } total += sumAICFromUsageJSONLFiles([selected], { strict: true }); } if (!Number.isFinite(total)) throw new Error("Daily AIC component total is not finite"); diff --git a/actions/setup/js/daily_aic_component_coverage.test.cjs b/actions/setup/js/daily_aic_component_coverage.test.cjs index 554598c0300..f3153a6dfdc 100644 --- a/actions/setup/js/daily_aic_component_coverage.test.cjs +++ b/actions/setup/js/daily_aic_component_coverage.test.cjs @@ -98,6 +98,47 @@ it.each(["skipped", "not-configured"])("accepts %s detection without requiring p await expect(f.result).resolves.toBe(2); }); +it.each(["agent", "detection"])("accepts provable zero usage when %s execution never started", async component => { + const f = evaluate( + { + [`${component}/execution.json`]: JSON.stringify({ + version: 1, + component, + run_id: 1, + run_attempt: 1, + state: "not_started", + }), + }, + component === "agent" ? [job("agent", { conclusion: "failure" })] : [job("agent", { conclusion: "skipped" }), job("detection", { conclusion: "failure" })] + ); + await expect(f.result).resolves.toBe(0); +}); + +it.each([ + ["started execution", { version: 1, component: "agent", run_id: 1, run_attempt: 1, state: "started" }], + ["malformed evidence", { version: 1, component: "agent", run_id: 1, run_attempt: 1 }], +])("fails closed for missing accounting after %s", async (_name, evidence) => { + const f = evaluate({ "agent/execution.json": JSON.stringify(evidence) }, [job("agent", { conclusion: "failure" })]); + await expect(f.result).rejects.toThrow("Missing accounting for executed agent"); +}); + +it("rejects stale zero-usage evidence from an earlier rerun attempt", async () => { + const f = evaluate( + { + "agent/execution.json": JSON.stringify({ + version: 1, + component: "agent", + run_id: 1, + run_attempt: 1, + state: "not_started", + }), + }, + [job("agent", { id: 10, run_attempt: 2, conclusion: "failure", started_at: later, completed_at: later })], + { attempt: 2, runStarted: later, producerTime: later } + ); + await expect(f.result).rejects.toThrow("Missing accounting for executed agent"); +}); + it("selects raw accounting once per component instead of summing overlapping summaries", async () => { const f = evaluate( { diff --git a/actions/setup/sh/collect_usage_artifact_files.sh b/actions/setup/sh/collect_usage_artifact_files.sh index 84428313f81..ae63522972a 100644 --- a/actions/setup/sh/collect_usage_artifact_files.sh +++ b/actions/setup/sh/collect_usage_artifact_files.sh @@ -40,6 +40,8 @@ if [ -f /tmp/gh-aw/aw-info.jsonl ]; then cp /tmp/gh-aw/aw-info.jsonl /tmp/gh-aw/ if [ -f /tmp/gh-aw/agent_usage.json ]; then cp /tmp/gh-aw/agent_usage.json /tmp/gh-aw/usage/agent_usage.json || true; fi if [ -f /tmp/gh-aw/agent_usage.jsonl ]; then cp /tmp/gh-aw/agent_usage.jsonl /tmp/gh-aw/usage/agent_usage.jsonl || true; fi if [ -f /tmp/gh-aw/detection_usage.jsonl ]; then cp /tmp/gh-aw/detection_usage.jsonl /tmp/gh-aw/usage/detection_usage.jsonl || true; fi +if [ -f /tmp/gh-aw/agent_execution.json ]; then cp /tmp/gh-aw/agent_execution.json /tmp/gh-aw/usage/agent/execution.json || true; fi +if [ -f /tmp/gh-aw/threat-detection/execution.json ]; then cp /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/usage/detection/execution.json || true; fi if [ -f /tmp/gh-aw/evals/evals.jsonl ]; then cp /tmp/gh-aw/evals/evals.jsonl /tmp/gh-aw/usage/evals.jsonl || true; fi if [ -f /tmp/gh-aw/evals/evals_token_usage.jsonl ]; then mkdir -p /tmp/gh-aw/usage/evals diff --git a/pkg/workflow/compiler_yaml_ai_execution.go b/pkg/workflow/compiler_yaml_ai_execution.go index 32eaae938bb..ee6268cae48 100644 --- a/pkg/workflow/compiler_yaml_ai_execution.go +++ b/pkg/workflow/compiler_yaml_ai_execution.go @@ -2,11 +2,38 @@ package workflow import ( "fmt" + "path" "strings" "github.com/github/gh-aw/pkg/constants" ) +const ( + agentExecutionEvidencePath = constants.TmpGhAwDirSlash + "agent_execution.json" + detectionExecutionEvidencePath = constants.ThreatDetectionDir + "/execution.json" +) + +func generateComponentExecutionEvidenceStep(component, state, filePath, condition string) []string { + stepName := "Initialize " + component + " execution evidence" + if state == "started" { + stepName = "Mark " + component + " execution started" + } + lines := []string{ + " - name: " + stepName + "\n", + } + if condition != "" { + lines = append(lines, " if: "+condition+"\n") + } + lines = append(lines, + " run: |\n", + fmt.Sprintf(" mkdir -p %q\n", path.Dir(filePath)), + fmt.Sprintf(" evidence_tmp=%q\n", filePath+".tmp"), + fmt.Sprintf(" printf '{\"version\":1,\"component\":\"%s\",\"run_id\":%%s,\"run_attempt\":%%s,\"state\":\"%s\"}\\n' \"$GITHUB_RUN_ID\" \"$GITHUB_RUN_ATTEMPT\" > \"$evidence_tmp\"\n", component, state), + fmt.Sprintf(" mv \"$evidence_tmp\" %q\n", filePath), + ) + return lines +} + // generateEngineExecutionSteps generates the GitHub Actions steps for executing the AI engine func (c *Compiler) generateEngineExecutionSteps(yaml *strings.Builder, data *WorkflowData, engine CodingAgentEngine, logFile string) { // --use-samples (hidden) replaces the agent step with a deterministic driver @@ -501,6 +528,11 @@ func (c *Compiler) generateAgentRunSteps(yaml *strings.Builder, data *WorkflowDa // Add AI execution step using the agentic engine compilerYamlLog.Printf("Generating engine execution steps for %s", engine.GetID()) + if !data.UseSamples { + for _, line := range generateComponentExecutionEvidenceStep("agent", "started", agentExecutionEvidencePath, "") { + yaml.WriteString(line) + } + } c.generateEngineExecutionSteps(yaml, data, engine, logFileFull) // Stop CLI proxy after AWF execution (always runs to ensure cleanup) diff --git a/pkg/workflow/compiler_yaml_main_job.go b/pkg/workflow/compiler_yaml_main_job.go index 7c7f6094def..25ca7f968a0 100644 --- a/pkg/workflow/compiler_yaml_main_job.go +++ b/pkg/workflow/compiler_yaml_main_job.go @@ -9,6 +9,10 @@ import ( func (c *Compiler) generateMainJobSteps(yaml *strings.Builder, data *WorkflowData) error { compilerYamlLog.Printf("Generating main job steps for workflow: %s", data.Name) + for _, line := range generateComponentExecutionEvidenceStep("agent", "not_started", agentExecutionEvidencePath, "") { + yaml.WriteString(line) + } + // Phase 1: Initial setup, checkout, and repository imports checkoutMgr, needsCheckout, err := c.generateInitialAndCheckoutSteps(yaml, data) if err != nil { diff --git a/pkg/workflow/compiler_yaml_post_agent.go b/pkg/workflow/compiler_yaml_post_agent.go index 3485d98c302..e87ee24bd97 100644 --- a/pkg/workflow/compiler_yaml_post_agent.go +++ b/pkg/workflow/compiler_yaml_post_agent.go @@ -13,6 +13,7 @@ import ( // patch/bundle paths, and firewall audit paths. func (c *Compiler) collectArtifactPaths(data *WorkflowData, engine CodingAgentEngine, logFileFull string, initialPaths []string) []string { //nolint:largefunc // Existing artifact policy remains explicit and ordered. paths := initialPaths + paths = append(paths, agentExecutionEvidencePath) // Merge engine-declared output files into the unified artifact instead of creating a // separate agent_outputs artifact. diff --git a/pkg/workflow/daily_aic_workflow_guardrail_test.go b/pkg/workflow/daily_aic_workflow_guardrail_test.go index 346722b6965..edd6672302f 100644 --- a/pkg/workflow/daily_aic_workflow_guardrail_test.go +++ b/pkg/workflow/daily_aic_workflow_guardrail_test.go @@ -195,6 +195,46 @@ Guardrail test workflow` } } +func TestDailyAICExecutionEvidenceSurroundsPreAgentFailure(t *testing.T) { + testDir := testutil.TempDir(t, "daily-aic-pre-agent-failure-*") + workflowFile := filepath.Join(testDir, "daily-aic-pre-agent-failure.md") + workflow := `--- +on: + workflow_dispatch: +steps: + - name: Fail before agent execution + run: exit 1 +safe-outputs: + add-comment: + max: 1 +--- + +Pre-agent failure accounting test` + if err := os.WriteFile(workflowFile, []byte(workflow), 0o644); err != nil { + t.Fatalf("failed to write test workflow: %v", err) + } + + compiler := NewCompiler() + if err := compiler.CompileWorkflow(workflowFile); err != nil { + t.Fatalf("failed to compile workflow: %v", err) + } + lockContent, err := os.ReadFile(stringutil.MarkdownToLockFile(workflowFile)) + if err != nil { + t.Fatalf("failed to read lock file: %v", err) + } + lockStr := string(lockContent) + initialize := strings.Index(lockStr, "name: Initialize agent execution evidence") + failure := strings.Index(lockStr, "name: Fail before agent execution") + started := strings.Index(lockStr, "name: Mark agent execution started") + execution := strings.Index(lockStr, "id: agentic_execution") + if initialize < 0 || failure <= initialize || started <= failure || execution <= started { + t.Fatalf("expected execution evidence to prove a setup failure occurred before agent execution") + } + if !strings.Contains(lockStr, "/tmp/gh-aw/agent_execution.json") { + t.Fatal("expected the agent artifact to include execution evidence") + } +} + func TestDailyETGuardrailDynamicGate(t *testing.T) { testDir := testutil.TempDir(t, "daily-effective-workflow-no-guardrail-*") workflowFile := filepath.Join(testDir, "no-daily-guardrail.md") diff --git a/pkg/workflow/threat_detection_external.go b/pkg/workflow/threat_detection_external.go index ddf43e2f52d..70dbb7f0b56 100644 --- a/pkg/workflow/threat_detection_external.go +++ b/pkg/workflow/threat_detection_external.go @@ -617,12 +617,13 @@ func (c *Compiler) buildUploadDetectionArtifactStep(data *WorkflowData) []string detectionArtifactName := artifactPrefixExprForAgentDownstreamJob(data) + constants.DetectionArtifactName.String() steps := []string{ " - name: Upload threat detection artifact\n", - fmt.Sprintf(" if: %s\n", detectionStepCondition), + " if: always()\n", fmt.Sprintf(" uses: %s\n", c.getActionPin("actions/upload-artifact")), " with:\n", " name: " + detectionArtifactName + "\n", " path: |\n", " " + constants.ThreatDetectionResultPath + "\n", + " " + detectionExecutionEvidencePath + "\n", } // Include the detection AWF run's own firewall proxy/audit logs (token usage, squid // logs) so detection-phase usage surfaces in the usage artifact and counts toward the diff --git a/pkg/workflow/threat_detection_steps.go b/pkg/workflow/threat_detection_steps.go index ee123d6b547..4597b463a36 100644 --- a/pkg/workflow/threat_detection_steps.go +++ b/pkg/workflow/threat_detection_steps.go @@ -14,7 +14,7 @@ import ( // These steps run after the agent job completes and analyze agent output for threats using the // same agentic engine with sandbox.agent and fully blocked network. // The detection job downloads the agent artifact to access the output files. -func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { +func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { //nolint:largefunc // Detection step order remains intentionally explicit. threatLog.Print("Building threat detection steps for detection job") if data.SafeOutputs == nil || data.SafeOutputs.ThreatDetection == nil { return nil @@ -24,6 +24,7 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { // Comment separator steps = append(steps, " # --- Threat Detection ---\n") + steps = append(steps, generateComponentExecutionEvidenceStep("detection", "not_started", detectionExecutionEvidencePath, "")...) // Step 0: Clean stale firewall files left by the agent artifact download. // The agent artifact populates sandbox/firewall/logs and sandbox/firewall/audit @@ -83,6 +84,7 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { steps = append(steps, c.buildInstallThreatDetectStep(data)...) // Step 11: Run threat-detect under AWF with a read-write mount for the result file + steps = append(steps, generateComponentExecutionEvidenceStep("detection", "started", detectionExecutionEvidencePath, detectionStepCondition)...) steps = append(steps, c.buildExternalDetectorExecutionStep(data)...) // Step 11a: Render detection.log to the Actions log wrapped in group/stop-commands macros. @@ -109,6 +111,7 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { // Inline engine path (default) // Step 7: Engine execution (AWF, no network) + steps = append(steps, generateComponentExecutionEvidenceStep("detection", "started", detectionExecutionEvidencePath, detectionStepCondition)...) steps = append(steps, c.buildDetectionEngineExecutionStep(data)...) // Step 7a: Echo detection step summary so the GitHub runner can mask any secrets. @@ -505,12 +508,13 @@ func (c *Compiler) buildUploadDetectionLogStep(data *WorkflowData) []string { detectionArtifactName := artifactPrefixExprForAgentDownstreamJob(data) + constants.DetectionArtifactName.String() steps := []string{ " - name: Upload threat detection log\n", - fmt.Sprintf(" if: %s\n", detectionStepCondition), + " if: always()\n", fmt.Sprintf(" uses: %s\n", c.getActionPin("actions/upload-artifact")), " with:\n", " name: " + detectionArtifactName + "\n", " path: |\n", " /tmp/gh-aw/threat-detection/detection.log\n", + " " + detectionExecutionEvidencePath + "\n", } if isFirewallEnabled(data) { steps = append(steps, diff --git a/pkg/workflow/threat_detection_steps_test.go b/pkg/workflow/threat_detection_steps_test.go index 3471851ddb8..432baf834da 100644 --- a/pkg/workflow/threat_detection_steps_test.go +++ b/pkg/workflow/threat_detection_steps_test.go @@ -79,6 +79,8 @@ func TestThreatDetectionStepsOrdering(t *testing.T) { // Find the positions of key steps preStepPos := strings.Index(stepsString, "Custom Pre Scan") setupStepPos := strings.Index(stepsString, "Setup threat detection") + initializePos := strings.Index(stepsString, "Initialize detection execution evidence") + startedPos := strings.Index(stepsString, "Mark detection execution started") uploadStepPos := strings.Index(stepsString, "Upload threat detection log") // Verify all steps exist @@ -91,6 +93,12 @@ func TestThreatDetectionStepsOrdering(t *testing.T) { if uploadStepPos == -1 { t.Error("Expected to find 'Upload threat detection log' step") } + if initializePos < 0 || initializePos > preStepPos || startedPos < setupStepPos { + t.Error("Expected detection evidence to surround pre-execution setup") + } + if !strings.Contains(stepsString[uploadStepPos:], "if: always()") || !strings.Contains(stepsString[uploadStepPos:], "/tmp/gh-aw/threat-detection/execution.json") { + t.Error("Expected detection execution evidence to be uploaded after pre-execution failures") + } if !strings.Contains(stepsString, "Parse and conclude threat detection") { t.Error("Expected to find 'Parse and conclude threat detection' step") } From 7a738e9d815ac3a34e7f72c491e176f8fed19a10 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sat, 12 Sep 2026 02:36:54 +0000 Subject: [PATCH 3/5] Move execution evidence into agent invocation Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 23 ++++---- .github/workflows/ace-editor.lock.yml | 12 ++--- .github/workflows/agent-job-health.lock.yml | 23 ++++---- .../agent-performance-analyzer.lock.yml | 23 ++++---- .../workflows/agent-persona-explorer.lock.yml | 23 ++++---- .../workflows/agentic-token-audit.lock.yml | 23 ++++---- .../agentic-token-optimizer.lock.yml | 12 ++--- .../agentic-token-trend-audit.lock.yml | 23 ++++---- .github/workflows/ai-moderator.lock.yml | 12 ++--- .../workflows/api-consumption-report.lock.yml | 23 ++++---- .github/workflows/approach-validator.lock.yml | 23 ++++---- .github/workflows/archie.lock.yml | 23 ++++---- .../workflows/architecture-guardian.lock.yml | 23 ++++---- ...rchivx-agentic-workflows-analyzer.lock.yml | 23 ++++---- .github/workflows/artifacts-summary.lock.yml | 23 ++++---- .github/workflows/audit-workflows.lock.yml | 23 ++++---- .github/workflows/auto-triage-issues.lock.yml | 23 ++++---- .github/workflows/avenger.lock.yml | 23 ++++---- .../aw-failure-investigator.lock.yml | 23 ++++---- .github/workflows/blog-auditor.lock.yml | 23 ++++---- .github/workflows/bot-detection.lock.yml | 12 ++--- .../breaking-change-checker.lock.yml | 23 ++++---- .github/workflows/changeset.lock.yml | 23 ++++---- .../workflows/chaos-pr-bundle-fuzzer.lock.yml | 23 ++++---- .github/workflows/ci-coach.lock.yml | 23 ++++---- .github/workflows/ci-doctor.lock.yml | 23 ++++---- .../claude-code-user-docs-review.lock.yml | 23 ++++---- .../cli-consistency-checker.lock.yml | 23 ++++---- .../workflows/cli-version-checker.lock.yml | 23 ++++---- .github/workflows/cloclo.lock.yml | 23 ++++---- .../workflows/code-scanning-fixer.lock.yml | 23 ++++---- .github/workflows/code-simplifier.lock.yml | 23 ++++---- .../codex-github-remote-mcp-test.lock.yml | 12 ++--- .../commit-changes-analyzer.lock.yml | 23 ++++---- .../constraint-solving-potd.lock.yml | 23 ++++---- .github/workflows/contribution-check.lock.yml | 23 ++++---- .../workflows/copilot-agent-analysis.lock.yml | 23 ++++---- .../copilot-centralization-drilldown.lock.yml | 23 ++++---- .../copilot-centralization-optimizer.lock.yml | 23 ++++---- .../copilot-cli-deep-research.lock.yml | 23 ++++---- .github/workflows/copilot-opt.lock.yml | 23 ++++---- .../copilot-pr-merged-report.lock.yml | 23 ++++---- .../copilot-pr-nlp-analysis.lock.yml | 23 ++++---- .../copilot-pr-prompt-analysis.lock.yml | 23 ++++---- .../copilot-session-insights.lock.yml | 23 ++++---- .github/workflows/craft.lock.yml | 23 ++++---- ...daily-action-setup-security-audit.lock.yml | 23 ++++---- ...aily-agent-of-the-day-blog-writer.lock.yml | 23 ++++---- .../daily-agentrx-trace-optimizer.lock.yml | 23 ++++---- .../daily-ambient-context-optimizer.lock.yml | 23 ++++---- .../daily-architecture-diagram.lock.yml | 23 ++++---- .../workflows/daily-arxiv-researcher.lock.yml | 23 ++++---- .../daily-assign-issue-to-user.lock.yml | 23 ++++---- ...strostylelite-markdown-spellcheck.lock.yml | 23 ++++---- ...daily-aw-cross-repo-compile-check.lock.yml | 23 ++++---- ...daily-awf-spec-compiler-surfacing.lock.yml | 23 ++++---- .../workflows/daily-byok-ollama-test.lock.yml | 23 ++++---- .../daily-cache-strategy-analyzer.lock.yml | 23 ++++---- .../daily-caveman-optimizer.lock.yml | 23 ++++---- .github/workflows/daily-choice-test.lock.yml | 23 ++++---- .../workflows/daily-cli-performance.lock.yml | 23 ++++---- .../workflows/daily-cli-tools-tester.lock.yml | 23 ++++---- .../workflows/daily-code-debt-aider.lock.yml | 23 ++++---- .github/workflows/daily-code-metrics.lock.yml | 23 ++++---- .../daily-community-attribution.lock.yml | 23 ++++---- .../workflows/daily-compiler-quality.lock.yml | 23 ++++---- ...ly-compiler-threat-spec-optimizer.lock.yml | 23 ++++---- .../daily-credit-limit-test.lock.yml | 23 ++++---- .github/workflows/daily-doc-healer.lock.yml | 23 ++++---- .github/workflows/daily-doc-updater.lock.yml | 23 ++++---- .../daily-documentation-diagram.lock.yml | 23 ++++---- .../daily-elixir-credo-snippet-audit.lock.yml | 23 ++++---- .github/workflows/daily-evals-report.lock.yml | 23 ++++---- .../daily-experiment-report.lock.yml | 23 ++++---- .github/workflows/daily-fact.lock.yml | 23 ++++---- .github/workflows/daily-file-diet.lock.yml | 23 ++++---- .../workflows/daily-firewall-report.lock.yml | 23 ++++---- .../daily-formal-spec-verifier.lock.yml | 23 ++++---- .../workflows/daily-function-namer.lock.yml | 23 ++++---- .../workflows/daily-geo-optimizer.lock.yml | 23 ++++---- .../daily-github-docs-seo-optimizer.lock.yml | 23 ++++---- .../daily-go-test-parallelizer.lock.yml | 23 ++++---- .../daily-go-test-stubs-aider.lock.yml | 23 ++++---- .github/workflows/daily-grader-audit.lock.yml | 23 ++++---- .../daily-graft-intelligence.lock.yml | 23 ++++---- ...daily-harness-experiment-proposer.lock.yml | 12 ++--- .github/workflows/daily-hippo-learn.lock.yml | 23 ++++---- .../workflows/daily-issues-report.lock.yml | 23 ++++---- .../daily-malicious-code-scan.lock.yml | 12 ++--- .../daily-max-ai-credits-test.lock.yml | 23 ++++---- .../daily-mcp-concurrency-analysis.lock.yml | 23 ++++---- .../workflows/daily-model-inventory.lock.yml | 23 ++++---- .../workflows/daily-model-resolution.lock.yml | 23 ++++---- .../daily-multi-device-docs-tester.lock.yml | 23 ++++---- .github/workflows/daily-news.lock.yml | 23 ++++---- .../daily-observability-report.lock.yml | 23 ++++---- .../daily-performance-summary.lock.yml | 23 ++++---- .../workflows/daily-pr-review-cursor.lock.yml | 23 ++++---- .../daily-regression-audit-kiro.lock.yml | 23 ++++---- .github/workflows/daily-regulatory.lock.yml | 23 ++++---- .../daily-reliability-review.lock.yml | 23 ++++---- .../daily-rendering-scripts-verifier.lock.yml | 23 ++++---- .../workflows/daily-repo-chronicle.lock.yml | 23 ++++---- .../daily-safe-output-integrator.lock.yml | 23 ++++---- .../daily-safe-output-optimizer.lock.yml | 23 ++++---- .../daily-safe-outputs-conformance.lock.yml | 23 ++++---- .../daily-safeoutputs-git-simulator.lock.yml | 23 ++++---- .../daily-schema-audit-cursor.lock.yml | 23 ++++---- .../workflows/daily-secrets-analysis.lock.yml | 23 ++++---- .../daily-security-observability.lock.yml | 23 ++++---- .../daily-security-red-team.lock.yml | 23 ++++---- .github/workflows/daily-semgrep-scan.lock.yml | 23 ++++---- .../daily-spdd-spec-planner.lock.yml | 23 ++++---- .../daily-spec-coverage-kiro.lock.yml | 23 ++++---- .../daily-spending-forecast.lock.yml | 23 ++++---- .../workflows/daily-squid-image-scan.lock.yml | 23 ++++---- .github/workflows/daily-storify.lock.yml | 23 ++++---- .../daily-syntax-error-quality.lock.yml | 23 ++++---- .../daily-team-evolution-insights.lock.yml | 23 ++++---- .github/workflows/daily-team-status.lock.yml | 23 ++++---- .../daily-testify-uber-super-expert.lock.yml | 23 ++++---- .../daily-token-consumption-report.lock.yml | 23 ++++---- ...ily-trajectory-grader-implementer.lock.yml | 23 ++++---- .../workflows/daily-vulnhunter-scan.lock.yml | 23 ++++---- .../daily-windows-defender-scan.lock.yml | 23 ++++---- ...dows-terminal-integration-builder.lock.yml | 23 ++++---- .../workflows/daily-workflow-updater.lock.yml | 23 ++++---- .../workflows/daily-yamllint-fixer.lock.yml | 23 ++++---- .../dataflow-pr-discussion-dataset.lock.yml | 23 ++++---- .github/workflows/dead-code-remover.lock.yml | 23 ++++---- .github/workflows/deep-report.lock.yml | 23 ++++---- .../workflows/deepsec-security-scan.lock.yml | 23 ++++---- .github/workflows/delight.lock.yml | 23 ++++---- .github/workflows/dependabot-burner.lock.yml | 23 ++++---- .../workflows/dependabot-go-checker.lock.yml | 23 ++++---- .../deployment-incident-monitor.lock.yml | 23 ++++---- .../workflows/design-decision-gate.lock.yml | 23 ++++---- .../workflows/designer-drift-audit.lock.yml | 23 ++++---- .../detection-analysis-report.lock.yml | 23 ++++---- .github/workflows/dev-hawk.lock.yml | 23 ++++---- .github/workflows/dev.lock.yml | 23 ++++---- .../developer-docs-consolidator.lock.yml | 23 ++++---- .github/workflows/dictation-prompt.lock.yml | 23 ++++---- .github/workflows/docs-noob-tester.lock.yml | 23 ++++---- .github/workflows/draft-pr-cleanup.lock.yml | 23 ++++---- .../duplicate-code-detector.lock.yml | 23 ++++---- .github/workflows/eslint-miner.lock.yml | 23 ++++---- .github/workflows/eslint-monster.lock.yml | 23 ++++---- .github/workflows/eslint-refiner.lock.yml | 23 ++++---- .github/workflows/evoskill-evolver.lock.yml | 23 ++++---- .../example-failure-category-filter.lock.yml | 23 ++++---- .../example-permissions-warning.lock.yml | 12 ++--- .../example-workflow-analyzer.lock.yml | 23 ++++---- .github/workflows/feature-grower.lock.yml | 23 ++++---- .github/workflows/firewall-escape.lock.yml | 23 ++++---- .github/workflows/firewall.lock.yml | 12 ++--- .../workflows/front-page-copy-guard.lock.yml | 23 ++++---- .../workflows/functional-pragmatist.lock.yml | 23 ++++---- .../github-mcp-structural-analysis.lock.yml | 23 ++++---- .../github-mcp-tools-report.lock.yml | 23 ++++---- .../github-remote-mcp-auth-test.lock.yml | 23 ++++---- .../workflows/glossary-maintainer.lock.yml | 23 ++++---- .github/workflows/go-fan.lock.yml | 23 ++++---- .github/workflows/go-logger.lock.yml | 23 ++++---- .../workflows/go-pattern-detector.lock.yml | 23 ++++---- .github/workflows/gpclean.lock.yml | 23 ++++---- .github/workflows/grumpy-reviewer.lock.yml | 23 ++++---- .github/workflows/hippo-embed.lock.yml | 12 ++--- .github/workflows/hourly-ci-cleaner.lock.yml | 23 ++++---- .../impeccable-skills-reviewer.lock.yml | 23 ++++---- .../workflows/instructions-janitor.lock.yml | 23 ++++---- .github/workflows/issue-arborist.lock.yml | 23 ++++---- .github/workflows/issue-monster.lock.yml | 23 ++++---- .github/workflows/issue-triage-agent.lock.yml | 23 ++++---- .github/workflows/jsweep.lock.yml | 23 ++++---- .../workflows/layout-spec-maintainer.lock.yml | 23 ++++---- .github/workflows/lint-monster.lock.yml | 23 ++++---- .github/workflows/linter-miner.lock.yml | 23 ++++---- .github/workflows/lockfile-stats.lock.yml | 23 ++++---- .../mattpocock-skills-reviewer.lock.yml | 23 ++++---- .github/workflows/mcp-inspector.lock.yml | 23 ++++---- .github/workflows/mergefest.lock.yml | 23 ++++---- .github/workflows/metrics-collector.lock.yml | 23 ++++---- .github/workflows/necromancer.lock.yml | 23 ++++---- .../workflows/notion-issue-summary.lock.yml | 12 ++--- .../objective-impact-report.lock.yml | 23 ++++---- .github/workflows/org-health-report.lock.yml | 23 ++++---- .github/workflows/outcome-collector.lock.yml | 23 ++++---- .github/workflows/pdf-summary.lock.yml | 23 ++++---- .github/workflows/plan.lock.yml | 23 ++++---- .github/workflows/poem-bot.lock.yml | 23 ++++---- .github/workflows/ponytail-reviewer.lock.yml | 23 ++++---- .github/workflows/portfolio-analyst.lock.yml | 23 ++++---- .../pr-code-quality-reviewer.lock.yml | 23 ++++---- .../workflows/pr-description-caveman.lock.yml | 23 ++++---- .../workflows/pr-nitpick-reviewer.lock.yml | 23 ++++---- .github/workflows/pr-sous-chef.lock.yml | 23 ++++---- .github/workflows/pr-triage-agent.lock.yml | 23 ++++---- .../prompt-clustering-analysis.lock.yml | 23 ++++---- .github/workflows/purelock.lock.yml | 23 ++++---- .github/workflows/python-data-charts.lock.yml | 23 ++++---- .github/workflows/q.lock.yml | 23 ++++---- .../workflows/refactoring-cadence.lock.yml | 23 ++++---- .github/workflows/refiner.lock.yml | 23 ++++---- .github/workflows/release.lock.yml | 12 ++--- .../workflows/repo-audit-analyzer.lock.yml | 23 ++++---- .github/workflows/repo-tree-map.lock.yml | 23 ++++---- .../repository-quality-improver.lock.yml | 23 ++++---- .github/workflows/research.lock.yml | 23 ++++---- .github/workflows/ruflo-backed-task.lock.yml | 23 ++++---- .github/workflows/safe-output-health.lock.yml | 23 ++++---- .../schema-consistency-checker.lock.yml | 23 ++++---- .../schema-feature-coverage.lock.yml | 23 ++++---- .github/workflows/scout.lock.yml | 23 ++++---- .../workflows/security-compliance.lock.yml | 23 ++++---- .github/workflows/security-review.lock.yml | 23 ++++---- .../semantic-function-refactor.lock.yml | 23 ++++---- .github/workflows/sergo.lock.yml | 23 ++++---- .../sighthound-security-scan.lock.yml | 23 ++++---- .github/workflows/skillet.lock.yml | 23 ++++---- .../workflows/slide-deck-maintainer.lock.yml | 23 ++++---- .../workflows/smoke-agent-all-merged.lock.yml | 23 ++++---- .../workflows/smoke-agent-all-none.lock.yml | 23 ++++---- .../smoke-agent-public-approved.lock.yml | 23 ++++---- .../smoke-agent-public-none.lock.yml | 23 ++++---- .../smoke-agent-scoped-approved.lock.yml | 23 ++++---- .github/workflows/smoke-aider.lock.yml | 23 ++++---- .../workflows/smoke-call-workflow.lock.yml | 23 ++++---- .../smoke-checkout-pr-dispatch.lock.yml | 23 ++++---- .github/workflows/smoke-ci.lock.yml | 2 + .../smoke-claude-on-copilot.lock.yml | 23 ++++---- .github/workflows/smoke-claude.lock.yml | 23 ++++---- .github/workflows/smoke-codex.lock.yml | 23 ++++---- .../smoke-copilot-aoai-apikey.lock.yml | 23 ++++---- .../smoke-copilot-aoai-entra.lock.yml | 23 ++++---- .github/workflows/smoke-copilot-arm.lock.yml | 23 ++++---- .github/workflows/smoke-copilot-auto.lock.yml | 23 ++++---- .github/workflows/smoke-copilot-mai.lock.yml | 23 ++++---- .github/workflows/smoke-copilot-sdk.lock.yml | 23 ++++---- .../workflows/smoke-copilot-small.lock.yml | 23 ++++---- .../smoke-copilot-sub-agents.lock.yml | 23 ++++---- .github/workflows/smoke-copilot.lock.yml | 23 ++++---- .../smoke-create-cross-repo-pr.lock.yml | 23 ++++---- .github/workflows/smoke-crush.lock.yml | 23 ++++---- .github/workflows/smoke-cursor.lock.yml | 23 ++++---- .../workflows/smoke-deepseek-harness.lock.yml | 23 ++++---- .github/workflows/smoke-drive.lock.yml | 23 ++++---- .github/workflows/smoke-gemini.lock.yml | 23 ++++---- .../workflows/smoke-github-claude.lock.yml | 23 ++++---- .github/workflows/smoke-goose.lock.yml | 23 ++++---- .github/workflows/smoke-issues.lock.yml | 23 ++++---- .github/workflows/smoke-kiro.lock.yml | 23 ++++---- .github/workflows/smoke-multi-pr.lock.yml | 23 ++++---- .github/workflows/smoke-opencode.lock.yml | 23 ++++---- .../workflows/smoke-otel-backends.lock.yml | 23 ++++---- .github/workflows/smoke-pi.lock.yml | 23 ++++---- .github/workflows/smoke-project.lock.yml | 23 ++++---- .github/workflows/smoke-pydantic.lock.yml | 23 ++++---- .../workflows/smoke-service-ports.lock.yml | 23 ++++---- .github/workflows/smoke-temporary-id.lock.yml | 23 ++++---- .github/workflows/smoke-test-tools.lock.yml | 23 ++++---- .../smoke-update-cross-repo-pr.lock.yml | 23 ++++---- .../smoke-workflow-call-with-inputs.lock.yml | 23 ++++---- .../workflows/smoke-workflow-call.lock.yml | 23 ++++---- .github/workflows/spec-enforcer.lock.yml | 23 ++++---- .github/workflows/spec-extractor.lock.yml | 23 ++++---- .github/workflows/spec-librarian.lock.yml | 23 ++++---- .github/workflows/squad-game-planner.lock.yml | 23 ++++---- .../workflows/squad-implement-worker.lock.yml | 23 ++++---- .github/workflows/squad-plan.lock.yml | 23 ++++---- .github/workflows/squad.lock.yml | 23 ++++---- .github/workflows/stale-pr-cleanup.lock.yml | 23 ++++---- .../workflows/stale-repo-identifier.lock.yml | 23 ++++---- .../workflows/static-analysis-report.lock.yml | 23 ++++---- .../workflows/step-name-alignment.lock.yml | 23 ++++---- .github/workflows/sub-issue-closer.lock.yml | 23 ++++---- .github/workflows/super-linter.lock.yml | 23 ++++---- .../workflows/technical-doc-writer.lock.yml | 23 ++++---- .github/workflows/terminal-stylist.lock.yml | 23 ++++---- .../workflows/test-quality-sentinel.lock.yml | 23 ++++---- .github/workflows/tidy.lock.yml | 23 ++++---- .github/workflows/typist.lock.yml | 23 ++++---- .../workflows/ubuntu-image-analyzer.lock.yml | 23 ++++---- .../uk-ai-operational-resilience.lock.yml | 23 ++++---- .github/workflows/unbloat-docs.lock.yml | 23 ++++---- .github/workflows/update-astro.lock.yml | 23 ++++---- .github/workflows/video-analyzer.lock.yml | 23 ++++---- .../visual-regression-checker.lock.yml | 23 ++++---- .../weekly-blog-post-writer.lock.yml | 23 ++++---- .../weekly-editors-health-check.lock.yml | 23 ++++---- .../workflows/weekly-issue-summary.lock.yml | 23 ++++---- .../weekly-network-domains-audit.lock.yml | 23 ++++---- .../weekly-safe-outputs-spec-review.lock.yml | 23 ++++---- .github/workflows/windows-grower.lock.yml | 23 ++++---- .github/workflows/windows.lock.yml | 24 ++++----- .github/workflows/workflow-generator.lock.yml | 23 ++++---- .../workflow-health-manager.lock.yml | 23 ++++---- .../workflows/workflow-normalizer.lock.yml | 23 ++++---- .../workflow-skill-extractor.lock.yml | 23 ++++---- pkg/workflow/compiler_yaml_ai_execution.go | 52 +++++++++++++++++-- .../daily_aic_workflow_guardrail_test.go | 7 ++- pkg/workflow/notify_comment.go | 2 + pkg/workflow/notify_comment_test.go | 12 +++++ .../TestWasmGolden_AllEngines/claude.golden | 11 ++++ .../TestWasmGolden_AllEngines/codex.golden | 11 ++++ .../TestWasmGolden_AllEngines/copilot.golden | 11 ++++ .../TestWasmGolden_AllEngines/gemini.golden | 11 ++++ .../TestWasmGolden_AllEngines/pi.golden | 11 ++++ .../basic-copilot.golden | 11 ++++ .../playwright-cli-mode.golden | 11 ++++ .../smoke-copilot.golden | 11 ++++ .../with-imports.golden | 11 ++++ pkg/workflow/threat_detection_external.go | 3 ++ .../threat_detection_inline_engine.go | 1 + pkg/workflow/threat_detection_steps.go | 2 - pkg/workflow/threat_detection_steps_test.go | 10 ++-- 316 files changed, 3110 insertions(+), 3803 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index 22a763ea536..c746cf093ee 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -978,18 +978,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1400,7 +1398,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1728,13 +1728,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1768,6 +1761,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/ace-editor.lock.yml b/.github/workflows/ace-editor.lock.yml index 4799c439a5c..850a4dbe11e 100644 --- a/.github/workflows/ace-editor.lock.yml +++ b/.github/workflows/ace-editor.lock.yml @@ -898,18 +898,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1273,7 +1271,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 3c16b2db5ed..9c5b1b072ed 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -1012,12 +1012,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1125,6 +1119,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1536,7 +1534,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1841,13 +1841,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1885,6 +1878,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index 0b03a572fdb..af77a2f89c5 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -1077,12 +1077,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1093,6 +1087,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1547,7 +1545,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1856,13 +1856,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1902,6 +1895,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index 0d1b07ff042..2892263f920 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -1084,18 +1084,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 180 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1507,7 +1505,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1813,13 +1813,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1858,6 +1851,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/agentic-token-audit.lock.yml b/.github/workflows/agentic-token-audit.lock.yml index a23a0137808..37dc18b4780 100644 --- a/.github/workflows/agentic-token-audit.lock.yml +++ b/.github/workflows/agentic-token-audit.lock.yml @@ -989,18 +989,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 25 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1435,7 +1433,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1744,13 +1744,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1789,6 +1782,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/agentic-token-optimizer.lock.yml b/.github/workflows/agentic-token-optimizer.lock.yml index 199bcc85fb6..17990b30a12 100644 --- a/.github/workflows/agentic-token-optimizer.lock.yml +++ b/.github/workflows/agentic-token-optimizer.lock.yml @@ -898,18 +898,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1322,7 +1320,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index d95552ff97b..51e39f26116 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -1051,18 +1051,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 25 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1467,7 +1465,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1791,13 +1791,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1831,6 +1824,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index 43ee0d2f97a..31004901946 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -926,18 +926,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1330,7 +1328,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index eb8c6c8d72f..6ebff33af2c 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -1074,18 +1074,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1507,7 +1505,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1836,13 +1836,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1876,6 +1869,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index eb629ed00c8..d05ef81114a 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -1010,12 +1010,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1115,6 +1109,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1521,7 +1519,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1839,13 +1839,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1883,6 +1876,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 910ee36ac1a..fbfd7eed1ac 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -975,18 +975,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1407,7 +1405,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1728,13 +1728,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1774,6 +1767,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 97799426784..4700aa57576 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -882,12 +882,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -913,6 +907,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1336,7 +1334,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1640,13 +1640,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1686,6 +1679,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index fbcebc92b98..48d08bcec19 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -1082,12 +1082,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1170,6 +1164,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1566,7 +1564,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1889,13 +1889,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1933,6 +1926,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index bf41bc824e2..b7eb4700c5a 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -927,18 +927,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1331,7 +1329,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1652,13 +1652,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1692,6 +1685,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index c2337050ee4..5a5e43db0e0 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -1157,18 +1157,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1623,7 +1621,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1962,13 +1962,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2002,6 +1995,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index 7430b89bd75..ed21dbe3672 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1022,18 +1022,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1429,7 +1427,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1750,13 +1750,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1790,6 +1783,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index 9a9dbae94f5..8cf644eade5 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -1025,18 +1025,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1486,7 +1484,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1836,13 +1836,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1876,6 +1869,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index 8aed16d1388..92d91230036 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -1118,12 +1118,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1206,6 +1200,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1601,7 +1599,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1907,13 +1907,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1951,6 +1944,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 86f03b8e1e2..145f159129d 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -933,12 +933,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1039,6 +1033,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1436,7 +1434,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1744,13 +1744,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1788,6 +1781,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/bot-detection.lock.yml b/.github/workflows/bot-detection.lock.yml index 4a65275dcbf..5c8ed072b76 100644 --- a/.github/workflows/bot-detection.lock.yml +++ b/.github/workflows/bot-detection.lock.yml @@ -1017,18 +1017,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1411,7 +1409,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 3b94d8a1741..85241c25006 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -917,12 +917,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -953,6 +947,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1377,7 +1375,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1687,13 +1687,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1733,6 +1726,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index 2b89d5096e5..8f8c2b5c14d 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -1027,18 +1027,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1432,7 +1430,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1752,13 +1752,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1792,6 +1785,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index fb722fc14e4..1110ed0a60e 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -985,18 +985,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1398,7 +1396,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1719,13 +1719,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1759,6 +1752,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index 85ad76df8e7..c0226b91ec6 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -1011,12 +1011,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1027,6 +1021,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1468,7 +1466,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1805,13 +1805,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1851,6 +1844,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index 1665c997f3b..fcbef1891cf 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1085,12 +1085,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1170,6 +1164,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1560,7 +1558,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1888,13 +1888,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1932,6 +1925,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index b0999a22879..9a9e1d9373c 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -872,12 +872,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -973,6 +967,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1397,7 +1395,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1703,13 +1703,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1747,6 +1740,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index 68c87b2f953..f075cdfa9c9 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -869,12 +869,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -885,6 +879,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1308,7 +1306,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1605,13 +1605,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1651,6 +1644,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index 7e3031b8c6a..2b0e6d981d6 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -870,18 +870,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1282,7 +1280,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1572,13 +1572,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1618,6 +1611,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index deb2f18b23e..05cdc4bef60 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -1315,18 +1315,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1743,7 +1741,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2113,13 +2113,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2153,6 +2146,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index cd82468235a..b73931ddd8a 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -1000,12 +1000,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1044,6 +1038,10 @@ jobs: timeout-minutes: 40 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1488,7 +1486,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1813,13 +1813,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1859,6 +1852,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index 3c9afba4c17..67e1df75a1f 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -935,18 +935,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1365,7 +1363,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1694,13 +1694,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1739,6 +1732,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/codex-github-remote-mcp-test.lock.yml b/.github/workflows/codex-github-remote-mcp-test.lock.yml index 75131e1025f..039410ae71a 100644 --- a/.github/workflows/codex-github-remote-mcp-test.lock.yml +++ b/.github/workflows/codex-github-remote-mcp-test.lock.yml @@ -852,18 +852,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1212,7 +1210,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 5125e3d5455..87d070b8a90 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -923,18 +923,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1290,7 +1288,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1610,13 +1610,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1650,6 +1643,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index 85abf01c93e..4cf150bb123 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -848,18 +848,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1264,7 +1262,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1566,13 +1566,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1611,6 +1604,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index 391001a63e2..d95a7345257 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -1009,12 +1009,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1042,6 +1036,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1438,7 +1436,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1736,13 +1736,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,6 +1774,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 38e146c1cb3..3b6ccd21799 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -973,12 +973,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1068,6 +1062,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1479,7 +1477,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1788,13 +1788,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1832,6 +1825,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/copilot-centralization-drilldown.lock.yml b/.github/workflows/copilot-centralization-drilldown.lock.yml index 55a43712998..482b91c3fe1 100644 --- a/.github/workflows/copilot-centralization-drilldown.lock.yml +++ b/.github/workflows/copilot-centralization-drilldown.lock.yml @@ -935,18 +935,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1296,7 +1294,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1614,13 +1614,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1654,6 +1647,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/copilot-centralization-optimizer.lock.yml b/.github/workflows/copilot-centralization-optimizer.lock.yml index c92ea61cf28..f1e017c9e3d 100644 --- a/.github/workflows/copilot-centralization-optimizer.lock.yml +++ b/.github/workflows/copilot-centralization-optimizer.lock.yml @@ -979,18 +979,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1373,7 +1371,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1695,13 +1695,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1735,6 +1728,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index c60a72d5e33..144a5716338 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -876,12 +876,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -892,6 +886,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1322,7 +1320,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1623,13 +1623,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1669,6 +1662,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index 0d112c986a5..d59e8ed3a36 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -903,12 +903,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -945,6 +939,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1363,7 +1361,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1664,13 +1664,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1709,6 +1702,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index bb507a8d786..7fea761f69f 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -830,12 +830,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -845,6 +839,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1252,7 +1250,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1554,13 +1554,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1600,6 +1593,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index cb99576f8d0..ec10b4a0130 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -973,12 +973,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -989,6 +983,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1442,7 +1440,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1748,13 +1748,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1794,6 +1787,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 9482ed58134..5fa42292bef 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -919,12 +919,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -935,6 +929,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1375,7 +1373,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1681,13 +1681,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1727,6 +1720,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 6bae3a8e147..14cd71e0e46 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -965,12 +965,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1048,6 +1042,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1482,7 +1480,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1785,13 +1785,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1829,6 +1822,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index eb866440108..36e5f42499e 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -937,12 +937,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -953,6 +947,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1354,7 +1352,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1677,13 +1677,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1723,6 +1716,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-action-setup-security-audit.lock.yml b/.github/workflows/daily-action-setup-security-audit.lock.yml index e0779f6be93..b3b0ecd9ff9 100644 --- a/.github/workflows/daily-action-setup-security-audit.lock.yml +++ b/.github/workflows/daily-action-setup-security-audit.lock.yml @@ -882,12 +882,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -898,6 +892,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1305,7 +1303,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1612,13 +1612,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1657,6 +1650,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 91ba1fc3e04..4c53c1700a6 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -1037,12 +1037,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1053,6 +1047,10 @@ jobs: timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1475,7 +1473,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1808,13 +1808,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1853,6 +1846,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index dc71f47d910..199bef361bf 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -1057,12 +1057,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1149,6 +1143,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1530,7 +1528,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1841,13 +1841,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1885,6 +1878,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index 959ef20defb..865066be800 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -947,12 +947,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -963,6 +957,10 @@ jobs: timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1352,7 +1350,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1655,13 +1655,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1701,6 +1694,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index d7e96c856c8..618571c185b 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -1105,18 +1105,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1492,7 +1490,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1846,13 +1846,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1886,6 +1879,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-arxiv-researcher.lock.yml b/.github/workflows/daily-arxiv-researcher.lock.yml index fbc88fdf54d..55abda40249 100644 --- a/.github/workflows/daily-arxiv-researcher.lock.yml +++ b/.github/workflows/daily-arxiv-researcher.lock.yml @@ -930,12 +930,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -974,6 +968,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1410,7 +1408,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1714,13 +1714,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1760,6 +1753,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index fe0808d1cb9..da1494b45d9 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -893,12 +893,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -909,6 +903,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1298,7 +1296,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1595,13 +1595,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1641,6 +1634,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index 4d402faaf5d..a930537c7f2 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -955,12 +955,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1042,6 +1036,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1405,7 +1403,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1736,13 +1736,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1780,6 +1773,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index 72950078acc..f0c88d4ff5b 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -893,12 +893,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -984,6 +978,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1362,7 +1360,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1666,13 +1666,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1710,6 +1703,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index 3739a29ce28..48301945ff3 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -960,18 +960,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1358,7 +1356,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1686,13 +1686,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1726,6 +1719,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index 837497d045b..3c5c3ca190e 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -882,18 +882,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1272,7 +1270,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1567,13 +1567,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1613,6 +1606,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index 2569ea35293..5b06a8a0956 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -1123,18 +1123,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 60 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1511,7 +1509,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1846,13 +1846,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1886,6 +1879,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index d7cfb20e895..5ed271f1f4a 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -974,12 +974,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1065,6 +1059,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1447,7 +1445,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1781,13 +1781,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1826,6 +1819,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index c449e02b1d1..865fe711089 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -851,12 +851,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -938,6 +932,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1287,7 +1285,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1585,13 +1585,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1629,6 +1622,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index aee596ff39b..3fee8b8b665 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -1232,18 +1232,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1644,7 +1642,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1975,13 +1975,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2015,6 +2008,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index b197b4393f8..31e96fba897 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -1036,18 +1036,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 60 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1399,7 +1397,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1719,13 +1719,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1759,6 +1752,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-code-debt-aider.lock.yml b/.github/workflows/daily-code-debt-aider.lock.yml index 0f5210cc196..0901f9a7d4f 100644 --- a/.github/workflows/daily-code-debt-aider.lock.yml +++ b/.github/workflows/daily-code-debt-aider.lock.yml @@ -880,12 +880,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -945,6 +939,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1255,7 +1253,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1571,13 +1571,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1617,6 +1610,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index 0bca82779cf..8914a3dfa03 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -996,18 +996,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1457,7 +1455,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1775,13 +1775,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1821,6 +1814,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index 93a6b3a9b24..acd3cdf7427 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -1040,12 +1040,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1085,6 +1079,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1488,7 +1486,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1821,13 +1821,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1866,6 +1859,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index d9f8393a658..9ce293792a0 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -967,12 +967,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1016,6 +1010,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1421,7 +1419,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1735,13 +1735,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,6 +1774,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index c721709dc24..199be22595f 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -932,12 +932,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -975,6 +969,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1371,7 +1369,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1702,13 +1702,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1747,6 +1740,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index bee03f8ce15..3b269833ec2 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -822,18 +822,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1168,7 +1166,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1454,13 +1454,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1500,6 +1493,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index f9a8033ca74..f99fc034230 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -1047,12 +1047,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1169,6 +1163,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1552,7 +1550,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1888,13 +1888,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1933,6 +1926,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index 0e4db8a34f0..f0732dbf9b0 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -1057,18 +1057,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1448,7 +1446,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1806,13 +1806,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1846,6 +1839,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-documentation-diagram.lock.yml b/.github/workflows/daily-documentation-diagram.lock.yml index c6e0199585d..04994a329f6 100644 --- a/.github/workflows/daily-documentation-diagram.lock.yml +++ b/.github/workflows/daily-documentation-diagram.lock.yml @@ -1007,18 +1007,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1418,7 +1416,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1767,13 +1767,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1807,6 +1800,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index afdeff9570e..5c1c2bddbd8 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -918,12 +918,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1005,6 +999,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1366,7 +1364,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1735,6 +1728,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index 219b2fded06..a5d401e4401 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -1048,18 +1048,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1415,7 +1413,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1741,13 +1741,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1781,6 +1774,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 478b7710a68..48d713cb74d 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -965,12 +965,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -981,6 +975,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1414,7 +1412,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1716,13 +1716,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1762,6 +1755,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index 0429cc53ab9..477a163787f 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -1072,18 +1072,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1459,7 +1457,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1793,13 +1793,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1833,6 +1826,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index c7e1fee0b31..b47a840429b 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -915,12 +915,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -957,6 +951,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1388,7 +1386,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1737,6 +1730,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-firewall-report.lock.yml b/.github/workflows/daily-firewall-report.lock.yml index f518ab3fd74..8083ece25aa 100644 --- a/.github/workflows/daily-firewall-report.lock.yml +++ b/.github/workflows/daily-firewall-report.lock.yml @@ -955,18 +955,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1394,7 +1392,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1703,13 +1703,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1748,6 +1741,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 5ab50802f1a..0739b952add 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -911,12 +911,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -947,6 +941,10 @@ jobs: timeout-minutes: 25 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1386,7 +1384,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1694,13 +1694,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1740,6 +1733,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index 0d8facc6839..e6e629aefaa 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -941,18 +941,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1322,7 +1320,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1620,13 +1620,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1665,6 +1658,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index 976c5ad90a0..1d3ade19949 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -885,12 +885,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -917,6 +911,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1317,7 +1315,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1622,13 +1622,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1668,6 +1661,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml index c9ff478f594..81cc7a3a1c4 100644 --- a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml +++ b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml @@ -792,12 +792,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -806,6 +800,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1194,7 +1192,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1475,13 +1475,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1502,6 +1495,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/daily-go-test-parallelizer.lock.yml b/.github/workflows/daily-go-test-parallelizer.lock.yml index 1282e0ddc41..ef134fb18f6 100644 --- a/.github/workflows/daily-go-test-parallelizer.lock.yml +++ b/.github/workflows/daily-go-test-parallelizer.lock.yml @@ -968,18 +968,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1380,7 +1378,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1726,13 +1726,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1766,6 +1759,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-go-test-stubs-aider.lock.yml b/.github/workflows/daily-go-test-stubs-aider.lock.yml index 50c2cf595e0..8b258b805a2 100644 --- a/.github/workflows/daily-go-test-stubs-aider.lock.yml +++ b/.github/workflows/daily-go-test-stubs-aider.lock.yml @@ -880,12 +880,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -945,6 +939,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1255,7 +1253,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1571,13 +1571,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1617,6 +1610,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-grader-audit.lock.yml b/.github/workflows/daily-grader-audit.lock.yml index 85b1e9618e0..3b9efc0ab47 100644 --- a/.github/workflows/daily-grader-audit.lock.yml +++ b/.github/workflows/daily-grader-audit.lock.yml @@ -893,12 +893,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -973,6 +967,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1377,7 +1375,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1671,13 +1671,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1715,6 +1708,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index fb424f892fd..7d201d49104 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -893,12 +893,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -932,6 +926,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1331,7 +1329,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1634,13 +1634,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1680,6 +1673,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-harness-experiment-proposer.lock.yml b/.github/workflows/daily-harness-experiment-proposer.lock.yml index 7621f1067dc..aaf595bff83 100644 --- a/.github/workflows/daily-harness-experiment-proposer.lock.yml +++ b/.github/workflows/daily-harness-experiment-proposer.lock.yml @@ -936,12 +936,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1027,6 +1021,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1403,7 +1401,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index dc5bfeceffe..0ff33af3648 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -1020,18 +1020,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1413,7 +1411,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1712,13 +1712,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1758,6 +1751,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 9c8972d20dc..38016643e9c 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -1143,12 +1143,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1159,6 +1153,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1593,7 +1591,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1908,13 +1908,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1953,6 +1946,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 35fba5054b4..418a25da62f 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -887,12 +887,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -903,6 +897,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1284,7 +1282,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index abab38d3e02..0cdfbc5a5da 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -861,18 +861,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1208,7 +1206,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1523,13 +1523,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1563,6 +1556,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index 678ac2f31f3..a87a4148940 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -953,12 +953,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -994,6 +988,10 @@ jobs: timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1412,7 +1410,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1720,13 +1720,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1766,6 +1759,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index f7560c1a748..03c0d3e616d 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -893,12 +893,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -909,6 +903,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1607,7 +1605,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1910,13 +1910,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1956,6 +1949,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 31bc8d0660c..9a78249f737 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -914,12 +914,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -930,6 +924,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1317,7 +1315,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1619,13 +1619,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1664,6 +1657,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index fed17a282bc..4f17755319c 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -960,18 +960,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1332,7 +1330,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1627,13 +1627,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1672,6 +1665,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 21c56638bc3..bcd22f17209 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -1098,18 +1098,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1535,7 +1533,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1844,13 +1844,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1890,6 +1883,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index e22196b9a0e..582901513e4 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -975,18 +975,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1348,7 +1346,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1674,13 +1674,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1714,6 +1707,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 2aa6fe519fb..50009af8e29 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -1565,18 +1565,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 40 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1971,7 +1969,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2269,13 +2269,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2314,6 +2307,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-pr-review-cursor.lock.yml b/.github/workflows/daily-pr-review-cursor.lock.yml index a5f2b3e9d1c..20d2e93f763 100644 --- a/.github/workflows/daily-pr-review-cursor.lock.yml +++ b/.github/workflows/daily-pr-review-cursor.lock.yml @@ -850,12 +850,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -882,6 +876,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1264,7 +1262,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1567,13 +1567,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1612,6 +1605,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-regression-audit-kiro.lock.yml b/.github/workflows/daily-regression-audit-kiro.lock.yml index d1183e6bfe2..142faa25436 100644 --- a/.github/workflows/daily-regression-audit-kiro.lock.yml +++ b/.github/workflows/daily-regression-audit-kiro.lock.yml @@ -860,12 +860,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -892,6 +886,10 @@ jobs: timeout-minutes: 25 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1269,7 +1267,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1572,13 +1572,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1617,6 +1610,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 904beb34531..999ebcc11ca 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -1599,18 +1599,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1975,7 +1973,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2301,13 +2301,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2341,6 +2334,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index fd6814b3aee..e10b45b26b6 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -848,12 +848,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -994,6 +988,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1322,7 +1320,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1614,13 +1614,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1659,6 +1652,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 222b80eb716..1265c07fa91 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -1067,12 +1067,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1194,6 +1188,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1622,7 +1620,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1958,13 +1958,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2002,6 +1995,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 0f9195e9ebc..817fb682c51 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -901,18 +901,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1295,7 +1293,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1594,13 +1594,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1640,6 +1633,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 99b541bd4e7..b6d0fcd8969 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -913,12 +913,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -929,6 +923,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1330,7 +1328,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1660,13 +1660,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1706,6 +1699,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index fd435ce5c32..e9cfc8d1635 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -1054,12 +1054,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1167,6 +1161,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1543,7 +1541,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1848,13 +1848,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1892,6 +1885,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 99e47b48d01..a6bd44f9f88 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -875,12 +875,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -954,6 +948,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1323,7 +1321,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1625,13 +1625,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1669,6 +1662,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml index ffade3a85fc..a5bb99a9f36 100644 --- a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml +++ b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml @@ -984,12 +984,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1063,6 +1057,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1465,7 +1463,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1788,13 +1788,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1832,6 +1825,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-schema-audit-cursor.lock.yml b/.github/workflows/daily-schema-audit-cursor.lock.yml index 8411da184a5..540c3ef78d8 100644 --- a/.github/workflows/daily-schema-audit-cursor.lock.yml +++ b/.github/workflows/daily-schema-audit-cursor.lock.yml @@ -858,12 +858,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -890,6 +884,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1267,7 +1265,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1570,13 +1570,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1615,6 +1608,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index de655ff1fc4..34bd3f4188a 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -831,12 +831,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -847,6 +841,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1246,7 +1244,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1551,13 +1551,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1597,6 +1590,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index 032aa320ab3..730ac80b668 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -1024,12 +1024,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1040,6 +1034,10 @@ jobs: timeout-minutes: 60 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1471,7 +1469,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1780,13 +1780,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1825,6 +1818,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index b9b83c062dc..1eb211e6e31 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -917,12 +917,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -1063,6 +1057,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1391,7 +1389,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1737,6 +1730,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-semgrep-scan.lock.yml b/.github/workflows/daily-semgrep-scan.lock.yml index 8f4b72668c0..6045650632e 100644 --- a/.github/workflows/daily-semgrep-scan.lock.yml +++ b/.github/workflows/daily-semgrep-scan.lock.yml @@ -973,18 +973,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1342,7 +1340,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1667,13 +1667,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1707,6 +1700,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index af72e8fa51e..420e3f572aa 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -877,12 +877,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -914,6 +908,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1332,7 +1330,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1638,13 +1638,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1684,6 +1677,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-spec-coverage-kiro.lock.yml b/.github/workflows/daily-spec-coverage-kiro.lock.yml index 4d7ced16707..972d2728ce6 100644 --- a/.github/workflows/daily-spec-coverage-kiro.lock.yml +++ b/.github/workflows/daily-spec-coverage-kiro.lock.yml @@ -859,12 +859,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -890,6 +884,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1267,7 +1265,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1570,13 +1570,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1615,6 +1608,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-spending-forecast.lock.yml b/.github/workflows/daily-spending-forecast.lock.yml index b619df06ed0..165845ac40d 100644 --- a/.github/workflows/daily-spending-forecast.lock.yml +++ b/.github/workflows/daily-spending-forecast.lock.yml @@ -1088,18 +1088,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1496,7 +1494,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1818,13 +1818,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1858,6 +1851,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-squid-image-scan.lock.yml b/.github/workflows/daily-squid-image-scan.lock.yml index d023d8abd74..3947cd112a0 100644 --- a/.github/workflows/daily-squid-image-scan.lock.yml +++ b/.github/workflows/daily-squid-image-scan.lock.yml @@ -996,12 +996,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1027,6 +1021,10 @@ jobs: timeout-minutes: 90 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1414,7 +1412,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1711,13 +1711,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1757,6 +1750,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-storify.lock.yml b/.github/workflows/daily-storify.lock.yml index ab6cbd398a3..bd39324e8c1 100644 --- a/.github/workflows/daily-storify.lock.yml +++ b/.github/workflows/daily-storify.lock.yml @@ -1035,18 +1035,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1462,7 +1460,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1795,13 +1795,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1835,6 +1828,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-syntax-error-quality.lock.yml b/.github/workflows/daily-syntax-error-quality.lock.yml index 369a6363761..fbd575b540c 100644 --- a/.github/workflows/daily-syntax-error-quality.lock.yml +++ b/.github/workflows/daily-syntax-error-quality.lock.yml @@ -867,12 +867,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -883,6 +877,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1271,7 +1269,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1574,13 +1574,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1620,6 +1613,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 68113f8797e..728a2ff6836 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -912,12 +912,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1131,6 +1125,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) # shellcheck disable=SC2016 @@ -1446,7 +1444,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1738,13 +1738,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1784,6 +1777,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-team-status.lock.yml b/.github/workflows/daily-team-status.lock.yml index 525cb0ae148..a5499e5a92a 100644 --- a/.github/workflows/daily-team-status.lock.yml +++ b/.github/workflows/daily-team-status.lock.yml @@ -858,12 +858,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -889,6 +883,10 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1270,7 +1268,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1573,13 +1573,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1618,6 +1611,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index de4a6e1464b..afe8a18415d 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -935,12 +935,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -981,6 +975,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1400,7 +1398,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1705,13 +1705,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1751,6 +1744,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index d2ee026c295..50cb67c75e3 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -951,12 +951,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1170,6 +1164,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1501,7 +1499,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1795,13 +1795,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1841,6 +1834,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-trajectory-grader-implementer.lock.yml b/.github/workflows/daily-trajectory-grader-implementer.lock.yml index 34d7f3c47de..f7f654f588c 100644 --- a/.github/workflows/daily-trajectory-grader-implementer.lock.yml +++ b/.github/workflows/daily-trajectory-grader-implementer.lock.yml @@ -894,12 +894,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -936,6 +930,10 @@ jobs: timeout-minutes: 25 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1352,7 +1350,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1679,13 +1679,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1724,6 +1717,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index 1d618b68d77..81de6514009 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -869,12 +869,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -956,6 +950,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1315,7 +1313,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1609,13 +1609,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1653,6 +1646,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-windows-defender-scan.lock.yml b/.github/workflows/daily-windows-defender-scan.lock.yml index c78d9a268e0..635c095ae75 100644 --- a/.github/workflows/daily-windows-defender-scan.lock.yml +++ b/.github/workflows/daily-windows-defender-scan.lock.yml @@ -973,18 +973,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1339,7 +1337,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2104,13 +2104,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2144,6 +2137,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml index 239e58f36e7..a789d1e2090 100644 --- a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml +++ b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml @@ -891,18 +891,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1265,7 +1263,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1583,13 +1583,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1623,6 +1616,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/daily-workflow-updater.lock.yml b/.github/workflows/daily-workflow-updater.lock.yml index 7864ebfe831..e51c4a0678b 100644 --- a/.github/workflows/daily-workflow-updater.lock.yml +++ b/.github/workflows/daily-workflow-updater.lock.yml @@ -879,12 +879,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -895,6 +889,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1295,7 +1293,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1623,13 +1623,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1669,6 +1662,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/daily-yamllint-fixer.lock.yml b/.github/workflows/daily-yamllint-fixer.lock.yml index 6356f77c317..75348fe4dae 100644 --- a/.github/workflows/daily-yamllint-fixer.lock.yml +++ b/.github/workflows/daily-yamllint-fixer.lock.yml @@ -907,12 +907,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -986,6 +980,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1358,7 +1356,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1677,13 +1677,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1721,6 +1714,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index fd60710997c..8476d9b2b2b 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -1233,12 +1233,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1270,6 +1264,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1695,7 +1693,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2011,13 +2011,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2056,6 +2049,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index cdd068597ea..cf20f185f43 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -947,12 +947,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -963,6 +957,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1361,7 +1359,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1684,13 +1684,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1730,6 +1723,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index 61edcb004a5..c693290e8ac 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -1643,12 +1643,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1741,6 +1735,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -2175,7 +2173,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2491,13 +2491,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2535,6 +2528,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/deepsec-security-scan.lock.yml b/.github/workflows/deepsec-security-scan.lock.yml index 827865a2cad..a079d89ce0d 100644 --- a/.github/workflows/deepsec-security-scan.lock.yml +++ b/.github/workflows/deepsec-security-scan.lock.yml @@ -904,12 +904,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -991,6 +985,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1350,7 +1348,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1644,13 +1644,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1688,6 +1681,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index ae911087497..d6ee0a0edbb 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -908,12 +908,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -950,6 +944,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1381,7 +1379,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1737,6 +1730,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index f2ba272c4f9..918d8c4c972 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -1031,12 +1031,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1077,6 +1071,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1464,7 +1462,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1809,13 +1809,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1854,6 +1847,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/dependabot-go-checker.lock.yml b/.github/workflows/dependabot-go-checker.lock.yml index e07c2a5d3ab..9d20622bb14 100644 --- a/.github/workflows/dependabot-go-checker.lock.yml +++ b/.github/workflows/dependabot-go-checker.lock.yml @@ -1030,18 +1030,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1397,7 +1395,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1721,13 +1721,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1761,6 +1754,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index 226c0857f90..4ba6e7c5127 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -860,12 +860,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -876,6 +870,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1274,7 +1272,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1572,13 +1572,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1617,6 +1610,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index 5ad70b578ca..0ef67ff3d30 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -982,18 +982,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1346,7 +1344,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1659,13 +1659,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1704,6 +1697,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/designer-drift-audit.lock.yml b/.github/workflows/designer-drift-audit.lock.yml index 65766d9e88a..4ad14fc2dcf 100644 --- a/.github/workflows/designer-drift-audit.lock.yml +++ b/.github/workflows/designer-drift-audit.lock.yml @@ -902,18 +902,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1267,7 +1265,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1583,13 +1583,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1623,6 +1616,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index f199de52b7e..e9f10a81a76 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -1004,12 +1004,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1096,6 +1090,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1485,7 +1483,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1790,13 +1790,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1834,6 +1827,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/dev-hawk.lock.yml b/.github/workflows/dev-hawk.lock.yml index eaffcbc738d..115146412b8 100644 --- a/.github/workflows/dev-hawk.lock.yml +++ b/.github/workflows/dev-hawk.lock.yml @@ -959,12 +959,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -991,6 +985,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1380,7 +1378,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1678,13 +1678,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1724,6 +1717,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/dev.lock.yml b/.github/workflows/dev.lock.yml index 3c3e31d9cbe..61c8875829e 100644 --- a/.github/workflows/dev.lock.yml +++ b/.github/workflows/dev.lock.yml @@ -993,18 +993,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1360,7 +1358,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1700,13 +1700,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1740,6 +1733,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index cb5e6ddddfa..eca23b3436d 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -1023,12 +1023,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1140,6 +1134,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1547,7 +1545,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1875,13 +1875,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1919,6 +1912,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/dictation-prompt.lock.yml b/.github/workflows/dictation-prompt.lock.yml index f79f63b391a..112e6144653 100644 --- a/.github/workflows/dictation-prompt.lock.yml +++ b/.github/workflows/dictation-prompt.lock.yml @@ -880,12 +880,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -896,6 +890,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1296,7 +1294,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1618,13 +1618,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1664,6 +1657,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 5e08ddee968..acabd2aba94 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -892,12 +892,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -908,6 +902,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1317,7 +1315,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1616,13 +1616,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1662,6 +1655,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/draft-pr-cleanup.lock.yml b/.github/workflows/draft-pr-cleanup.lock.yml index b57ed9a9069..a1672056505 100644 --- a/.github/workflows/draft-pr-cleanup.lock.yml +++ b/.github/workflows/draft-pr-cleanup.lock.yml @@ -890,12 +890,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -921,6 +915,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1310,7 +1308,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1608,13 +1608,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1654,6 +1647,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 887ac12ccde..99f94a23d65 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -881,18 +881,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1239,7 +1237,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1526,13 +1526,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1572,6 +1565,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/eslint-miner.lock.yml b/.github/workflows/eslint-miner.lock.yml index 12482a78857..bca5004167b 100644 --- a/.github/workflows/eslint-miner.lock.yml +++ b/.github/workflows/eslint-miner.lock.yml @@ -915,12 +915,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -931,6 +925,10 @@ jobs: timeout-minutes: 120 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1350,7 +1348,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1681,13 +1681,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1727,6 +1720,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index b5043e98b18..ea56d2ae837 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -1103,18 +1103,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1470,7 +1468,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1798,13 +1798,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1838,6 +1831,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index 341a4131827..e00d515e43c 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -907,12 +907,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1004,6 +998,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1405,7 +1403,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1711,13 +1711,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1755,6 +1748,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/evoskill-evolver.lock.yml b/.github/workflows/evoskill-evolver.lock.yml index aa59bebebaa..611b901bc98 100644 --- a/.github/workflows/evoskill-evolver.lock.yml +++ b/.github/workflows/evoskill-evolver.lock.yml @@ -903,12 +903,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -946,6 +940,10 @@ jobs: timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1360,7 +1358,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1737,6 +1730,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/example-failure-category-filter.lock.yml b/.github/workflows/example-failure-category-filter.lock.yml index 3712fe7dc43..647ac34b151 100644 --- a/.github/workflows/example-failure-category-filter.lock.yml +++ b/.github/workflows/example-failure-category-filter.lock.yml @@ -915,18 +915,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1270,7 +1268,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1587,13 +1587,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1627,6 +1620,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/example-permissions-warning.lock.yml b/.github/workflows/example-permissions-warning.lock.yml index 2b94c90a047..eeb02c99020 100644 --- a/.github/workflows/example-permissions-warning.lock.yml +++ b/.github/workflows/example-permissions-warning.lock.yml @@ -853,18 +853,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1181,7 +1179,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index 8cf216ad43e..db87376b495 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -918,12 +918,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1006,6 +1000,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1354,7 +1352,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1648,13 +1648,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1692,6 +1685,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/feature-grower.lock.yml b/.github/workflows/feature-grower.lock.yml index ceec98db5a1..6ab2e4b5531 100644 --- a/.github/workflows/feature-grower.lock.yml +++ b/.github/workflows/feature-grower.lock.yml @@ -947,18 +947,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1319,7 +1317,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1638,13 +1638,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1678,6 +1671,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/firewall-escape.lock.yml b/.github/workflows/firewall-escape.lock.yml index 520e0b63c47..ee16d227c2b 100644 --- a/.github/workflows/firewall-escape.lock.yml +++ b/.github/workflows/firewall-escape.lock.yml @@ -917,12 +917,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -934,6 +928,10 @@ jobs: timeout-minutes: 60 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1358,7 +1356,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1668,13 +1668,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1714,6 +1707,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/firewall.lock.yml b/.github/workflows/firewall.lock.yml index 9f799184591..6068c401f95 100644 --- a/.github/workflows/firewall.lock.yml +++ b/.github/workflows/firewall.lock.yml @@ -778,12 +778,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -795,6 +789,10 @@ jobs: timeout-minutes: 5 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1145,7 +1143,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/front-page-copy-guard.lock.yml b/.github/workflows/front-page-copy-guard.lock.yml index cf2697d8cb0..3aec5bd887d 100644 --- a/.github/workflows/front-page-copy-guard.lock.yml +++ b/.github/workflows/front-page-copy-guard.lock.yml @@ -918,18 +918,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1282,7 +1280,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1598,13 +1598,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1638,6 +1631,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/functional-pragmatist.lock.yml b/.github/workflows/functional-pragmatist.lock.yml index 4089de019de..a90da5626b7 100644 --- a/.github/workflows/functional-pragmatist.lock.yml +++ b/.github/workflows/functional-pragmatist.lock.yml @@ -973,18 +973,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1342,7 +1340,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1731,6 +1724,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index a1259dae074..6b8b43f3c8a 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -1199,12 +1199,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1291,6 +1285,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1684,7 +1682,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1981,13 +1981,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2025,6 +2018,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 152e6879f0a..5367bb092aa 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -963,12 +963,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1054,6 +1048,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1424,7 +1422,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1746,13 +1746,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1790,6 +1783,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 1fd32e3dc37..68039a90814 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -914,18 +914,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1269,7 +1267,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1587,13 +1587,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1627,6 +1620,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index 5b472175f21..46f6ed39c56 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -1030,18 +1030,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1463,7 +1461,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1793,13 +1793,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1838,6 +1831,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index a76b70675ba..3eb785d0833 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -941,12 +941,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1067,6 +1061,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1433,7 +1431,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1734,13 +1734,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1778,6 +1771,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/go-logger.lock.yml b/.github/workflows/go-logger.lock.yml index ae93cd6ecd1..acc912233e0 100644 --- a/.github/workflows/go-logger.lock.yml +++ b/.github/workflows/go-logger.lock.yml @@ -937,12 +937,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1054,6 +1048,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1444,7 +1442,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1766,13 +1766,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1810,6 +1803,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/go-pattern-detector.lock.yml b/.github/workflows/go-pattern-detector.lock.yml index 1d1bb8c46eb..03b64a14999 100644 --- a/.github/workflows/go-pattern-detector.lock.yml +++ b/.github/workflows/go-pattern-detector.lock.yml @@ -896,12 +896,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -984,6 +978,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1375,7 +1373,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1667,13 +1667,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1711,6 +1704,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/gpclean.lock.yml b/.github/workflows/gpclean.lock.yml index 0f2b30a3213..f5ca9020986 100644 --- a/.github/workflows/gpclean.lock.yml +++ b/.github/workflows/gpclean.lock.yml @@ -1011,18 +1011,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1397,7 +1395,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1724,13 +1724,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1764,6 +1757,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index 62d55943c05..4ec74e5718b 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -1064,18 +1064,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1428,7 +1426,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1768,13 +1768,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1808,6 +1801,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/hippo-embed.lock.yml b/.github/workflows/hippo-embed.lock.yml index 7d1fd22037f..c256aa38828 100644 --- a/.github/workflows/hippo-embed.lock.yml +++ b/.github/workflows/hippo-embed.lock.yml @@ -915,18 +915,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 60 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1255,7 +1253,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/hourly-ci-cleaner.lock.yml b/.github/workflows/hourly-ci-cleaner.lock.yml index 118db5fdee1..e57be27d516 100644 --- a/.github/workflows/hourly-ci-cleaner.lock.yml +++ b/.github/workflows/hourly-ci-cleaner.lock.yml @@ -941,12 +941,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1020,6 +1014,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1447,7 +1445,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1773,13 +1773,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1817,6 +1810,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index bc49d1dac4c..e18f1a84a32 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -1062,18 +1062,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1461,7 +1459,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1759,13 +1759,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1805,6 +1798,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/instructions-janitor.lock.yml b/.github/workflows/instructions-janitor.lock.yml index bab620d4251..22c0ba7077c 100644 --- a/.github/workflows/instructions-janitor.lock.yml +++ b/.github/workflows/instructions-janitor.lock.yml @@ -930,12 +930,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1053,6 +1047,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1422,7 +1420,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1742,13 +1742,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1786,6 +1779,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/issue-arborist.lock.yml b/.github/workflows/issue-arborist.lock.yml index 43e812d11da..073908c0465 100644 --- a/.github/workflows/issue-arborist.lock.yml +++ b/.github/workflows/issue-arborist.lock.yml @@ -1085,18 +1085,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1455,7 +1453,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1782,13 +1782,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1822,6 +1815,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index 43cce76869b..fb203d6cd5c 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -1405,18 +1405,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1766,7 +1764,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2056,13 +2056,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2102,6 +2095,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/issue-triage-agent.lock.yml b/.github/workflows/issue-triage-agent.lock.yml index 2ddb8bde116..7aceac99100 100644 --- a/.github/workflows/issue-triage-agent.lock.yml +++ b/.github/workflows/issue-triage-agent.lock.yml @@ -1109,18 +1109,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1476,7 +1474,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1793,13 +1793,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1833,6 +1826,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/jsweep.lock.yml b/.github/workflows/jsweep.lock.yml index 84db655c3b6..bcd7890c605 100644 --- a/.github/workflows/jsweep.lock.yml +++ b/.github/workflows/jsweep.lock.yml @@ -921,12 +921,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -937,6 +931,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1335,7 +1333,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1642,13 +1642,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1687,6 +1680,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/layout-spec-maintainer.lock.yml b/.github/workflows/layout-spec-maintainer.lock.yml index 7022d9e503f..accdc89e025 100644 --- a/.github/workflows/layout-spec-maintainer.lock.yml +++ b/.github/workflows/layout-spec-maintainer.lock.yml @@ -897,12 +897,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -949,6 +943,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1339,7 +1337,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1666,13 +1666,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1711,6 +1704,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/lint-monster.lock.yml b/.github/workflows/lint-monster.lock.yml index d868622dbf0..42e89224a07 100644 --- a/.github/workflows/lint-monster.lock.yml +++ b/.github/workflows/lint-monster.lock.yml @@ -1097,18 +1097,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1453,7 +1451,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1779,13 +1779,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1819,6 +1812,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index 5e3125df9ad..5b2bb47a6fd 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -978,12 +978,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -995,6 +989,10 @@ jobs: timeout-minutes: 120 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1393,7 +1391,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1722,13 +1722,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1768,6 +1761,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 245a33403a6..2f7d62af01a 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -878,12 +878,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -969,6 +963,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1336,7 +1334,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1633,13 +1633,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1677,6 +1670,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index f67e7952385..6a5412a95b9 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -1164,18 +1164,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1564,7 +1562,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1885,13 +1885,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1931,6 +1924,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 95b456aff9a..0bea4f9326f 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -1192,12 +1192,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1237,6 +1231,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1647,7 +1645,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1948,13 +1948,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1993,6 +1986,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/mergefest.lock.yml b/.github/workflows/mergefest.lock.yml index f9222ccd747..efc9fc5677d 100644 --- a/.github/workflows/mergefest.lock.yml +++ b/.github/workflows/mergefest.lock.yml @@ -891,12 +891,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -945,6 +939,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1335,7 +1333,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1655,13 +1655,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1700,6 +1693,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/metrics-collector.lock.yml b/.github/workflows/metrics-collector.lock.yml index 7e2cd8408df..e6e88758144 100644 --- a/.github/workflows/metrics-collector.lock.yml +++ b/.github/workflows/metrics-collector.lock.yml @@ -1039,18 +1039,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1413,7 +1411,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1733,13 +1733,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1773,6 +1766,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/necromancer.lock.yml b/.github/workflows/necromancer.lock.yml index 8d05e041896..d254b0247e6 100644 --- a/.github/workflows/necromancer.lock.yml +++ b/.github/workflows/necromancer.lock.yml @@ -935,18 +935,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 25 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1296,7 +1294,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1609,13 +1609,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1655,6 +1648,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/notion-issue-summary.lock.yml b/.github/workflows/notion-issue-summary.lock.yml index 6ddaf8ec90d..d65634ce8f6 100644 --- a/.github/workflows/notion-issue-summary.lock.yml +++ b/.github/workflows/notion-issue-summary.lock.yml @@ -860,18 +860,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1188,7 +1186,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/objective-impact-report.lock.yml b/.github/workflows/objective-impact-report.lock.yml index 9c05a67b9aa..db0056aa489 100644 --- a/.github/workflows/objective-impact-report.lock.yml +++ b/.github/workflows/objective-impact-report.lock.yml @@ -912,12 +912,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -947,6 +941,10 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1329,7 +1327,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1625,13 +1625,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1670,6 +1663,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/org-health-report.lock.yml b/.github/workflows/org-health-report.lock.yml index 7fb81eb3f51..1efbaf454c7 100644 --- a/.github/workflows/org-health-report.lock.yml +++ b/.github/workflows/org-health-report.lock.yml @@ -937,12 +937,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -953,6 +947,10 @@ jobs: timeout-minutes: 60 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1384,7 +1382,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1685,13 +1685,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1730,6 +1723,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/outcome-collector.lock.yml b/.github/workflows/outcome-collector.lock.yml index bda286da12e..4084394a7dc 100644 --- a/.github/workflows/outcome-collector.lock.yml +++ b/.github/workflows/outcome-collector.lock.yml @@ -942,18 +942,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1325,7 +1323,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1651,13 +1651,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1691,6 +1684,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/pdf-summary.lock.yml b/.github/workflows/pdf-summary.lock.yml index 076fc3af820..985afa7e0c6 100644 --- a/.github/workflows/pdf-summary.lock.yml +++ b/.github/workflows/pdf-summary.lock.yml @@ -1070,18 +1070,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1446,7 +1444,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1791,13 +1791,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1831,6 +1824,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/plan.lock.yml b/.github/workflows/plan.lock.yml index 01351201264..0191a870572 100644 --- a/.github/workflows/plan.lock.yml +++ b/.github/workflows/plan.lock.yml @@ -1008,12 +1008,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1039,6 +1033,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1432,7 +1430,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1758,13 +1758,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1803,6 +1796,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/poem-bot.lock.yml b/.github/workflows/poem-bot.lock.yml index f3dcafe2d33..5ef5ce37fa2 100644 --- a/.github/workflows/poem-bot.lock.yml +++ b/.github/workflows/poem-bot.lock.yml @@ -1359,18 +1359,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1756,7 +1754,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2106,13 +2106,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2146,6 +2139,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index 42b0e93c96f..073e77c33e7 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -1120,18 +1120,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1489,7 +1487,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1829,13 +1829,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1869,6 +1862,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 4b65f06bd76..274340dbc03 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -1015,12 +1015,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1129,6 +1123,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1509,7 +1507,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1812,13 +1812,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1856,6 +1849,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 5bd19b349c6..5eff0b3a5ca 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -1074,12 +1074,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1106,6 +1100,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1505,7 +1503,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1826,13 +1826,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1872,6 +1865,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index 5f69969ed30..b01cc4e8619 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -879,12 +879,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -917,6 +911,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1300,7 +1298,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1596,13 +1596,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1641,6 +1634,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index f94a70501c9..bd2162b8ea7 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -1031,12 +1031,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1047,6 +1041,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1435,7 +1433,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1757,13 +1757,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1802,6 +1795,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index 5db3e5fc96d..ea00d787bf2 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -1409,18 +1409,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 25 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1851,7 +1849,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2171,13 +2171,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2217,6 +2210,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index d65940bc07b..2e824067fa0 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -1337,12 +1337,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1353,6 +1347,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1773,7 +1771,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2076,13 +2076,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2121,6 +2114,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 150f4dce5d7..e6f39bf6a9f 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -1033,12 +1033,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1125,6 +1119,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1505,7 +1503,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1802,13 +1802,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1846,6 +1839,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index f49cf5a3468..c3fceb182de 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -1099,18 +1099,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 35 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1512,7 +1510,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1858,13 +1858,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1898,6 +1891,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index 652476c7094..413ffa50f10 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -1079,18 +1079,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1475,7 +1473,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1796,13 +1796,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1836,6 +1829,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index 6c751fdf7f9..668b41c2d22 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -1114,12 +1114,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1130,6 +1124,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1523,7 +1521,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1868,13 +1868,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1913,6 +1906,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index b86272760b5..4e7961e22b8 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -864,18 +864,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1230,7 +1228,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1525,13 +1525,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1571,6 +1564,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index 04aa94b62c8..2006fbe5bb0 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -1108,18 +1108,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1509,7 +1507,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1833,13 +1833,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1878,6 +1871,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/release.lock.yml b/.github/workflows/release.lock.yml index 6272341abf5..8520173106a 100644 --- a/.github/workflows/release.lock.yml +++ b/.github/workflows/release.lock.yml @@ -878,12 +878,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -913,6 +907,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1448,7 +1446,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index b43ade637f8..0cdba40e0cf 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -954,18 +954,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1340,7 +1338,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1665,13 +1665,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1705,6 +1698,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/repo-tree-map.lock.yml b/.github/workflows/repo-tree-map.lock.yml index f2306150f02..44208998c82 100644 --- a/.github/workflows/repo-tree-map.lock.yml +++ b/.github/workflows/repo-tree-map.lock.yml @@ -814,18 +814,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1162,7 +1160,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1449,13 +1449,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1495,6 +1488,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index f02834290b9..cbb02710f62 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -873,18 +873,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1287,7 +1285,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1588,13 +1588,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1633,6 +1626,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/research.lock.yml b/.github/workflows/research.lock.yml index a42cb741da0..0722e241e2e 100644 --- a/.github/workflows/research.lock.yml +++ b/.github/workflows/research.lock.yml @@ -844,18 +844,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1204,7 +1202,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1493,13 +1493,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1539,6 +1532,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/ruflo-backed-task.lock.yml b/.github/workflows/ruflo-backed-task.lock.yml index 62c54de7094..ab727df1b26 100644 --- a/.github/workflows/ruflo-backed-task.lock.yml +++ b/.github/workflows/ruflo-backed-task.lock.yml @@ -1067,12 +1067,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1155,6 +1149,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1517,7 +1515,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1858,13 +1858,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1902,6 +1895,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 20343572f0e..99af6dd4022 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -960,12 +960,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1073,6 +1067,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1437,7 +1435,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1734,13 +1734,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1778,6 +1771,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index 866283f0496..ddadec80bcd 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -951,18 +951,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1322,7 +1320,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1643,13 +1643,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1683,6 +1676,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/schema-feature-coverage.lock.yml b/.github/workflows/schema-feature-coverage.lock.yml index 8fe9a4124aa..0f35d8a06da 100644 --- a/.github/workflows/schema-feature-coverage.lock.yml +++ b/.github/workflows/schema-feature-coverage.lock.yml @@ -952,18 +952,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1308,7 +1306,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1626,13 +1626,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1666,6 +1659,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/scout.lock.yml b/.github/workflows/scout.lock.yml index 89c04edfcda..35453a07189 100644 --- a/.github/workflows/scout.lock.yml +++ b/.github/workflows/scout.lock.yml @@ -1052,12 +1052,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1162,6 +1156,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1543,7 +1541,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1862,13 +1862,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1906,6 +1899,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/security-compliance.lock.yml b/.github/workflows/security-compliance.lock.yml index fdc2b6dcfdf..5f369905ffd 100644 --- a/.github/workflows/security-compliance.lock.yml +++ b/.github/workflows/security-compliance.lock.yml @@ -893,18 +893,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1319,7 +1317,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1619,13 +1619,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1664,6 +1657,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index 83020d8a7ec..fe93c27e264 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -1343,18 +1343,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1717,7 +1715,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2059,13 +2059,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2099,6 +2092,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 9d18b9d9a7c..1b39fda782e 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -947,12 +947,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1051,6 +1045,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1404,7 +1402,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1696,13 +1696,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1740,6 +1733,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 9b2f42d5ca7..69c39874136 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -955,12 +955,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1058,6 +1052,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1448,7 +1446,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1752,13 +1752,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1796,6 +1789,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/sighthound-security-scan.lock.yml b/.github/workflows/sighthound-security-scan.lock.yml index 44213ee13e4..c4afa4e128c 100644 --- a/.github/workflows/sighthound-security-scan.lock.yml +++ b/.github/workflows/sighthound-security-scan.lock.yml @@ -925,18 +925,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1279,7 +1277,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1595,13 +1595,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1635,6 +1628,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index c34dce6a717..7951a74cdc9 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -1066,18 +1066,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1435,7 +1433,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1775,13 +1775,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1815,6 +1808,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index c758b74faea..8ba0cc49190 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -994,12 +994,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1053,6 +1047,10 @@ jobs: timeout-minutes: 45 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1448,7 +1446,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1778,13 +1778,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1823,6 +1816,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/smoke-agent-all-merged.lock.yml b/.github/workflows/smoke-agent-all-merged.lock.yml index e1c5a6dfe43..f314de87c1f 100644 --- a/.github/workflows/smoke-agent-all-merged.lock.yml +++ b/.github/workflows/smoke-agent-all-merged.lock.yml @@ -942,12 +942,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1029,6 +1023,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1380,7 +1378,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1683,13 +1683,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1723,6 +1716,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-agent-all-none.lock.yml b/.github/workflows/smoke-agent-all-none.lock.yml index bc98b2d5840..bf1be15f3dc 100644 --- a/.github/workflows/smoke-agent-all-none.lock.yml +++ b/.github/workflows/smoke-agent-all-none.lock.yml @@ -940,12 +940,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1024,6 +1018,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1375,7 +1373,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1678,13 +1678,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1718,6 +1711,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-agent-public-approved.lock.yml b/.github/workflows/smoke-agent-public-approved.lock.yml index d942713114c..ad84e6c37ae 100644 --- a/.github/workflows/smoke-agent-public-approved.lock.yml +++ b/.github/workflows/smoke-agent-public-approved.lock.yml @@ -991,12 +991,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1078,6 +1072,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1429,7 +1427,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1735,13 +1735,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1775,6 +1768,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-agent-public-none.lock.yml b/.github/workflows/smoke-agent-public-none.lock.yml index 86ec59fb9d0..cc0a36a3f00 100644 --- a/.github/workflows/smoke-agent-public-none.lock.yml +++ b/.github/workflows/smoke-agent-public-none.lock.yml @@ -940,12 +940,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1024,6 +1018,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1375,7 +1373,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1678,13 +1678,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1718,6 +1711,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-agent-scoped-approved.lock.yml b/.github/workflows/smoke-agent-scoped-approved.lock.yml index a28ec44b4c8..14632aa8446 100644 --- a/.github/workflows/smoke-agent-scoped-approved.lock.yml +++ b/.github/workflows/smoke-agent-scoped-approved.lock.yml @@ -978,12 +978,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1081,6 +1075,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1440,7 +1438,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1743,13 +1743,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1783,6 +1776,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-aider.lock.yml b/.github/workflows/smoke-aider.lock.yml index 3f94bca1411..e91ccf07959 100644 --- a/.github/workflows/smoke-aider.lock.yml +++ b/.github/workflows/smoke-aider.lock.yml @@ -969,12 +969,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Aider Config run: | umask 077 @@ -1034,6 +1028,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1344,7 +1342,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1636,13 +1636,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1662,6 +1655,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-call-workflow.lock.yml b/.github/workflows/smoke-call-workflow.lock.yml index 286b10da50f..5a3f8bc7743 100644 --- a/.github/workflows/smoke-call-workflow.lock.yml +++ b/.github/workflows/smoke-call-workflow.lock.yml @@ -996,18 +996,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1377,7 +1375,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1677,13 +1677,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1796,6 +1789,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml index ffbeb84798e..f8707dcabae 100644 --- a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml +++ b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml @@ -933,12 +933,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -967,6 +961,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1341,7 +1339,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1645,13 +1645,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1672,6 +1665,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-ci.lock.yml b/.github/workflows/smoke-ci.lock.yml index 8246497f988..2473d705f28 100644 --- a/.github/workflows/smoke-ci.lock.yml +++ b/.github/workflows/smoke-ci.lock.yml @@ -1572,7 +1572,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore diff --git a/.github/workflows/smoke-claude-on-copilot.lock.yml b/.github/workflows/smoke-claude-on-copilot.lock.yml index 5a97ea8aa64..99ddcca55ee 100644 --- a/.github/workflows/smoke-claude-on-copilot.lock.yml +++ b/.github/workflows/smoke-claude-on-copilot.lock.yml @@ -906,12 +906,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -985,6 +979,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1345,7 +1343,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1659,13 +1659,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1704,6 +1697,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml index fe86fc01c8d..054c0081c92 100644 --- a/.github/workflows/smoke-claude.lock.yml +++ b/.github/workflows/smoke-claude.lock.yml @@ -1596,12 +1596,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1686,6 +1680,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -2155,7 +2153,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2464,13 +2464,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2504,6 +2497,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index c65e601c7cf..c420f7fc85d 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -1347,18 +1347,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1838,7 +1836,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2142,13 +2142,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2261,6 +2254,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index 6ab1c156dfc..072a9e30310 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -2207,12 +2207,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2226,6 +2220,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2736,7 +2734,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -3052,13 +3052,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3079,6 +3072,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index 1ec9483025b..6e4cedd848f 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -2223,12 +2223,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2242,6 +2236,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2755,7 +2753,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -3073,13 +3073,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3100,6 +3093,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index cb2cb6aa86e..707c345beb6 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -1971,12 +1971,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1990,6 +1984,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2471,7 +2469,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2781,13 +2781,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2808,6 +2801,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-auto.lock.yml b/.github/workflows/smoke-copilot-auto.lock.yml index a4cc4eebca4..2d5411ad147 100644 --- a/.github/workflows/smoke-copilot-auto.lock.yml +++ b/.github/workflows/smoke-copilot-auto.lock.yml @@ -896,18 +896,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 5 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1292,7 +1290,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1593,13 +1593,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1620,6 +1613,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-mai.lock.yml b/.github/workflows/smoke-copilot-mai.lock.yml index ee7256f3857..0af773ceb57 100644 --- a/.github/workflows/smoke-copilot-mai.lock.yml +++ b/.github/workflows/smoke-copilot-mai.lock.yml @@ -971,18 +971,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1368,7 +1366,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1670,13 +1670,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1697,6 +1690,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-sdk.lock.yml b/.github/workflows/smoke-copilot-sdk.lock.yml index db86a0019db..9c63dafe87b 100644 --- a/.github/workflows/smoke-copilot-sdk.lock.yml +++ b/.github/workflows/smoke-copilot-sdk.lock.yml @@ -942,12 +942,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -958,6 +952,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1337,7 +1335,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1639,13 +1639,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1666,6 +1659,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-small.lock.yml b/.github/workflows/smoke-copilot-small.lock.yml index 72d70502431..5afe202a29b 100644 --- a/.github/workflows/smoke-copilot-small.lock.yml +++ b/.github/workflows/smoke-copilot-small.lock.yml @@ -969,18 +969,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1363,7 +1361,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1665,13 +1665,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1692,6 +1685,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot-sub-agents.lock.yml b/.github/workflows/smoke-copilot-sub-agents.lock.yml index f3a71f72d10..80062b79df5 100644 --- a/.github/workflows/smoke-copilot-sub-agents.lock.yml +++ b/.github/workflows/smoke-copilot-sub-agents.lock.yml @@ -896,12 +896,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -912,6 +906,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1301,7 +1299,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1588,13 +1588,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1615,6 +1608,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index 15a6a1b0ef8..86359902724 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -2230,12 +2230,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -2249,6 +2243,10 @@ jobs: timeout-minutes: 8 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2767,7 +2765,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -3085,13 +3085,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -3112,6 +3105,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-create-cross-repo-pr.lock.yml b/.github/workflows/smoke-create-cross-repo-pr.lock.yml index 6a4052bd2db..a1c1fb392b3 100644 --- a/.github/workflows/smoke-create-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-create-cross-repo-pr.lock.yml @@ -1050,18 +1050,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1438,7 +1436,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1743,13 +1743,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1770,6 +1763,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 8318e86d538..548a27e2efd 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -1026,12 +1026,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Crush Config run: | umask 077 @@ -1301,6 +1295,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1687,7 +1685,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1979,13 +1979,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2005,6 +1998,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 27c0d2826ad..2688f6a2779 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -1024,12 +1024,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Cursor harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1188,6 +1182,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1567,7 +1565,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1858,13 +1858,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1885,6 +1878,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index a1c57c778b1..5d9c673d364 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -971,12 +971,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write DeepSeek Harness harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1099,6 +1093,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1477,7 +1475,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1769,13 +1769,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1795,6 +1788,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-drive.lock.yml b/.github/workflows/smoke-drive.lock.yml index 8fa4d9b3f90..81a6ea88261 100644 --- a/.github/workflows/smoke-drive.lock.yml +++ b/.github/workflows/smoke-drive.lock.yml @@ -1089,18 +1089,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1480,7 +1478,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1779,13 +1779,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1898,6 +1891,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index b00193b03e0..dd2eef5fe8d 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -1085,12 +1085,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Gemini Config run: | mkdir -p "$GITHUB_WORKSPACE/.gemini" @@ -1110,6 +1104,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1545,7 +1543,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1866,13 +1866,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1911,6 +1904,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/smoke-github-claude.lock.yml b/.github/workflows/smoke-github-claude.lock.yml index 0ebb63c8eae..0ed007f4bbf 100644 --- a/.github/workflows/smoke-github-claude.lock.yml +++ b/.github/workflows/smoke-github-claude.lock.yml @@ -906,12 +906,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -985,6 +979,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1345,7 +1343,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1659,13 +1659,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1704,6 +1697,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 5fa07774bf4..2f993dec3c9 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -1053,12 +1053,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Goose harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1272,6 +1266,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1659,7 +1657,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1951,13 +1951,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1977,6 +1970,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-issues.lock.yml b/.github/workflows/smoke-issues.lock.yml index 9230ff03b18..2befde32dc6 100644 --- a/.github/workflows/smoke-issues.lock.yml +++ b/.github/workflows/smoke-issues.lock.yml @@ -876,18 +876,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 5 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1265,7 +1263,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1561,13 +1561,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1606,6 +1599,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index c43bd72b193..d036052195d 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -1024,12 +1024,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Kiro harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1109,6 +1103,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1476,7 +1474,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1767,13 +1767,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1794,6 +1787,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-multi-pr.lock.yml b/.github/workflows/smoke-multi-pr.lock.yml index 944dbdf9243..9df2e5510ff 100644 --- a/.github/workflows/smoke-multi-pr.lock.yml +++ b/.github/workflows/smoke-multi-pr.lock.yml @@ -988,12 +988,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1026,6 +1020,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1401,7 +1399,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1707,13 +1707,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1734,6 +1727,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index dfb221d0992..2ae4e3f7861 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -982,12 +982,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write OpenCode Config run: | umask 077 @@ -1128,6 +1122,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1513,7 +1511,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1805,13 +1805,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1831,6 +1824,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-otel-backends.lock.yml b/.github/workflows/smoke-otel-backends.lock.yml index dcd49d58aa9..ac42649cc29 100644 --- a/.github/workflows/smoke-otel-backends.lock.yml +++ b/.github/workflows/smoke-otel-backends.lock.yml @@ -1157,18 +1157,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1531,7 +1529,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1830,13 +1830,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1949,6 +1942,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index def1e8eb7fa..45e5cd95fbd 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -1007,18 +1007,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1378,7 +1376,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1674,13 +1674,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1701,6 +1694,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-project.lock.yml b/.github/workflows/smoke-project.lock.yml index 7cd0626494e..fbf2dca0f6d 100644 --- a/.github/workflows/smoke-project.lock.yml +++ b/.github/workflows/smoke-project.lock.yml @@ -1242,18 +1242,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1710,7 +1708,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2047,13 +2047,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2074,6 +2067,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-pydantic.lock.yml b/.github/workflows/smoke-pydantic.lock.yml index 6bd5dd84133..e88b57d064f 100644 --- a/.github/workflows/smoke-pydantic.lock.yml +++ b/.github/workflows/smoke-pydantic.lock.yml @@ -1033,12 +1033,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Write Pydantic AI harness script run: | mkdir -p "${RUNNER_TEMP}/gh-aw/actions" @@ -1426,6 +1420,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/agent-stdio.log) GH_AW_MAX_AI_CREDITS="${GH_AW_MAX_AI_CREDITS:-1000}" @@ -1743,7 +1741,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2034,13 +2034,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -2060,6 +2053,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-service-ports.lock.yml b/.github/workflows/smoke-service-ports.lock.yml index 7fc9c284612..02fb4b3178f 100644 --- a/.github/workflows/smoke-service-ports.lock.yml +++ b/.github/workflows/smoke-service-ports.lock.yml @@ -898,18 +898,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1314,7 +1312,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1607,13 +1607,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1634,6 +1627,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-temporary-id.lock.yml b/.github/workflows/smoke-temporary-id.lock.yml index c39722ef510..76fb2295276 100644 --- a/.github/workflows/smoke-temporary-id.lock.yml +++ b/.github/workflows/smoke-temporary-id.lock.yml @@ -1002,18 +1002,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1430,7 +1428,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1731,13 +1731,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1758,6 +1751,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-test-tools.lock.yml b/.github/workflows/smoke-test-tools.lock.yml index af5a9af9274..c45f2ae52eb 100644 --- a/.github/workflows/smoke-test-tools.lock.yml +++ b/.github/workflows/smoke-test-tools.lock.yml @@ -952,18 +952,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 5 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1376,7 +1374,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1669,13 +1669,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1696,6 +1689,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-update-cross-repo-pr.lock.yml b/.github/workflows/smoke-update-cross-repo-pr.lock.yml index 1ebd8d3356a..c8abcf4e870 100644 --- a/.github/workflows/smoke-update-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-update-cross-repo-pr.lock.yml @@ -1047,18 +1047,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1454,7 +1452,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1762,13 +1762,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1789,6 +1782,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml index 3c95db02e4b..596d29e3fec 100644 --- a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml +++ b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml @@ -956,12 +956,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -986,6 +980,10 @@ jobs: timeout-minutes: 5 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1347,7 +1345,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1628,13 +1628,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1655,6 +1648,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/smoke-workflow-call.lock.yml b/.github/workflows/smoke-workflow-call.lock.yml index e7fbfbeb7cd..857e9b587ff 100644 --- a/.github/workflows/smoke-workflow-call.lock.yml +++ b/.github/workflows/smoke-workflow-call.lock.yml @@ -948,12 +948,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -982,6 +976,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1356,7 +1354,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1638,13 +1638,6 @@ jobs: touch /tmp/gh-aw/threat-detection/detection.log rm -f /tmp/gh-aw/step-summary.md touch /tmp/gh-aw/step-summary.md - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: @@ -1665,6 +1658,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" diff --git a/.github/workflows/spec-enforcer.lock.yml b/.github/workflows/spec-enforcer.lock.yml index 2e3af3f91f5..20d03ee9dec 100644 --- a/.github/workflows/spec-enforcer.lock.yml +++ b/.github/workflows/spec-enforcer.lock.yml @@ -1039,18 +1039,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1437,7 +1435,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1789,13 +1789,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1829,6 +1822,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 41de4af049a..7e3b704e967 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -960,12 +960,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1011,6 +1005,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1414,7 +1412,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1743,13 +1743,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1789,6 +1782,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 6eeab0260ea..0db3b7d7eaf 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -899,12 +899,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -956,6 +950,10 @@ jobs: timeout-minutes: 25 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1338,7 +1336,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1640,13 +1640,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1686,6 +1679,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/squad-game-planner.lock.yml b/.github/workflows/squad-game-planner.lock.yml index 2569548cf54..6c54ed00663 100644 --- a/.github/workflows/squad-game-planner.lock.yml +++ b/.github/workflows/squad-game-planner.lock.yml @@ -904,18 +904,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1298,7 +1296,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1593,13 +1593,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1639,6 +1632,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/squad-implement-worker.lock.yml b/.github/workflows/squad-implement-worker.lock.yml index 44d1fae49ab..037e84020e1 100644 --- a/.github/workflows/squad-implement-worker.lock.yml +++ b/.github/workflows/squad-implement-worker.lock.yml @@ -1056,18 +1056,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1453,7 +1451,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1757,13 +1757,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1803,6 +1796,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/squad-plan.lock.yml b/.github/workflows/squad-plan.lock.yml index bb9f82cb61f..a111223a0a4 100644 --- a/.github/workflows/squad-plan.lock.yml +++ b/.github/workflows/squad-plan.lock.yml @@ -961,18 +961,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1356,7 +1354,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1673,13 +1673,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1719,6 +1712,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/squad.lock.yml b/.github/workflows/squad.lock.yml index a914ece613b..acae4fc100f 100644 --- a/.github/workflows/squad.lock.yml +++ b/.github/workflows/squad.lock.yml @@ -1592,18 +1592,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1990,7 +1988,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -2316,13 +2316,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -2362,6 +2355,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/stale-pr-cleanup.lock.yml b/.github/workflows/stale-pr-cleanup.lock.yml index 6e04339ec57..000cec4eb1f 100644 --- a/.github/workflows/stale-pr-cleanup.lock.yml +++ b/.github/workflows/stale-pr-cleanup.lock.yml @@ -889,12 +889,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -920,6 +914,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1304,7 +1302,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1602,13 +1602,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1648,6 +1641,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index bb34cbfa04e..c61dc539acf 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -1087,18 +1087,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1489,7 +1487,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1782,13 +1782,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1828,6 +1821,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/static-analysis-report.lock.yml b/.github/workflows/static-analysis-report.lock.yml index 443e0f9e6d2..ea4af6eed3d 100644 --- a/.github/workflows/static-analysis-report.lock.yml +++ b/.github/workflows/static-analysis-report.lock.yml @@ -1024,12 +1024,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1116,6 +1110,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1484,7 +1482,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1779,13 +1779,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1823,6 +1816,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/step-name-alignment.lock.yml b/.github/workflows/step-name-alignment.lock.yml index 0a6be0829de..88593044c0a 100644 --- a/.github/workflows/step-name-alignment.lock.yml +++ b/.github/workflows/step-name-alignment.lock.yml @@ -874,12 +874,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -985,6 +979,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1361,7 +1359,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1656,13 +1656,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1700,6 +1693,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/sub-issue-closer.lock.yml b/.github/workflows/sub-issue-closer.lock.yml index e9bda2254ad..ddaf1296836 100644 --- a/.github/workflows/sub-issue-closer.lock.yml +++ b/.github/workflows/sub-issue-closer.lock.yml @@ -880,18 +880,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1239,7 +1237,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1526,13 +1526,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1572,6 +1565,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/super-linter.lock.yml b/.github/workflows/super-linter.lock.yml index 0a339e57e02..2f31f44f7cd 100644 --- a/.github/workflows/super-linter.lock.yml +++ b/.github/workflows/super-linter.lock.yml @@ -869,18 +869,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1236,7 +1234,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1524,13 +1524,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1570,6 +1563,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/technical-doc-writer.lock.yml b/.github/workflows/technical-doc-writer.lock.yml index 938d3fd3989..f4e0f964064 100644 --- a/.github/workflows/technical-doc-writer.lock.yml +++ b/.github/workflows/technical-doc-writer.lock.yml @@ -1041,18 +1041,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1493,7 +1491,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1824,13 +1824,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1869,6 +1862,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index 187819e1951..e64633257ea 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -861,18 +861,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 10 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1209,7 +1207,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1496,13 +1496,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1542,6 +1535,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index f8042314dc2..28c34790143 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -1001,12 +1001,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1035,6 +1029,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1432,7 +1430,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1759,13 +1759,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1806,6 +1799,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/tidy.lock.yml b/.github/workflows/tidy.lock.yml index 7668c19561a..912324250ad 100644 --- a/.github/workflows/tidy.lock.yml +++ b/.github/workflows/tidy.lock.yml @@ -996,12 +996,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -1036,6 +1030,10 @@ jobs: timeout-minutes: 20 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1423,7 +1421,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1769,13 +1769,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1814,6 +1807,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index cb4dc356950..bc0a8983007 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -944,12 +944,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Claude Code CLI id: agentic_execution # Allowed tools (sorted): @@ -1054,6 +1048,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1414,7 +1412,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1716,13 +1716,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1760,6 +1753,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index 4bcca9e9128..ec5c43445ce 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -897,12 +897,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -938,6 +932,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1323,7 +1321,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1650,13 +1650,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1695,6 +1688,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index 45b96ef2817..efc0153cf12 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -890,12 +890,6 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -923,6 +917,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1306,7 +1304,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1610,13 +1610,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1655,6 +1648,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index 8b0bd07d743..a63b263ac24 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -1033,18 +1033,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1417,7 +1415,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1756,13 +1756,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1801,6 +1794,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/update-astro.lock.yml b/.github/workflows/update-astro.lock.yml index 7768a789d3b..b29b89e3179 100644 --- a/.github/workflows/update-astro.lock.yml +++ b/.github/workflows/update-astro.lock.yml @@ -997,18 +997,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 45 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1401,7 +1399,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1748,13 +1748,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1788,6 +1781,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/video-analyzer.lock.yml b/.github/workflows/video-analyzer.lock.yml index 4f62724202a..ef7254d076e 100644 --- a/.github/workflows/video-analyzer.lock.yml +++ b/.github/workflows/video-analyzer.lock.yml @@ -838,18 +838,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 15 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1185,7 +1183,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1470,13 +1470,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1516,6 +1509,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/visual-regression-checker.lock.yml b/.github/workflows/visual-regression-checker.lock.yml index 68476a312d1..064384b5fe0 100644 --- a/.github/workflows/visual-regression-checker.lock.yml +++ b/.github/workflows/visual-regression-checker.lock.yml @@ -920,12 +920,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -956,6 +950,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1330,7 +1328,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1626,13 +1626,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1671,6 +1664,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/weekly-blog-post-writer.lock.yml b/.github/workflows/weekly-blog-post-writer.lock.yml index 56a467cf6be..58ea5402cff 100644 --- a/.github/workflows/weekly-blog-post-writer.lock.yml +++ b/.github/workflows/weekly-blog-post-writer.lock.yml @@ -1090,18 +1090,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1517,7 +1515,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1856,13 +1856,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1901,6 +1894,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/weekly-editors-health-check.lock.yml b/.github/workflows/weekly-editors-health-check.lock.yml index 524222c2f09..95431991c4c 100644 --- a/.github/workflows/weekly-editors-health-check.lock.yml +++ b/.github/workflows/weekly-editors-health-check.lock.yml @@ -933,12 +933,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -975,6 +969,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1364,7 +1362,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1691,13 +1691,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1736,6 +1729,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index 2a0572b3ded..a86db029c23 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -877,18 +877,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1259,7 +1257,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1554,13 +1554,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1600,6 +1593,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/weekly-network-domains-audit.lock.yml b/.github/workflows/weekly-network-domains-audit.lock.yml index c238b30b43b..c8f4037ad7b 100644 --- a/.github/workflows/weekly-network-domains-audit.lock.yml +++ b/.github/workflows/weekly-network-domains-audit.lock.yml @@ -844,18 +844,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1210,7 +1208,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1504,13 +1504,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1550,6 +1543,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml index 73c9892a58e..fd4195a1023 100644 --- a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml +++ b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml @@ -877,18 +877,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Pi CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1228,7 +1226,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1544,13 +1544,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1590,6 +1583,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/windows-grower.lock.yml b/.github/workflows/windows-grower.lock.yml index 0398873e788..af90ba7e6f0 100644 --- a/.github/workflows/windows-grower.lock.yml +++ b/.github/workflows/windows-grower.lock.yml @@ -921,18 +921,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 20 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1303,7 +1301,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1623,13 +1623,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1663,6 +1656,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/windows.lock.yml b/.github/workflows/windows.lock.yml index 0fb60096b92..0ad0814f740 100644 --- a/.github/workflows/windows.lock.yml +++ b/.github/workflows/windows.lock.yml @@ -1039,13 +1039,6 @@ jobs: continue-on-error: true shell: bash run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - shell: bash - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 10 @@ -1053,6 +1046,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1406,7 +1403,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1746,13 +1745,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1786,6 +1778,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/workflow-generator.lock.yml b/.github/workflows/workflow-generator.lock.yml index 21675652fd8..34fddcb0234 100644 --- a/.github/workflows/workflow-generator.lock.yml +++ b/.github/workflows/workflow-generator.lock.yml @@ -954,18 +954,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 5 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1351,7 +1349,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1649,13 +1649,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1694,6 +1687,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/workflow-health-manager.lock.yml b/.github/workflows/workflow-health-manager.lock.yml index 5e77727de43..a9a02a981eb 100644 --- a/.github/workflows/workflow-health-manager.lock.yml +++ b/.github/workflows/workflow-health-manager.lock.yml @@ -980,18 +980,16 @@ jobs: CLI_PROXY_IMAGE: 'ghcr.io/github/gh-aw-mcpg:v0.4.20' run: | bash "${RUNNER_TEMP}/gh-aw/actions/start_cli_proxy.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1403,7 +1401,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1703,13 +1703,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1748,6 +1741,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/.github/workflows/workflow-normalizer.lock.yml b/.github/workflows/workflow-normalizer.lock.yml index db0433eb18b..447630f91fe 100644 --- a/.github/workflows/workflow-normalizer.lock.yml +++ b/.github/workflows/workflow-normalizer.lock.yml @@ -1034,18 +1034,16 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute Codex CLI id: agentic_execution timeout-minutes: 30 run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1407,7 +1405,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1732,13 +1732,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1772,6 +1765,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) diff --git a/.github/workflows/workflow-skill-extractor.lock.yml b/.github/workflows/workflow-skill-extractor.lock.yml index 880db7ff98e..90f65cac0f5 100644 --- a/.github/workflows/workflow-skill-extractor.lock.yml +++ b/.github/workflows/workflow-skill-extractor.lock.yml @@ -889,12 +889,6 @@ jobs: id: pre_agent_audit continue-on-error: true run: bash "${RUNNER_TEMP}/gh-aw/actions/audit_pre_agent_workspace.sh" - - name: Mark agent execution started - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Execute GitHub Copilot CLI id: agentic_execution # Copilot CLI tool arguments (sorted): @@ -923,6 +917,10 @@ jobs: timeout-minutes: 30 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1296,7 +1294,9 @@ jobs: /tmp/gh-aw/usage/graders/grader_results.json /tmp/gh-aw/usage/github_rate_limits.jsonl /tmp/gh-aw/usage/agent/token_usage.jsonl + /tmp/gh-aw/usage/agent/execution.json /tmp/gh-aw/usage/detection/token_usage.jsonl + /tmp/gh-aw/usage/detection/execution.json /tmp/gh-aw/usage/evals/token_usage.jsonl /tmp/gh-aw/usage/activity/summary.json if-no-files-found: ignore @@ -1594,13 +1594,6 @@ jobs: continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.1 - - name: Mark detection execution started - if: always() && steps.detection_guard.outputs.run_detection == 'true' - run: | - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' @@ -1639,6 +1632,10 @@ jobs: HAS_PATCH: ${{ needs.agent.outputs.has_patch }} GH_AW_DETECTION_CONTINUE_ON_ERROR: "true" run: | + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" set -o pipefail printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt GH_AW_COPILOT_SRC="$(command -v copilot 2>/dev/null || true)" diff --git a/pkg/workflow/compiler_yaml_ai_execution.go b/pkg/workflow/compiler_yaml_ai_execution.go index ee6268cae48..819b1c9122d 100644 --- a/pkg/workflow/compiler_yaml_ai_execution.go +++ b/pkg/workflow/compiler_yaml_ai_execution.go @@ -34,6 +34,47 @@ func generateComponentExecutionEvidenceStep(component, state, filePath, conditio return lines } +func componentExecutionEvidenceShellLines(component, state, filePath string) []string { + return []string{ + fmt.Sprintf("mkdir -p %q", path.Dir(filePath)), + fmt.Sprintf("evidence_tmp=%q", filePath+".tmp"), + fmt.Sprintf("printf '{\"version\":1,\"component\":\"%s\",\"run_id\":%%s,\"run_attempt\":%%s,\"state\":\"%s\"}\\n' \"$GITHUB_RUN_ID\" \"$GITHUB_RUN_ATTEMPT\" > \"$evidence_tmp\"", component, state), + fmt.Sprintf("mv \"$evidence_tmp\" %q", filePath), + } +} + +func injectComponentExecutionStarted(step GitHubActionStep, component, filePath string) GitHubActionStep { + runIndex := -1 + for i, line := range step { + if strings.TrimSpace(line) == "run: |" { + runIndex = i + break + } + } + if runIndex < 0 { + return step + } + + insertIndex := runIndex + 1 + for insertIndex < len(step) { + trimmed := strings.TrimSpace(step[insertIndex]) + if trimmed == "set -o pipefail" || strings.HasPrefix(trimmed, "trap 'gh_aw_exit_code=") { + insertIndex++ + continue + } + break + } + + startedLines := componentExecutionEvidenceShellLines(component, "started", filePath) + injected := make(GitHubActionStep, 0, len(step)+len(startedLines)) + injected = append(injected, step[:insertIndex]...) + for _, line := range startedLines { + injected = append(injected, " "+line) + } + injected = append(injected, step[insertIndex:]...) + return injected +} + // generateEngineExecutionSteps generates the GitHub Actions steps for executing the AI engine func (c *Compiler) generateEngineExecutionSteps(yaml *strings.Builder, data *WorkflowData, engine CodingAgentEngine, logFile string) { // --use-samples (hidden) replaces the agent step with a deterministic driver @@ -49,6 +90,12 @@ func (c *Compiler) generateEngineExecutionSteps(yaml *strings.Builder, data *Wor compilerYamlLog.Printf("Generating engine execution steps: engine=%s, steps=%d", engine.GetID(), len(steps)) for _, step := range steps { + for _, line := range step { + if strings.Contains(line, "id: agentic_execution") { + step = injectComponentExecutionStarted(step, "agent", agentExecutionEvidencePath) + break + } + } for _, line := range step { yaml.WriteString(line) yaml.WriteByte('\n') @@ -528,11 +575,6 @@ func (c *Compiler) generateAgentRunSteps(yaml *strings.Builder, data *WorkflowDa // Add AI execution step using the agentic engine compilerYamlLog.Printf("Generating engine execution steps for %s", engine.GetID()) - if !data.UseSamples { - for _, line := range generateComponentExecutionEvidenceStep("agent", "started", agentExecutionEvidencePath, "") { - yaml.WriteString(line) - } - } c.generateEngineExecutionSteps(yaml, data, engine, logFileFull) // Stop CLI proxy after AWF execution (always runs to ensure cleanup) diff --git a/pkg/workflow/daily_aic_workflow_guardrail_test.go b/pkg/workflow/daily_aic_workflow_guardrail_test.go index edd6672302f..c0d96a8918e 100644 --- a/pkg/workflow/daily_aic_workflow_guardrail_test.go +++ b/pkg/workflow/daily_aic_workflow_guardrail_test.go @@ -225,9 +225,12 @@ Pre-agent failure accounting test` lockStr := string(lockContent) initialize := strings.Index(lockStr, "name: Initialize agent execution evidence") failure := strings.Index(lockStr, "name: Fail before agent execution") - started := strings.Index(lockStr, "name: Mark agent execution started") execution := strings.Index(lockStr, "id: agentic_execution") - if initialize < 0 || failure <= initialize || started <= failure || execution <= started { + started := -1 + if execution >= 0 { + started = strings.Index(lockStr[execution:], `"state":"started"`) + } + if initialize < 0 || failure <= initialize || execution <= failure || started < 0 { t.Fatalf("expected execution evidence to prove a setup failure occurred before agent execution") } if !strings.Contains(lockStr, "/tmp/gh-aw/agent_execution.json") { diff --git a/pkg/workflow/notify_comment.go b/pkg/workflow/notify_comment.go index 33ca10fb6a8..b7bbf45dadd 100644 --- a/pkg/workflow/notify_comment.go +++ b/pkg/workflow/notify_comment.go @@ -248,7 +248,9 @@ func buildUsageArtifactUploadSteps(prefix string, hasEvals bool, pinAction func( " /tmp/gh-aw/usage/graders/grader_results.json\n", " /tmp/gh-aw/usage/github_rate_limits.jsonl\n", " /tmp/gh-aw/usage/agent/token_usage.jsonl\n", + " /tmp/gh-aw/usage/agent/execution.json\n", " /tmp/gh-aw/usage/detection/token_usage.jsonl\n", + " /tmp/gh-aw/usage/detection/execution.json\n", " /tmp/gh-aw/usage/evals/token_usage.jsonl\n", " /tmp/gh-aw/usage/activity/summary.json\n", " if-no-files-found: ignore\n", diff --git a/pkg/workflow/notify_comment_test.go b/pkg/workflow/notify_comment_test.go index dad05b155b5..16e6fdce8ae 100644 --- a/pkg/workflow/notify_comment_test.go +++ b/pkg/workflow/notify_comment_test.go @@ -1356,9 +1356,15 @@ func TestConclusionJobIncludesUsageArtifactSteps(t *testing.T) { if !strings.Contains(allSteps, "/tmp/gh-aw/usage/agent/token_usage.jsonl") { t.Errorf("Expected usage artifact to include agent token usage path.\nGenerated steps:\n%s", allSteps) } + if !strings.Contains(allSteps, "/tmp/gh-aw/usage/agent/execution.json") { + t.Errorf("Expected usage artifact to include agent execution evidence path.\nGenerated steps:\n%s", allSteps) + } if !strings.Contains(allSteps, "/tmp/gh-aw/usage/detection/token_usage.jsonl") { t.Errorf("Expected usage artifact to include detection token usage path.\nGenerated steps:\n%s", allSteps) } + if !strings.Contains(allSteps, "/tmp/gh-aw/usage/detection/execution.json") { + t.Errorf("Expected usage artifact to include detection execution evidence path.\nGenerated steps:\n%s", allSteps) + } if !strings.Contains(allSteps, "/tmp/gh-aw/usage/activity/summary.json") { t.Errorf("Expected usage artifact to include activity summary path.\nGenerated steps:\n%s", allSteps) } @@ -1435,6 +1441,12 @@ func TestConclusionJobIncludesUsageArtifactSteps(t *testing.T) { if !strings.Contains(script, ": > /tmp/gh-aw/usage/detection/token_usage.jsonl") { t.Errorf("Expected collect script to ensure detection token usage file exists.\nScript:\n%s", script) } + if !strings.Contains(script, "cp /tmp/gh-aw/agent_execution.json /tmp/gh-aw/usage/agent/execution.json") { + t.Errorf("Expected collect script to copy agent execution evidence into usage artifact staging.\nScript:\n%s", script) + } + if !strings.Contains(script, "cp /tmp/gh-aw/threat-detection/execution.json /tmp/gh-aw/usage/detection/execution.json") { + t.Errorf("Expected collect script to copy detection execution evidence into usage artifact staging.\nScript:\n%s", script) + } if !strings.Contains(script, "generate_usage_activity_summary.cjs") { t.Errorf("Expected collect script to generate activity summary aggregates.\nScript:\n%s", script) } diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden index 68f05156faa..b71f597950c 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden @@ -360,6 +360,12 @@ jobs: GH_AW_INFO_VERSION: "CLAUDE_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "claude" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -585,6 +591,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -760,6 +770,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/claude-debug.log /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden index 9d58f9e54b5..4f19611ab67 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden @@ -361,6 +361,12 @@ jobs: GH_AW_INFO_VERSION: "CODEX_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "codex" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -572,6 +578,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -743,6 +753,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/mcp-config/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden index 2b141132dbf..409bc5cee5e 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden @@ -360,6 +360,12 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -519,6 +525,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -718,6 +728,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden index ffb97036b82..602eb08222d 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden @@ -351,6 +351,12 @@ jobs: GH_AW_INFO_VERSION: "0.59.0" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "gemini" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -523,6 +529,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -678,6 +688,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/gemini-client-error-*.json /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden index 736d0b30df0..d88d7517481 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden @@ -350,6 +350,12 @@ jobs: GH_AW_INFO_VERSION: "PI_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "pi" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -453,6 +459,10 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -610,6 +620,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/pi-streaming.jsonl /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden index 1ad5a5e0aa3..23d29368ee9 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden @@ -360,6 +360,12 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -519,6 +525,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -718,6 +728,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden index a4bc5cac619..0823e5f613a 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden @@ -360,6 +360,12 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -552,6 +558,10 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -752,6 +762,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden index 73f66df7b1c..73c22f568e4 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden @@ -402,6 +402,12 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -681,6 +687,10 @@ jobs: timeout-minutes: 15 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -881,6 +891,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden index 76ad756e5e5..6a0372aea4e 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden @@ -361,6 +361,12 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -520,6 +526,10 @@ jobs: timeout-minutes: 10 run: | set -o pipefail + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -719,6 +729,7 @@ jobs: name: agent path: | /tmp/gh-aw/aw-prompts/prompt.txt + /tmp/gh-aw/agent_execution.json /tmp/gh-aw/sandbox/agent/logs/ /tmp/gh-aw/redacted-urls.log /tmp/gh-aw/mcp-logs/ diff --git a/pkg/workflow/threat_detection_external.go b/pkg/workflow/threat_detection_external.go index 70dbb7f0b56..74186961164 100644 --- a/pkg/workflow/threat_detection_external.go +++ b/pkg/workflow/threat_detection_external.go @@ -531,6 +531,9 @@ func (c *Compiler) buildExternalDetectorExecutionStep(data *WorkflowData) []stri // threat-detect without interpolating user-controlled prompt text into a command. steps = append(steps, c.buildThreatDetectionContextEnvVars(data, continueOnError, continueOnErrorExpr)...) steps = append(steps, " run: |\n") + for _, line := range componentExecutionEvidenceShellLines("detection", "started", detectionExecutionEvidencePath) { + steps = append(steps, " "+line+"\n") + } for _, line := range strings.SplitAfter(command, "\n") { if line == "" { continue diff --git a/pkg/workflow/threat_detection_inline_engine.go b/pkg/workflow/threat_detection_inline_engine.go index 5e967881211..35df29fdee2 100644 --- a/pkg/workflow/threat_detection_inline_engine.go +++ b/pkg/workflow/threat_detection_inline_engine.go @@ -215,6 +215,7 @@ func (c *Compiler) buildDetectionEngineExecutionStep(data *WorkflowData) []strin for _, line := range step { if strings.Contains(line, "id: agentic_execution") { isAWFExecutionStep = true + step = injectComponentExecutionStarted(step, "detection", detectionExecutionEvidencePath) break } } diff --git a/pkg/workflow/threat_detection_steps.go b/pkg/workflow/threat_detection_steps.go index 4597b463a36..40a8369103e 100644 --- a/pkg/workflow/threat_detection_steps.go +++ b/pkg/workflow/threat_detection_steps.go @@ -84,7 +84,6 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { //nolin steps = append(steps, c.buildInstallThreatDetectStep(data)...) // Step 11: Run threat-detect under AWF with a read-write mount for the result file - steps = append(steps, generateComponentExecutionEvidenceStep("detection", "started", detectionExecutionEvidencePath, detectionStepCondition)...) steps = append(steps, c.buildExternalDetectorExecutionStep(data)...) // Step 11a: Render detection.log to the Actions log wrapped in group/stop-commands macros. @@ -111,7 +110,6 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { //nolin // Inline engine path (default) // Step 7: Engine execution (AWF, no network) - steps = append(steps, generateComponentExecutionEvidenceStep("detection", "started", detectionExecutionEvidencePath, detectionStepCondition)...) steps = append(steps, c.buildDetectionEngineExecutionStep(data)...) // Step 7a: Echo detection step summary so the GitHub runner can mask any secrets. diff --git a/pkg/workflow/threat_detection_steps_test.go b/pkg/workflow/threat_detection_steps_test.go index 432baf834da..b27dc51eef6 100644 --- a/pkg/workflow/threat_detection_steps_test.go +++ b/pkg/workflow/threat_detection_steps_test.go @@ -80,7 +80,11 @@ func TestThreatDetectionStepsOrdering(t *testing.T) { preStepPos := strings.Index(stepsString, "Custom Pre Scan") setupStepPos := strings.Index(stepsString, "Setup threat detection") initializePos := strings.Index(stepsString, "Initialize detection execution evidence") - startedPos := strings.Index(stepsString, "Mark detection execution started") + engineStepPos := strings.Index(stepsString, "id: detection_agentic_execution") + startedPos := -1 + if engineStepPos >= 0 { + startedPos = strings.Index(stepsString[engineStepPos:], `"state":"started"`) + } uploadStepPos := strings.Index(stepsString, "Upload threat detection log") // Verify all steps exist @@ -93,8 +97,8 @@ func TestThreatDetectionStepsOrdering(t *testing.T) { if uploadStepPos == -1 { t.Error("Expected to find 'Upload threat detection log' step") } - if initializePos < 0 || initializePos > preStepPos || startedPos < setupStepPos { - t.Error("Expected detection evidence to surround pre-execution setup") + if initializePos < 0 || initializePos > preStepPos || engineStepPos < setupStepPos || startedPos < 0 { + t.Error("Expected detection evidence to initialize before setup and start inside engine execution") } if !strings.Contains(stepsString[uploadStepPos:], "if: always()") || !strings.Contains(stepsString[uploadStepPos:], "/tmp/gh-aw/threat-detection/execution.json") { t.Error("Expected detection execution evidence to be uploaded after pre-execution failures") From 273a8c5d115c60424232f4cc8acb790ca63cf0c8 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sat, 12 Sep 2026 02:45:55 +0000 Subject: [PATCH 4/5] Start execution evidence at AWF invocation Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 8 ++--- .github/workflows/ace-editor.lock.yml | 8 ++--- .github/workflows/agent-job-health.lock.yml | 8 ++--- .../agent-performance-analyzer.lock.yml | 8 ++--- .../workflows/agent-persona-explorer.lock.yml | 8 ++--- .../workflows/agentic-token-audit.lock.yml | 8 ++--- .../agentic-token-optimizer.lock.yml | 8 ++--- .../agentic-token-trend-audit.lock.yml | 8 ++--- .github/workflows/ai-moderator.lock.yml | 8 ++--- .../workflows/api-consumption-report.lock.yml | 8 ++--- .github/workflows/approach-validator.lock.yml | 8 ++--- .github/workflows/archie.lock.yml | 8 ++--- .../workflows/architecture-guardian.lock.yml | 8 ++--- ...rchivx-agentic-workflows-analyzer.lock.yml | 8 ++--- .github/workflows/artifacts-summary.lock.yml | 8 ++--- .github/workflows/audit-workflows.lock.yml | 8 ++--- .github/workflows/auto-triage-issues.lock.yml | 8 ++--- .github/workflows/avenger.lock.yml | 8 ++--- .../aw-failure-investigator.lock.yml | 8 ++--- .github/workflows/blog-auditor.lock.yml | 8 ++--- .github/workflows/bot-detection.lock.yml | 8 ++--- .../breaking-change-checker.lock.yml | 8 ++--- .github/workflows/changeset.lock.yml | 8 ++--- .../workflows/chaos-pr-bundle-fuzzer.lock.yml | 8 ++--- .github/workflows/ci-coach.lock.yml | 8 ++--- .github/workflows/ci-doctor.lock.yml | 8 ++--- .../claude-code-user-docs-review.lock.yml | 8 ++--- .../cli-consistency-checker.lock.yml | 8 ++--- .../workflows/cli-version-checker.lock.yml | 8 ++--- .github/workflows/cloclo.lock.yml | 8 ++--- .../workflows/code-scanning-fixer.lock.yml | 8 ++--- .github/workflows/code-simplifier.lock.yml | 8 ++--- .../codex-github-remote-mcp-test.lock.yml | 8 ++--- .../commit-changes-analyzer.lock.yml | 8 ++--- .../constraint-solving-potd.lock.yml | 8 ++--- .github/workflows/contribution-check.lock.yml | 8 ++--- .../workflows/copilot-agent-analysis.lock.yml | 8 ++--- .../copilot-centralization-drilldown.lock.yml | 8 ++--- .../copilot-centralization-optimizer.lock.yml | 8 ++--- .../copilot-cli-deep-research.lock.yml | 8 ++--- .github/workflows/copilot-opt.lock.yml | 8 ++--- .../copilot-pr-merged-report.lock.yml | 8 ++--- .../copilot-pr-nlp-analysis.lock.yml | 8 ++--- .../copilot-pr-prompt-analysis.lock.yml | 8 ++--- .../copilot-session-insights.lock.yml | 8 ++--- .github/workflows/craft.lock.yml | 8 ++--- ...daily-action-setup-security-audit.lock.yml | 8 ++--- ...aily-agent-of-the-day-blog-writer.lock.yml | 8 ++--- .../daily-agentrx-trace-optimizer.lock.yml | 8 ++--- .../daily-ambient-context-optimizer.lock.yml | 8 ++--- .../daily-architecture-diagram.lock.yml | 8 ++--- .../workflows/daily-arxiv-researcher.lock.yml | 8 ++--- .../daily-assign-issue-to-user.lock.yml | 8 ++--- ...strostylelite-markdown-spellcheck.lock.yml | 8 ++--- ...daily-aw-cross-repo-compile-check.lock.yml | 8 ++--- ...daily-awf-spec-compiler-surfacing.lock.yml | 8 ++--- .../workflows/daily-byok-ollama-test.lock.yml | 8 ++--- .../daily-cache-strategy-analyzer.lock.yml | 8 ++--- .../daily-caveman-optimizer.lock.yml | 8 ++--- .github/workflows/daily-choice-test.lock.yml | 8 ++--- .../workflows/daily-cli-performance.lock.yml | 8 ++--- .../workflows/daily-cli-tools-tester.lock.yml | 8 ++--- .github/workflows/daily-code-metrics.lock.yml | 8 ++--- .../daily-community-attribution.lock.yml | 8 ++--- .../workflows/daily-compiler-quality.lock.yml | 8 ++--- ...ly-compiler-threat-spec-optimizer.lock.yml | 8 ++--- .../daily-credit-limit-test.lock.yml | 8 ++--- .github/workflows/daily-doc-healer.lock.yml | 8 ++--- .github/workflows/daily-doc-updater.lock.yml | 8 ++--- .../daily-documentation-diagram.lock.yml | 8 ++--- .../daily-elixir-credo-snippet-audit.lock.yml | 8 ++--- .github/workflows/daily-evals-report.lock.yml | 8 ++--- .../daily-experiment-report.lock.yml | 8 ++--- .github/workflows/daily-fact.lock.yml | 8 ++--- .github/workflows/daily-file-diet.lock.yml | 8 ++--- .../workflows/daily-firewall-report.lock.yml | 8 ++--- .../daily-formal-spec-verifier.lock.yml | 8 ++--- .../workflows/daily-function-namer.lock.yml | 8 ++--- .../workflows/daily-geo-optimizer.lock.yml | 8 ++--- .../daily-github-docs-seo-optimizer.lock.yml | 16 ++++----- .../daily-go-test-parallelizer.lock.yml | 8 ++--- .github/workflows/daily-grader-audit.lock.yml | 8 ++--- .../daily-graft-intelligence.lock.yml | 8 ++--- ...daily-harness-experiment-proposer.lock.yml | 8 ++--- .github/workflows/daily-hippo-learn.lock.yml | 8 ++--- .../workflows/daily-issues-report.lock.yml | 8 ++--- .../daily-malicious-code-scan.lock.yml | 8 ++--- .../daily-max-ai-credits-test.lock.yml | 8 ++--- .../daily-mcp-concurrency-analysis.lock.yml | 8 ++--- .../workflows/daily-model-inventory.lock.yml | 8 ++--- .../workflows/daily-model-resolution.lock.yml | 8 ++--- .../daily-multi-device-docs-tester.lock.yml | 8 ++--- .github/workflows/daily-news.lock.yml | 8 ++--- .../daily-observability-report.lock.yml | 8 ++--- .../daily-performance-summary.lock.yml | 8 ++--- .../workflows/daily-pr-review-cursor.lock.yml | 8 ++--- .../daily-regression-audit-kiro.lock.yml | 8 ++--- .github/workflows/daily-regulatory.lock.yml | 8 ++--- .../daily-rendering-scripts-verifier.lock.yml | 8 ++--- .../workflows/daily-repo-chronicle.lock.yml | 8 ++--- .../daily-safe-output-integrator.lock.yml | 8 ++--- .../daily-safe-output-optimizer.lock.yml | 8 ++--- .../daily-safe-outputs-conformance.lock.yml | 8 ++--- .../daily-safeoutputs-git-simulator.lock.yml | 8 ++--- .../daily-schema-audit-cursor.lock.yml | 8 ++--- .../workflows/daily-secrets-analysis.lock.yml | 8 ++--- .../daily-security-observability.lock.yml | 8 ++--- .github/workflows/daily-semgrep-scan.lock.yml | 8 ++--- .../daily-spdd-spec-planner.lock.yml | 8 ++--- .../daily-spec-coverage-kiro.lock.yml | 8 ++--- .../daily-spending-forecast.lock.yml | 8 ++--- .../workflows/daily-squid-image-scan.lock.yml | 8 ++--- .github/workflows/daily-storify.lock.yml | 8 ++--- .../daily-syntax-error-quality.lock.yml | 8 ++--- .github/workflows/daily-team-status.lock.yml | 8 ++--- .../daily-testify-uber-super-expert.lock.yml | 8 ++--- ...ily-trajectory-grader-implementer.lock.yml | 8 ++--- .../workflows/daily-vulnhunter-scan.lock.yml | 8 ++--- .../daily-windows-defender-scan.lock.yml | 8 ++--- ...dows-terminal-integration-builder.lock.yml | 8 ++--- .../workflows/daily-workflow-updater.lock.yml | 8 ++--- .../workflows/daily-yamllint-fixer.lock.yml | 8 ++--- .../dataflow-pr-discussion-dataset.lock.yml | 8 ++--- .github/workflows/dead-code-remover.lock.yml | 8 ++--- .github/workflows/deep-report.lock.yml | 8 ++--- .../workflows/deepsec-security-scan.lock.yml | 8 ++--- .github/workflows/delight.lock.yml | 8 ++--- .github/workflows/dependabot-burner.lock.yml | 8 ++--- .../workflows/dependabot-go-checker.lock.yml | 8 ++--- .../deployment-incident-monitor.lock.yml | 8 ++--- .../workflows/design-decision-gate.lock.yml | 8 ++--- .../workflows/designer-drift-audit.lock.yml | 8 ++--- .../detection-analysis-report.lock.yml | 8 ++--- .github/workflows/dev-hawk.lock.yml | 8 ++--- .github/workflows/dev.lock.yml | 8 ++--- .../developer-docs-consolidator.lock.yml | 8 ++--- .github/workflows/dictation-prompt.lock.yml | 8 ++--- .github/workflows/docs-noob-tester.lock.yml | 8 ++--- .github/workflows/draft-pr-cleanup.lock.yml | 8 ++--- .../duplicate-code-detector.lock.yml | 8 ++--- .github/workflows/eslint-miner.lock.yml | 8 ++--- .github/workflows/eslint-monster.lock.yml | 8 ++--- .github/workflows/eslint-refiner.lock.yml | 8 ++--- .github/workflows/evoskill-evolver.lock.yml | 8 ++--- .../example-failure-category-filter.lock.yml | 8 ++--- .../example-permissions-warning.lock.yml | 8 ++--- .../example-workflow-analyzer.lock.yml | 8 ++--- .github/workflows/feature-grower.lock.yml | 8 ++--- .github/workflows/firewall-escape.lock.yml | 8 ++--- .github/workflows/firewall.lock.yml | 8 ++--- .../workflows/front-page-copy-guard.lock.yml | 8 ++--- .../workflows/functional-pragmatist.lock.yml | 8 ++--- .../github-mcp-structural-analysis.lock.yml | 8 ++--- .../github-mcp-tools-report.lock.yml | 8 ++--- .../github-remote-mcp-auth-test.lock.yml | 8 ++--- .../workflows/glossary-maintainer.lock.yml | 8 ++--- .github/workflows/go-fan.lock.yml | 8 ++--- .github/workflows/go-logger.lock.yml | 8 ++--- .../workflows/go-pattern-detector.lock.yml | 8 ++--- .github/workflows/gpclean.lock.yml | 8 ++--- .github/workflows/grumpy-reviewer.lock.yml | 8 ++--- .github/workflows/hippo-embed.lock.yml | 8 ++--- .github/workflows/hourly-ci-cleaner.lock.yml | 8 ++--- .../impeccable-skills-reviewer.lock.yml | 8 ++--- .../workflows/instructions-janitor.lock.yml | 8 ++--- .github/workflows/issue-arborist.lock.yml | 8 ++--- .github/workflows/issue-monster.lock.yml | 8 ++--- .github/workflows/issue-triage-agent.lock.yml | 8 ++--- .github/workflows/jsweep.lock.yml | 8 ++--- .../workflows/layout-spec-maintainer.lock.yml | 8 ++--- .github/workflows/lint-monster.lock.yml | 8 ++--- .github/workflows/linter-miner.lock.yml | 8 ++--- .github/workflows/lockfile-stats.lock.yml | 8 ++--- .../mattpocock-skills-reviewer.lock.yml | 8 ++--- .github/workflows/mcp-inspector.lock.yml | 8 ++--- .github/workflows/mergefest.lock.yml | 8 ++--- .github/workflows/metrics-collector.lock.yml | 8 ++--- .github/workflows/necromancer.lock.yml | 8 ++--- .../workflows/notion-issue-summary.lock.yml | 8 ++--- .../objective-impact-report.lock.yml | 8 ++--- .github/workflows/org-health-report.lock.yml | 8 ++--- .github/workflows/outcome-collector.lock.yml | 8 ++--- .github/workflows/pdf-summary.lock.yml | 8 ++--- .github/workflows/plan.lock.yml | 8 ++--- .github/workflows/poem-bot.lock.yml | 8 ++--- .github/workflows/ponytail-reviewer.lock.yml | 8 ++--- .github/workflows/portfolio-analyst.lock.yml | 8 ++--- .../pr-code-quality-reviewer.lock.yml | 8 ++--- .../workflows/pr-description-caveman.lock.yml | 8 ++--- .../workflows/pr-nitpick-reviewer.lock.yml | 8 ++--- .github/workflows/pr-sous-chef.lock.yml | 8 ++--- .github/workflows/pr-triage-agent.lock.yml | 8 ++--- .../prompt-clustering-analysis.lock.yml | 8 ++--- .github/workflows/purelock.lock.yml | 8 ++--- .github/workflows/python-data-charts.lock.yml | 8 ++--- .github/workflows/q.lock.yml | 8 ++--- .../workflows/refactoring-cadence.lock.yml | 8 ++--- .github/workflows/refiner.lock.yml | 8 ++--- .github/workflows/release.lock.yml | 8 ++--- .../workflows/repo-audit-analyzer.lock.yml | 8 ++--- .github/workflows/repo-tree-map.lock.yml | 8 ++--- .../repository-quality-improver.lock.yml | 8 ++--- .github/workflows/research.lock.yml | 8 ++--- .github/workflows/ruflo-backed-task.lock.yml | 8 ++--- .github/workflows/safe-output-health.lock.yml | 8 ++--- .../schema-consistency-checker.lock.yml | 8 ++--- .../schema-feature-coverage.lock.yml | 8 ++--- .github/workflows/scout.lock.yml | 8 ++--- .../workflows/security-compliance.lock.yml | 8 ++--- .github/workflows/security-review.lock.yml | 8 ++--- .../semantic-function-refactor.lock.yml | 8 ++--- .github/workflows/sergo.lock.yml | 8 ++--- .../sighthound-security-scan.lock.yml | 8 ++--- .github/workflows/skillet.lock.yml | 8 ++--- .../workflows/slide-deck-maintainer.lock.yml | 8 ++--- .../workflows/smoke-agent-all-merged.lock.yml | 16 ++++----- .../workflows/smoke-agent-all-none.lock.yml | 16 ++++----- .../smoke-agent-public-approved.lock.yml | 16 ++++----- .../smoke-agent-public-none.lock.yml | 16 ++++----- .../smoke-agent-scoped-approved.lock.yml | 16 ++++----- .github/workflows/smoke-aider.lock.yml | 8 ++--- .../workflows/smoke-call-workflow.lock.yml | 16 ++++----- .../smoke-checkout-pr-dispatch.lock.yml | 16 ++++----- .../smoke-claude-on-copilot.lock.yml | 8 ++--- .github/workflows/smoke-claude.lock.yml | 16 ++++----- .github/workflows/smoke-codex.lock.yml | 16 ++++----- .../smoke-copilot-aoai-apikey.lock.yml | 16 ++++----- .../smoke-copilot-aoai-entra.lock.yml | 16 ++++----- .github/workflows/smoke-copilot-arm.lock.yml | 16 ++++----- .github/workflows/smoke-copilot-auto.lock.yml | 16 ++++----- .github/workflows/smoke-copilot-mai.lock.yml | 16 ++++----- .github/workflows/smoke-copilot-sdk.lock.yml | 16 ++++----- .../workflows/smoke-copilot-small.lock.yml | 16 ++++----- .../smoke-copilot-sub-agents.lock.yml | 16 ++++----- .github/workflows/smoke-copilot.lock.yml | 16 ++++----- .../smoke-create-cross-repo-pr.lock.yml | 16 ++++----- .github/workflows/smoke-crush.lock.yml | 8 ++--- .github/workflows/smoke-cursor.lock.yml | 8 ++--- .../workflows/smoke-deepseek-harness.lock.yml | 8 ++--- .github/workflows/smoke-drive.lock.yml | 16 ++++----- .github/workflows/smoke-gemini.lock.yml | 8 ++--- .../workflows/smoke-github-claude.lock.yml | 8 ++--- .github/workflows/smoke-goose.lock.yml | 8 ++--- .github/workflows/smoke-issues.lock.yml | 8 ++--- .github/workflows/smoke-kiro.lock.yml | 8 ++--- .github/workflows/smoke-multi-pr.lock.yml | 16 ++++----- .github/workflows/smoke-opencode.lock.yml | 8 ++--- .../workflows/smoke-otel-backends.lock.yml | 16 ++++----- .github/workflows/smoke-pi.lock.yml | 16 ++++----- .github/workflows/smoke-project.lock.yml | 16 ++++----- .github/workflows/smoke-pydantic.lock.yml | 8 ++--- .../workflows/smoke-service-ports.lock.yml | 16 ++++----- .github/workflows/smoke-temporary-id.lock.yml | 16 ++++----- .github/workflows/smoke-test-tools.lock.yml | 16 ++++----- .../smoke-update-cross-repo-pr.lock.yml | 16 ++++----- .../smoke-workflow-call-with-inputs.lock.yml | 16 ++++----- .../workflows/smoke-workflow-call.lock.yml | 16 ++++----- .github/workflows/spec-enforcer.lock.yml | 8 ++--- .github/workflows/spec-extractor.lock.yml | 8 ++--- .github/workflows/spec-librarian.lock.yml | 8 ++--- .github/workflows/squad-game-planner.lock.yml | 8 ++--- .../workflows/squad-implement-worker.lock.yml | 8 ++--- .github/workflows/squad-plan.lock.yml | 8 ++--- .github/workflows/squad.lock.yml | 8 ++--- .github/workflows/stale-pr-cleanup.lock.yml | 8 ++--- .../workflows/stale-repo-identifier.lock.yml | 8 ++--- .../workflows/static-analysis-report.lock.yml | 8 ++--- .../workflows/step-name-alignment.lock.yml | 8 ++--- .github/workflows/sub-issue-closer.lock.yml | 8 ++--- .github/workflows/super-linter.lock.yml | 8 ++--- .../workflows/technical-doc-writer.lock.yml | 8 ++--- .github/workflows/terminal-stylist.lock.yml | 8 ++--- .../workflows/test-quality-sentinel.lock.yml | 8 ++--- .github/workflows/tidy.lock.yml | 8 ++--- .github/workflows/typist.lock.yml | 8 ++--- .../workflows/ubuntu-image-analyzer.lock.yml | 8 ++--- .../uk-ai-operational-resilience.lock.yml | 8 ++--- .github/workflows/unbloat-docs.lock.yml | 8 ++--- .github/workflows/update-astro.lock.yml | 8 ++--- .github/workflows/video-analyzer.lock.yml | 8 ++--- .../visual-regression-checker.lock.yml | 8 ++--- .../weekly-blog-post-writer.lock.yml | 8 ++--- .../weekly-editors-health-check.lock.yml | 8 ++--- .../workflows/weekly-issue-summary.lock.yml | 8 ++--- .../weekly-network-domains-audit.lock.yml | 8 ++--- .../weekly-safe-outputs-spec-review.lock.yml | 8 ++--- .github/workflows/windows-grower.lock.yml | 8 ++--- .github/workflows/windows.lock.yml | 8 ++--- .github/workflows/workflow-generator.lock.yml | 8 ++--- .../workflow-health-manager.lock.yml | 8 ++--- .../workflows/workflow-normalizer.lock.yml | 8 ++--- .../workflow-skill-extractor.lock.yml | 8 ++--- pkg/workflow/compiler_yaml_ai_execution.go | 36 +++++++++++++++---- .../TestWasmGolden_AllEngines/claude.golden | 8 ++--- .../TestWasmGolden_AllEngines/codex.golden | 8 ++--- .../TestWasmGolden_AllEngines/copilot.golden | 8 ++--- .../TestWasmGolden_AllEngines/gemini.golden | 8 ++--- .../TestWasmGolden_AllEngines/pi.golden | 8 ++--- .../basic-copilot.golden | 8 ++--- .../playwright-cli-mode.golden | 8 ++--- .../smoke-copilot.golden | 8 ++--- .../with-imports.golden | 8 ++--- pkg/workflow/threat_detection_external.go | 4 +-- 303 files changed, 1358 insertions(+), 1338 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index c746cf093ee..36706d0b181 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -984,10 +984,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1008,6 +1004,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ace-editor.lock.yml b/.github/workflows/ace-editor.lock.yml index 850a4dbe11e..9ce37d6967d 100644 --- a/.github/workflows/ace-editor.lock.yml +++ b/.github/workflows/ace-editor.lock.yml @@ -904,10 +904,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -928,6 +924,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 9c5b1b072ed..7e499a95f0e 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -1119,10 +1119,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1140,6 +1136,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index af77a2f89c5..57c2756579a 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -1087,10 +1087,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1128,6 +1124,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index 2892263f920..65a6f7c14ae 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -1090,10 +1090,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1114,6 +1110,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agentic-token-audit.lock.yml b/.github/workflows/agentic-token-audit.lock.yml index 37dc18b4780..0abe9430f9c 100644 --- a/.github/workflows/agentic-token-audit.lock.yml +++ b/.github/workflows/agentic-token-audit.lock.yml @@ -995,10 +995,6 @@ jobs: timeout-minutes: 25 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1044,6 +1040,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agentic-token-optimizer.lock.yml b/.github/workflows/agentic-token-optimizer.lock.yml index 17990b30a12..17a8178bb28 100644 --- a/.github/workflows/agentic-token-optimizer.lock.yml +++ b/.github/workflows/agentic-token-optimizer.lock.yml @@ -904,10 +904,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -950,6 +946,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index 51e39f26116..095b957a037 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -1057,10 +1057,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1081,6 +1077,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index 31004901946..d2850bf30d8 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -932,10 +932,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -963,6 +959,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 6ebff33af2c..a1793376baa 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -1080,10 +1080,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1104,6 +1100,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index d05ef81114a..8eb5bec3d2c 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -1109,10 +1109,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1133,6 +1129,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index fbfd7eed1ac..9df6326d260 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -981,10 +981,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1025,6 +1021,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index 4700aa57576..e0adb2e83fb 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -907,10 +907,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -951,6 +947,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index 48d08bcec19..c1f00f8e6a6 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -1164,10 +1164,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1185,6 +1181,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index b7eb4700c5a..a547e7821fb 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -933,10 +933,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -957,6 +953,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 5a5e43db0e0..a0b666588ac 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -1163,10 +1163,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1184,6 +1180,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index ed21dbe3672..a1f9985e76d 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1028,10 +1028,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1052,6 +1048,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index 8cf644eade5..cdcaf910b77 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -1031,10 +1031,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1055,6 +1051,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index 92d91230036..d942e64044c 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -1200,10 +1200,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1224,6 +1220,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 145f159129d..33e1c07f8b1 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -1033,10 +1033,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1057,6 +1053,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/bot-detection.lock.yml b/.github/workflows/bot-detection.lock.yml index 5c8ed072b76..011dbe26e76 100644 --- a/.github/workflows/bot-detection.lock.yml +++ b/.github/workflows/bot-detection.lock.yml @@ -1023,10 +1023,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1047,6 +1043,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 85241c25006..a6d2ded893d 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -947,10 +947,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -991,6 +987,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index 8f8c2b5c14d..b35d5e53fb1 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -1033,10 +1033,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1057,6 +1053,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index 1110ed0a60e..dc48e582d3e 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -991,10 +991,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1015,6 +1011,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index c0226b91ec6..393c528b304 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -1021,10 +1021,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1062,6 +1058,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index fcbef1891cf..29cb72cf860 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1164,10 +1164,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1193,6 +1189,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index 9a9e1d9373c..efbf131d734 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -967,10 +967,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -996,6 +992,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index f075cdfa9c9..e5d23fce484 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -879,10 +879,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -923,6 +919,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index 2b0e6d981d6..0b9901a2e4e 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -876,10 +876,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -907,6 +903,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index 05cdc4bef60..d18741774e2 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -1321,10 +1321,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1345,6 +1341,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index b73931ddd8a..a0c582f2b2a 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -1038,10 +1038,6 @@ jobs: timeout-minutes: 40 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1082,6 +1078,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index 67e1df75a1f..8b093e25515 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -941,10 +941,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -982,6 +978,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/codex-github-remote-mcp-test.lock.yml b/.github/workflows/codex-github-remote-mcp-test.lock.yml index 039410ae71a..6e73ee20560 100644 --- a/.github/workflows/codex-github-remote-mcp-test.lock.yml +++ b/.github/workflows/codex-github-remote-mcp-test.lock.yml @@ -858,10 +858,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -882,6 +878,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 87d070b8a90..2683ada795b 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -929,10 +929,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -953,6 +949,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index 4cf150bb123..afc215d47ac 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -854,10 +854,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -898,6 +894,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index d95a7345257..c768be2cb6a 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -1036,10 +1036,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1085,6 +1081,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 3b6ccd21799..33b1e83c57b 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -1062,10 +1062,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1086,6 +1082,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-centralization-drilldown.lock.yml b/.github/workflows/copilot-centralization-drilldown.lock.yml index 482b91c3fe1..6a70bec02cc 100644 --- a/.github/workflows/copilot-centralization-drilldown.lock.yml +++ b/.github/workflows/copilot-centralization-drilldown.lock.yml @@ -941,10 +941,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -962,6 +958,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-centralization-optimizer.lock.yml b/.github/workflows/copilot-centralization-optimizer.lock.yml index f1e017c9e3d..baa645f62fc 100644 --- a/.github/workflows/copilot-centralization-optimizer.lock.yml +++ b/.github/workflows/copilot-centralization-optimizer.lock.yml @@ -985,10 +985,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1006,6 +1002,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index 144a5716338..51db75ef314 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -886,10 +886,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -935,6 +931,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index d59e8ed3a36..d8038d50af8 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -939,10 +939,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -988,6 +984,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 7fea761f69f..94b3ca4e1b0 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -839,10 +839,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -883,6 +879,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index ec10b4a0130..cd3687980cf 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -983,10 +983,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1027,6 +1023,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 5fa42292bef..007bda4c274 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -929,10 +929,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -973,6 +969,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 14cd71e0e46..fe7406278ff 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -1042,10 +1042,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1071,6 +1067,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index 36e5f42499e..2d2b0dedf9e 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -947,10 +947,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -996,6 +992,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-action-setup-security-audit.lock.yml b/.github/workflows/daily-action-setup-security-audit.lock.yml index b3b0ecd9ff9..97d34fef250 100644 --- a/.github/workflows/daily-action-setup-security-audit.lock.yml +++ b/.github/workflows/daily-action-setup-security-audit.lock.yml @@ -892,10 +892,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -936,6 +932,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 4c53c1700a6..8076ff9eb45 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -1047,10 +1047,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1091,6 +1087,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index 199bef361bf..f02aded35cc 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -1143,10 +1143,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1167,6 +1163,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index 865066be800..2802ffbb8ed 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -957,10 +957,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1001,6 +997,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 618571c185b..8064ff34ea7 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -1111,10 +1111,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1135,6 +1131,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-arxiv-researcher.lock.yml b/.github/workflows/daily-arxiv-researcher.lock.yml index 55abda40249..237118ac632 100644 --- a/.github/workflows/daily-arxiv-researcher.lock.yml +++ b/.github/workflows/daily-arxiv-researcher.lock.yml @@ -968,10 +968,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1009,6 +1005,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index da1494b45d9..c7e23fcb5db 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -903,10 +903,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -947,6 +943,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index a930537c7f2..1272741b1d2 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -1036,10 +1036,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1060,6 +1056,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index f0c88d4ff5b..325bf15dcdf 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -978,10 +978,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1002,6 +998,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index 48301945ff3..b689adb187d 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -966,10 +966,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -990,6 +986,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index 3c5c3ca190e..30458b0c145 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -888,10 +888,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -932,6 +928,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index 5b06a8a0956..6c31bad8689 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -1129,10 +1129,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1153,6 +1149,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index 5ed271f1f4a..2b21a72f025 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -1059,10 +1059,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1083,6 +1079,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index 865fe711089..49f4d201d97 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -932,10 +932,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -956,6 +952,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 3fee8b8b665..e967d692e46 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -1238,10 +1238,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1262,6 +1258,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index 31e96fba897..e0b587b8c07 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -1042,10 +1042,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1063,6 +1059,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index 8914a3dfa03..e05077a19bf 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -1002,10 +1002,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1046,6 +1042,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index acd3cdf7427..c55fbbb80cd 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -1079,10 +1079,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1123,6 +1119,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 9ce293792a0..04bdd33bc22 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -1010,10 +1010,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1051,6 +1047,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index 199be22595f..e15a7c0cbcb 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -969,10 +969,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1013,6 +1009,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index 3b269833ec2..e07c3a07a8f 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -828,10 +828,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -859,6 +855,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index f99fc034230..1396530d3d1 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -1163,10 +1163,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1187,6 +1183,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index f0732dbf9b0..ace81ff8d49 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -1063,10 +1063,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1087,6 +1083,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-documentation-diagram.lock.yml b/.github/workflows/daily-documentation-diagram.lock.yml index 04994a329f6..833ce8369e0 100644 --- a/.github/workflows/daily-documentation-diagram.lock.yml +++ b/.github/workflows/daily-documentation-diagram.lock.yml @@ -1013,10 +1013,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1042,6 +1038,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index 5c1c2bddbd8..120537524f8 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -999,10 +999,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1023,6 +1019,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index a5d401e4401..fd4f56c72a4 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -1054,10 +1054,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1078,6 +1074,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 48d713cb74d..194630d21b6 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -975,10 +975,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1024,6 +1020,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index 477a163787f..0cff6df16b2 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -1078,10 +1078,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1102,6 +1098,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index b47a840429b..b869ae8f6fe 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -951,10 +951,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -995,6 +991,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-firewall-report.lock.yml b/.github/workflows/daily-firewall-report.lock.yml index 8083ece25aa..be2160f2dc5 100644 --- a/.github/workflows/daily-firewall-report.lock.yml +++ b/.github/workflows/daily-firewall-report.lock.yml @@ -961,10 +961,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1010,6 +1006,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 0739b952add..a03ade84078 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -941,10 +941,6 @@ jobs: timeout-minutes: 25 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -990,6 +986,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index e6e629aefaa..86eabbee3fd 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -947,10 +947,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -978,6 +974,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index 1d3ade19949..feef272563c 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -911,10 +911,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -960,6 +956,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml index 81cc7a3a1c4..07b08994bf5 100644 --- a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml +++ b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml @@ -800,10 +800,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -844,6 +840,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1495,10 +1495,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1544,6 +1540,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/daily-go-test-parallelizer.lock.yml b/.github/workflows/daily-go-test-parallelizer.lock.yml index ef134fb18f6..d1fb10339b8 100644 --- a/.github/workflows/daily-go-test-parallelizer.lock.yml +++ b/.github/workflows/daily-go-test-parallelizer.lock.yml @@ -974,10 +974,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1003,6 +999,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-grader-audit.lock.yml b/.github/workflows/daily-grader-audit.lock.yml index 3b9efc0ab47..d54fce25e27 100644 --- a/.github/workflows/daily-grader-audit.lock.yml +++ b/.github/workflows/daily-grader-audit.lock.yml @@ -967,10 +967,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -993,6 +989,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 7d201d49104..16b8ae38c4e 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -926,10 +926,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -975,6 +971,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-harness-experiment-proposer.lock.yml b/.github/workflows/daily-harness-experiment-proposer.lock.yml index aaf595bff83..4e8f41356f7 100644 --- a/.github/workflows/daily-harness-experiment-proposer.lock.yml +++ b/.github/workflows/daily-harness-experiment-proposer.lock.yml @@ -1021,10 +1021,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1042,6 +1038,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index 0ff33af3648..6fbc474d9f7 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -1026,10 +1026,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1057,6 +1053,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 38016643e9c..4ca4346a81e 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -1153,10 +1153,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1202,6 +1198,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index 418a25da62f..f0ca666d1a0 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -897,10 +897,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -941,6 +937,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index 0cdfbc5a5da..418173926d8 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -867,10 +867,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -888,6 +884,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index a87a4148940..733944b0b50 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -988,10 +988,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1037,6 +1033,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 03c0d3e616d..83cb6258df7 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -903,10 +903,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -947,6 +943,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 9a78249f737..13c582ac9c3 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -924,10 +924,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -973,6 +969,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 4f17755319c..221a8f8fd2f 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -966,10 +966,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -997,6 +993,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index bcd22f17209..0d489f2a8f3 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -1104,10 +1104,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1135,6 +1131,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 582901513e4..cc8cdd4bf23 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -981,10 +981,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1007,6 +1003,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 50009af8e29..2a5a98ea5ab 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -1571,10 +1571,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1602,6 +1598,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-pr-review-cursor.lock.yml b/.github/workflows/daily-pr-review-cursor.lock.yml index 20d2e93f763..fc96a0d1a1f 100644 --- a/.github/workflows/daily-pr-review-cursor.lock.yml +++ b/.github/workflows/daily-pr-review-cursor.lock.yml @@ -876,10 +876,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -925,6 +921,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-regression-audit-kiro.lock.yml b/.github/workflows/daily-regression-audit-kiro.lock.yml index 142faa25436..5885e34b757 100644 --- a/.github/workflows/daily-regression-audit-kiro.lock.yml +++ b/.github/workflows/daily-regression-audit-kiro.lock.yml @@ -886,10 +886,6 @@ jobs: timeout-minutes: 25 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -930,6 +926,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 999ebcc11ca..81cb84ce1a9 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -1605,10 +1605,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1626,6 +1622,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 1265c07fa91..b26d880edba 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -1188,10 +1188,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1217,6 +1213,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 817fb682c51..dde597e0bf5 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -907,10 +907,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -938,6 +934,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index b6d0fcd8969..075863b3ff7 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -923,10 +923,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -972,6 +968,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index e9cfc8d1635..2e0d6881b88 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -1161,10 +1161,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1182,6 +1178,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index a6bd44f9f88..6c6eb87bb73 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -948,10 +948,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -977,6 +973,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml index a5bb99a9f36..0e9adc28f1a 100644 --- a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml +++ b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml @@ -1057,10 +1057,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1086,6 +1082,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-schema-audit-cursor.lock.yml b/.github/workflows/daily-schema-audit-cursor.lock.yml index 540c3ef78d8..5b1962fc90d 100644 --- a/.github/workflows/daily-schema-audit-cursor.lock.yml +++ b/.github/workflows/daily-schema-audit-cursor.lock.yml @@ -884,10 +884,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -928,6 +924,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 34bd3f4188a..179c53efda7 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -841,10 +841,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -890,6 +886,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index 730ac80b668..976e6985052 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -1034,10 +1034,6 @@ jobs: timeout-minutes: 60 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1083,6 +1079,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-semgrep-scan.lock.yml b/.github/workflows/daily-semgrep-scan.lock.yml index 6045650632e..4341ddfb021 100644 --- a/.github/workflows/daily-semgrep-scan.lock.yml +++ b/.github/workflows/daily-semgrep-scan.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1003,6 +999,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 420e3f572aa..8a782d0e4ac 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -908,10 +908,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -957,6 +953,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-spec-coverage-kiro.lock.yml b/.github/workflows/daily-spec-coverage-kiro.lock.yml index 972d2728ce6..73b8649f33e 100644 --- a/.github/workflows/daily-spec-coverage-kiro.lock.yml +++ b/.github/workflows/daily-spec-coverage-kiro.lock.yml @@ -884,10 +884,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -928,6 +924,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-spending-forecast.lock.yml b/.github/workflows/daily-spending-forecast.lock.yml index 165845ac40d..f4c7b5b3c4f 100644 --- a/.github/workflows/daily-spending-forecast.lock.yml +++ b/.github/workflows/daily-spending-forecast.lock.yml @@ -1094,10 +1094,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1118,6 +1114,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-squid-image-scan.lock.yml b/.github/workflows/daily-squid-image-scan.lock.yml index 3947cd112a0..0919ef746f7 100644 --- a/.github/workflows/daily-squid-image-scan.lock.yml +++ b/.github/workflows/daily-squid-image-scan.lock.yml @@ -1021,10 +1021,6 @@ jobs: timeout-minutes: 90 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1065,6 +1061,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-storify.lock.yml b/.github/workflows/daily-storify.lock.yml index bd39324e8c1..b3d32ff0a65 100644 --- a/.github/workflows/daily-storify.lock.yml +++ b/.github/workflows/daily-storify.lock.yml @@ -1041,10 +1041,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1070,6 +1066,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-syntax-error-quality.lock.yml b/.github/workflows/daily-syntax-error-quality.lock.yml index fbd575b540c..b9ec9a4ddc4 100644 --- a/.github/workflows/daily-syntax-error-quality.lock.yml +++ b/.github/workflows/daily-syntax-error-quality.lock.yml @@ -877,10 +877,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -921,6 +917,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-team-status.lock.yml b/.github/workflows/daily-team-status.lock.yml index a5499e5a92a..c0866ad336e 100644 --- a/.github/workflows/daily-team-status.lock.yml +++ b/.github/workflows/daily-team-status.lock.yml @@ -883,10 +883,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -932,6 +928,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index afe8a18415d..a6e3f4ff76f 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -975,10 +975,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1024,6 +1020,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-trajectory-grader-implementer.lock.yml b/.github/workflows/daily-trajectory-grader-implementer.lock.yml index f7f654f588c..ceab7f37283 100644 --- a/.github/workflows/daily-trajectory-grader-implementer.lock.yml +++ b/.github/workflows/daily-trajectory-grader-implementer.lock.yml @@ -930,10 +930,6 @@ jobs: timeout-minutes: 25 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -979,6 +975,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index 81de6514009..2b7a600a038 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -950,10 +950,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -974,6 +970,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-windows-defender-scan.lock.yml b/.github/workflows/daily-windows-defender-scan.lock.yml index 635c095ae75..48b90b9edf3 100644 --- a/.github/workflows/daily-windows-defender-scan.lock.yml +++ b/.github/workflows/daily-windows-defender-scan.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1008,6 +1004,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml index a789d1e2090..c4361e733c2 100644 --- a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml +++ b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml @@ -897,10 +897,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -926,6 +922,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-workflow-updater.lock.yml b/.github/workflows/daily-workflow-updater.lock.yml index e51c4a0678b..ac856525c7e 100644 --- a/.github/workflows/daily-workflow-updater.lock.yml +++ b/.github/workflows/daily-workflow-updater.lock.yml @@ -889,10 +889,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -938,6 +934,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/daily-yamllint-fixer.lock.yml b/.github/workflows/daily-yamllint-fixer.lock.yml index 75348fe4dae..becfb180ee7 100644 --- a/.github/workflows/daily-yamllint-fixer.lock.yml +++ b/.github/workflows/daily-yamllint-fixer.lock.yml @@ -980,10 +980,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1009,6 +1005,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index 8476d9b2b2b..315a4eff23e 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -1264,10 +1264,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1313,6 +1309,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index cf20f185f43..c20748e86b6 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -957,10 +957,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1001,6 +997,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index c693290e8ac..abca4245f62 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -1735,10 +1735,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1759,6 +1755,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/deepsec-security-scan.lock.yml b/.github/workflows/deepsec-security-scan.lock.yml index a079d89ce0d..bda48c6d54a 100644 --- a/.github/workflows/deepsec-security-scan.lock.yml +++ b/.github/workflows/deepsec-security-scan.lock.yml @@ -985,10 +985,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1009,6 +1005,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index d6ee0a0edbb..98616ad4e2b 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -944,10 +944,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -993,6 +989,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index 918d8c4c972..76e4624d9fd 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -1071,10 +1071,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1115,6 +1111,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dependabot-go-checker.lock.yml b/.github/workflows/dependabot-go-checker.lock.yml index 9d20622bb14..7914c0a3a92 100644 --- a/.github/workflows/dependabot-go-checker.lock.yml +++ b/.github/workflows/dependabot-go-checker.lock.yml @@ -1036,10 +1036,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1060,6 +1056,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index 4ba6e7c5127..f0a47c814fb 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -870,10 +870,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -919,6 +915,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index 0ef67ff3d30..5e7fdf133d9 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -988,10 +988,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1019,6 +1015,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/designer-drift-audit.lock.yml b/.github/workflows/designer-drift-audit.lock.yml index 4ad14fc2dcf..259e06c2952 100644 --- a/.github/workflows/designer-drift-audit.lock.yml +++ b/.github/workflows/designer-drift-audit.lock.yml @@ -908,10 +908,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -937,6 +933,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index e9f10a81a76..aaf08330b52 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -1090,10 +1090,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1111,6 +1107,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dev-hawk.lock.yml b/.github/workflows/dev-hawk.lock.yml index 115146412b8..9f3cd7f09f5 100644 --- a/.github/workflows/dev-hawk.lock.yml +++ b/.github/workflows/dev-hawk.lock.yml @@ -985,10 +985,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1029,6 +1025,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dev.lock.yml b/.github/workflows/dev.lock.yml index 61c8875829e..aa2480f24d5 100644 --- a/.github/workflows/dev.lock.yml +++ b/.github/workflows/dev.lock.yml @@ -999,10 +999,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1023,6 +1019,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index eca23b3436d..69384ad9e46 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -1134,10 +1134,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1163,6 +1159,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/dictation-prompt.lock.yml b/.github/workflows/dictation-prompt.lock.yml index 112e6144653..dd214204db9 100644 --- a/.github/workflows/dictation-prompt.lock.yml +++ b/.github/workflows/dictation-prompt.lock.yml @@ -890,10 +890,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -939,6 +935,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index acabd2aba94..07aebe47c8a 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -902,10 +902,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -951,6 +947,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/draft-pr-cleanup.lock.yml b/.github/workflows/draft-pr-cleanup.lock.yml index a1672056505..f3369af5c06 100644 --- a/.github/workflows/draft-pr-cleanup.lock.yml +++ b/.github/workflows/draft-pr-cleanup.lock.yml @@ -915,10 +915,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -959,6 +955,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 99f94a23d65..5bd6dc99dad 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -887,10 +887,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -918,6 +914,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/eslint-miner.lock.yml b/.github/workflows/eslint-miner.lock.yml index bca5004167b..8c625ceb51d 100644 --- a/.github/workflows/eslint-miner.lock.yml +++ b/.github/workflows/eslint-miner.lock.yml @@ -925,10 +925,6 @@ jobs: timeout-minutes: 120 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -974,6 +970,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index ea56d2ae837..f41e50405f6 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -1109,10 +1109,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1133,6 +1129,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index e00d515e43c..f00b7cae6f3 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -998,10 +998,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1027,6 +1023,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/evoskill-evolver.lock.yml b/.github/workflows/evoskill-evolver.lock.yml index 611b901bc98..a90653a2332 100644 --- a/.github/workflows/evoskill-evolver.lock.yml +++ b/.github/workflows/evoskill-evolver.lock.yml @@ -940,10 +940,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -989,6 +985,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/example-failure-category-filter.lock.yml b/.github/workflows/example-failure-category-filter.lock.yml index 647ac34b151..6c28dcddfd5 100644 --- a/.github/workflows/example-failure-category-filter.lock.yml +++ b/.github/workflows/example-failure-category-filter.lock.yml @@ -921,10 +921,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -945,6 +941,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/example-permissions-warning.lock.yml b/.github/workflows/example-permissions-warning.lock.yml index eeb02c99020..aa2606e7984 100644 --- a/.github/workflows/example-permissions-warning.lock.yml +++ b/.github/workflows/example-permissions-warning.lock.yml @@ -859,10 +859,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -883,6 +879,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index db87376b495..7f95dea5447 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -1000,10 +1000,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1024,6 +1020,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/feature-grower.lock.yml b/.github/workflows/feature-grower.lock.yml index 6ab2e4b5531..d0516e432c7 100644 --- a/.github/workflows/feature-grower.lock.yml +++ b/.github/workflows/feature-grower.lock.yml @@ -953,10 +953,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -977,6 +973,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/firewall-escape.lock.yml b/.github/workflows/firewall-escape.lock.yml index ee16d227c2b..4e047a53cf0 100644 --- a/.github/workflows/firewall-escape.lock.yml +++ b/.github/workflows/firewall-escape.lock.yml @@ -928,10 +928,6 @@ jobs: timeout-minutes: 60 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -977,6 +973,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/firewall.lock.yml b/.github/workflows/firewall.lock.yml index 6068c401f95..bb553f28c95 100644 --- a/.github/workflows/firewall.lock.yml +++ b/.github/workflows/firewall.lock.yml @@ -789,10 +789,6 @@ jobs: timeout-minutes: 5 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -833,6 +829,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/front-page-copy-guard.lock.yml b/.github/workflows/front-page-copy-guard.lock.yml index 3aec5bd887d..ec6db9bff5c 100644 --- a/.github/workflows/front-page-copy-guard.lock.yml +++ b/.github/workflows/front-page-copy-guard.lock.yml @@ -924,10 +924,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -953,6 +949,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/functional-pragmatist.lock.yml b/.github/workflows/functional-pragmatist.lock.yml index a90da5626b7..e42eb7eed4d 100644 --- a/.github/workflows/functional-pragmatist.lock.yml +++ b/.github/workflows/functional-pragmatist.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1003,6 +999,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 6b8b43f3c8a..62e1203b3f1 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -1285,10 +1285,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1309,6 +1305,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 5367bb092aa..cb8bc7eac85 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -1048,10 +1048,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1072,6 +1068,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 68039a90814..0b6a99feb2a 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -920,10 +920,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -944,6 +940,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index 46f6ed39c56..c2cb548e613 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -1036,10 +1036,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1080,6 +1076,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index 3eb785d0833..7353e613a76 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -1061,10 +1061,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1085,6 +1081,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/go-logger.lock.yml b/.github/workflows/go-logger.lock.yml index acc912233e0..82f6eae8049 100644 --- a/.github/workflows/go-logger.lock.yml +++ b/.github/workflows/go-logger.lock.yml @@ -1048,10 +1048,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1077,6 +1073,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/go-pattern-detector.lock.yml b/.github/workflows/go-pattern-detector.lock.yml index 03b64a14999..a7e415f206e 100644 --- a/.github/workflows/go-pattern-detector.lock.yml +++ b/.github/workflows/go-pattern-detector.lock.yml @@ -978,10 +978,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1002,6 +998,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/gpclean.lock.yml b/.github/workflows/gpclean.lock.yml index f5ca9020986..2a54be5ea18 100644 --- a/.github/workflows/gpclean.lock.yml +++ b/.github/workflows/gpclean.lock.yml @@ -1017,10 +1017,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1041,6 +1037,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index 4ec74e5718b..44c6f8464ed 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -1070,10 +1070,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1099,6 +1095,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/hippo-embed.lock.yml b/.github/workflows/hippo-embed.lock.yml index c256aa38828..199878f2824 100644 --- a/.github/workflows/hippo-embed.lock.yml +++ b/.github/workflows/hippo-embed.lock.yml @@ -921,10 +921,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -952,6 +948,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/hourly-ci-cleaner.lock.yml b/.github/workflows/hourly-ci-cleaner.lock.yml index e57be27d516..316da1450ea 100644 --- a/.github/workflows/hourly-ci-cleaner.lock.yml +++ b/.github/workflows/hourly-ci-cleaner.lock.yml @@ -1014,10 +1014,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1043,6 +1039,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index e18f1a84a32..ec89cb656f9 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -1068,10 +1068,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1117,6 +1113,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/instructions-janitor.lock.yml b/.github/workflows/instructions-janitor.lock.yml index 22c0ba7077c..7681b6e715d 100644 --- a/.github/workflows/instructions-janitor.lock.yml +++ b/.github/workflows/instructions-janitor.lock.yml @@ -1047,10 +1047,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1071,6 +1067,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/issue-arborist.lock.yml b/.github/workflows/issue-arborist.lock.yml index 073908c0465..0c069da6542 100644 --- a/.github/workflows/issue-arborist.lock.yml +++ b/.github/workflows/issue-arborist.lock.yml @@ -1091,10 +1091,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1115,6 +1111,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index fb203d6cd5c..f378ce3be23 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -1411,10 +1411,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1442,6 +1438,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/issue-triage-agent.lock.yml b/.github/workflows/issue-triage-agent.lock.yml index 7aceac99100..1d92defbead 100644 --- a/.github/workflows/issue-triage-agent.lock.yml +++ b/.github/workflows/issue-triage-agent.lock.yml @@ -1115,10 +1115,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1139,6 +1135,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/jsweep.lock.yml b/.github/workflows/jsweep.lock.yml index bcd7890c605..867ef4728a7 100644 --- a/.github/workflows/jsweep.lock.yml +++ b/.github/workflows/jsweep.lock.yml @@ -931,10 +931,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -975,6 +971,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/layout-spec-maintainer.lock.yml b/.github/workflows/layout-spec-maintainer.lock.yml index accdc89e025..c17bf1b785b 100644 --- a/.github/workflows/layout-spec-maintainer.lock.yml +++ b/.github/workflows/layout-spec-maintainer.lock.yml @@ -943,10 +943,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -992,6 +988,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/lint-monster.lock.yml b/.github/workflows/lint-monster.lock.yml index 42e89224a07..f04de3db8e7 100644 --- a/.github/workflows/lint-monster.lock.yml +++ b/.github/workflows/lint-monster.lock.yml @@ -1103,10 +1103,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1127,6 +1123,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index 5b2bb47a6fd..c070ad78a84 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -989,10 +989,6 @@ jobs: timeout-minutes: 120 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1033,6 +1029,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 2f7d62af01a..4f7844ab1ed 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -963,10 +963,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -987,6 +983,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 6a5412a95b9..c3b1fb4d16b 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -1170,10 +1170,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1219,6 +1215,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 0bea4f9326f..34a3f70608b 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -1231,10 +1231,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1275,6 +1271,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/mergefest.lock.yml b/.github/workflows/mergefest.lock.yml index efc9fc5677d..906ce08109e 100644 --- a/.github/workflows/mergefest.lock.yml +++ b/.github/workflows/mergefest.lock.yml @@ -939,10 +939,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -988,6 +984,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/metrics-collector.lock.yml b/.github/workflows/metrics-collector.lock.yml index e6e88758144..34474829c97 100644 --- a/.github/workflows/metrics-collector.lock.yml +++ b/.github/workflows/metrics-collector.lock.yml @@ -1045,10 +1045,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1069,6 +1065,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/necromancer.lock.yml b/.github/workflows/necromancer.lock.yml index d254b0247e6..4cf33ab4ade 100644 --- a/.github/workflows/necromancer.lock.yml +++ b/.github/workflows/necromancer.lock.yml @@ -941,10 +941,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -972,6 +968,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/notion-issue-summary.lock.yml b/.github/workflows/notion-issue-summary.lock.yml index d65634ce8f6..7f0690e8fe4 100644 --- a/.github/workflows/notion-issue-summary.lock.yml +++ b/.github/workflows/notion-issue-summary.lock.yml @@ -866,10 +866,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -890,6 +886,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/objective-impact-report.lock.yml b/.github/workflows/objective-impact-report.lock.yml index db0056aa489..dff49b5d3e4 100644 --- a/.github/workflows/objective-impact-report.lock.yml +++ b/.github/workflows/objective-impact-report.lock.yml @@ -941,10 +941,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -990,6 +986,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/org-health-report.lock.yml b/.github/workflows/org-health-report.lock.yml index 1efbaf454c7..c6eb8d30d7c 100644 --- a/.github/workflows/org-health-report.lock.yml +++ b/.github/workflows/org-health-report.lock.yml @@ -947,10 +947,6 @@ jobs: timeout-minutes: 60 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -996,6 +992,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/outcome-collector.lock.yml b/.github/workflows/outcome-collector.lock.yml index 4084394a7dc..d4c9ac14fb9 100644 --- a/.github/workflows/outcome-collector.lock.yml +++ b/.github/workflows/outcome-collector.lock.yml @@ -948,10 +948,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -977,6 +973,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pdf-summary.lock.yml b/.github/workflows/pdf-summary.lock.yml index 985afa7e0c6..adf7fe507c5 100644 --- a/.github/workflows/pdf-summary.lock.yml +++ b/.github/workflows/pdf-summary.lock.yml @@ -1076,10 +1076,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1100,6 +1096,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/plan.lock.yml b/.github/workflows/plan.lock.yml index 0191a870572..eceb1178ea1 100644 --- a/.github/workflows/plan.lock.yml +++ b/.github/workflows/plan.lock.yml @@ -1033,10 +1033,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1077,6 +1073,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/poem-bot.lock.yml b/.github/workflows/poem-bot.lock.yml index 5ef5ce37fa2..127292cb2f5 100644 --- a/.github/workflows/poem-bot.lock.yml +++ b/.github/workflows/poem-bot.lock.yml @@ -1365,10 +1365,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1389,6 +1385,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index 073e77c33e7..c37e1140801 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -1126,10 +1126,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1155,6 +1151,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 274340dbc03..6fed2f7f5f6 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -1123,10 +1123,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1144,6 +1140,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 5eff0b3a5ca..0e2171ca948 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -1100,10 +1100,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1149,6 +1145,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index b01cc4e8619..429b545a576 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -911,10 +911,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -960,6 +956,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index bd2162b8ea7..012a666b07b 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -1041,10 +1041,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1090,6 +1086,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index ea00d787bf2..7c2f2dba12b 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -1415,10 +1415,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1446,6 +1442,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 2e824067fa0..33e7555b1bc 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -1347,10 +1347,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1388,6 +1384,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index e6f39bf6a9f..4d76740781d 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -1119,10 +1119,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1143,6 +1139,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index c3fceb182de..2b6044a3fd8 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -1105,10 +1105,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1129,6 +1125,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index 413ffa50f10..e0a8e5f1a5a 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -1085,10 +1085,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1109,6 +1105,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index 668b41c2d22..7110fb8a848 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -1124,10 +1124,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1173,6 +1169,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index 4e7961e22b8..3dd01236550 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -870,10 +870,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -901,6 +897,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index 2006fbe5bb0..e74b419477a 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -1114,10 +1114,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1158,6 +1154,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/release.lock.yml b/.github/workflows/release.lock.yml index 8520173106a..1db1c6b7b78 100644 --- a/.github/workflows/release.lock.yml +++ b/.github/workflows/release.lock.yml @@ -907,10 +907,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -951,6 +947,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index 0cdba40e0cf..8a52f2cfcdd 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -960,10 +960,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -984,6 +980,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/repo-tree-map.lock.yml b/.github/workflows/repo-tree-map.lock.yml index 44208998c82..ff13ef5df1c 100644 --- a/.github/workflows/repo-tree-map.lock.yml +++ b/.github/workflows/repo-tree-map.lock.yml @@ -820,10 +820,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -851,6 +847,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index cbb02710f62..036931ff79b 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -879,10 +879,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -928,6 +924,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/research.lock.yml b/.github/workflows/research.lock.yml index 0722e241e2e..3653ff61113 100644 --- a/.github/workflows/research.lock.yml +++ b/.github/workflows/research.lock.yml @@ -850,10 +850,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -881,6 +877,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ruflo-backed-task.lock.yml b/.github/workflows/ruflo-backed-task.lock.yml index ab727df1b26..a374c809373 100644 --- a/.github/workflows/ruflo-backed-task.lock.yml +++ b/.github/workflows/ruflo-backed-task.lock.yml @@ -1149,10 +1149,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1178,6 +1174,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 99af6dd4022..3faad88abf2 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -1067,10 +1067,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1088,6 +1084,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index ddadec80bcd..8878a1cab82 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -957,10 +957,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -978,6 +974,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/schema-feature-coverage.lock.yml b/.github/workflows/schema-feature-coverage.lock.yml index 0f35d8a06da..80cab34f44f 100644 --- a/.github/workflows/schema-feature-coverage.lock.yml +++ b/.github/workflows/schema-feature-coverage.lock.yml @@ -958,10 +958,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -982,6 +978,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/scout.lock.yml b/.github/workflows/scout.lock.yml index 35453a07189..d5d3918a938 100644 --- a/.github/workflows/scout.lock.yml +++ b/.github/workflows/scout.lock.yml @@ -1156,10 +1156,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1185,6 +1181,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/security-compliance.lock.yml b/.github/workflows/security-compliance.lock.yml index 5f369905ffd..f1e99bc53b0 100644 --- a/.github/workflows/security-compliance.lock.yml +++ b/.github/workflows/security-compliance.lock.yml @@ -899,10 +899,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -948,6 +944,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index fe93c27e264..ccfc7c1acae 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -1349,10 +1349,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1378,6 +1374,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 1b39fda782e..ff557261023 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -1045,10 +1045,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1071,6 +1067,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 69c39874136..af7f84cf0bb 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -1052,10 +1052,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1081,6 +1077,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/sighthound-security-scan.lock.yml b/.github/workflows/sighthound-security-scan.lock.yml index c4afa4e128c..1bfd3f1b451 100644 --- a/.github/workflows/sighthound-security-scan.lock.yml +++ b/.github/workflows/sighthound-security-scan.lock.yml @@ -931,10 +931,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -955,6 +951,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index 7951a74cdc9..83fd6854ad3 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -1072,10 +1072,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1101,6 +1097,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 8ba0cc49190..feff2c0705c 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -1047,10 +1047,6 @@ jobs: timeout-minutes: 45 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1091,6 +1087,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/smoke-agent-all-merged.lock.yml b/.github/workflows/smoke-agent-all-merged.lock.yml index f314de87c1f..0af7e04c383 100644 --- a/.github/workflows/smoke-agent-all-merged.lock.yml +++ b/.github/workflows/smoke-agent-all-merged.lock.yml @@ -1023,10 +1023,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1047,6 +1043,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1716,10 +1716,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1746,6 +1742,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-agent-all-none.lock.yml b/.github/workflows/smoke-agent-all-none.lock.yml index bf1be15f3dc..f6f042e0337 100644 --- a/.github/workflows/smoke-agent-all-none.lock.yml +++ b/.github/workflows/smoke-agent-all-none.lock.yml @@ -1018,10 +1018,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1042,6 +1038,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1711,10 +1711,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1741,6 +1737,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-agent-public-approved.lock.yml b/.github/workflows/smoke-agent-public-approved.lock.yml index ad84e6c37ae..6c6d5f22ab7 100644 --- a/.github/workflows/smoke-agent-public-approved.lock.yml +++ b/.github/workflows/smoke-agent-public-approved.lock.yml @@ -1072,10 +1072,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1096,6 +1092,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1768,10 +1768,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1798,6 +1794,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-agent-public-none.lock.yml b/.github/workflows/smoke-agent-public-none.lock.yml index cc0a36a3f00..1eae7388df4 100644 --- a/.github/workflows/smoke-agent-public-none.lock.yml +++ b/.github/workflows/smoke-agent-public-none.lock.yml @@ -1018,10 +1018,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1042,6 +1038,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1711,10 +1711,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1741,6 +1737,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-agent-scoped-approved.lock.yml b/.github/workflows/smoke-agent-scoped-approved.lock.yml index 14632aa8446..66ef904d6d5 100644 --- a/.github/workflows/smoke-agent-scoped-approved.lock.yml +++ b/.github/workflows/smoke-agent-scoped-approved.lock.yml @@ -1075,10 +1075,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1099,6 +1095,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1776,10 +1776,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1806,6 +1802,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-aider.lock.yml b/.github/workflows/smoke-aider.lock.yml index e91ccf07959..51e1e263cb9 100644 --- a/.github/workflows/smoke-aider.lock.yml +++ b/.github/workflows/smoke-aider.lock.yml @@ -1655,10 +1655,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1704,6 +1700,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-call-workflow.lock.yml b/.github/workflows/smoke-call-workflow.lock.yml index 5a3f8bc7743..084b73e20ec 100644 --- a/.github/workflows/smoke-call-workflow.lock.yml +++ b/.github/workflows/smoke-call-workflow.lock.yml @@ -1002,10 +1002,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1026,6 +1022,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1789,10 +1789,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1819,6 +1815,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml index f8707dcabae..b89fe988496 100644 --- a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml +++ b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml @@ -961,10 +961,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1005,6 +1001,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1665,10 +1665,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1714,6 +1710,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-claude-on-copilot.lock.yml b/.github/workflows/smoke-claude-on-copilot.lock.yml index 99ddcca55ee..58f14dd15e0 100644 --- a/.github/workflows/smoke-claude-on-copilot.lock.yml +++ b/.github/workflows/smoke-claude-on-copilot.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1008,6 +1004,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml index 054c0081c92..134efcd7e7a 100644 --- a/.github/workflows/smoke-claude.lock.yml +++ b/.github/workflows/smoke-claude.lock.yml @@ -1680,10 +1680,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1709,6 +1705,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -2497,10 +2497,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -2527,6 +2523,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index c420f7fc85d..278ce5086df 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -1353,10 +1353,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1382,6 +1378,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -2254,10 +2254,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -2284,6 +2280,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index 072a9e30310..682a6d10e3f 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -2220,10 +2220,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2266,6 +2262,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -3072,10 +3072,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -3121,6 +3117,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index 6e4cedd848f..b59c31bf718 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -2236,10 +2236,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2282,6 +2278,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -3093,10 +3093,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -3142,6 +3138,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index 707c345beb6..8f90b362665 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -1984,10 +1984,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2033,6 +2029,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -2801,10 +2801,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2850,6 +2846,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-auto.lock.yml b/.github/workflows/smoke-copilot-auto.lock.yml index 2d5411ad147..a6c4de2f296 100644 --- a/.github/workflows/smoke-copilot-auto.lock.yml +++ b/.github/workflows/smoke-copilot-auto.lock.yml @@ -902,10 +902,6 @@ jobs: timeout-minutes: 5 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -951,6 +947,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1613,10 +1613,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1662,6 +1658,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-mai.lock.yml b/.github/workflows/smoke-copilot-mai.lock.yml index 0af773ceb57..903bae4b082 100644 --- a/.github/workflows/smoke-copilot-mai.lock.yml +++ b/.github/workflows/smoke-copilot-mai.lock.yml @@ -977,10 +977,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1026,6 +1022,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1690,10 +1690,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1739,6 +1735,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-sdk.lock.yml b/.github/workflows/smoke-copilot-sdk.lock.yml index 9c63dafe87b..428ab20a6c3 100644 --- a/.github/workflows/smoke-copilot-sdk.lock.yml +++ b/.github/workflows/smoke-copilot-sdk.lock.yml @@ -952,10 +952,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -996,6 +992,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1659,10 +1659,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1708,6 +1704,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-small.lock.yml b/.github/workflows/smoke-copilot-small.lock.yml index 5afe202a29b..46521a68d45 100644 --- a/.github/workflows/smoke-copilot-small.lock.yml +++ b/.github/workflows/smoke-copilot-small.lock.yml @@ -975,10 +975,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1019,6 +1015,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1685,10 +1685,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1734,6 +1730,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot-sub-agents.lock.yml b/.github/workflows/smoke-copilot-sub-agents.lock.yml index 80062b79df5..5a87bf1a25f 100644 --- a/.github/workflows/smoke-copilot-sub-agents.lock.yml +++ b/.github/workflows/smoke-copilot-sub-agents.lock.yml @@ -906,10 +906,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -950,6 +946,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1608,10 +1608,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1657,6 +1653,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index 86359902724..8e4aa18f868 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -2243,10 +2243,6 @@ jobs: timeout-minutes: 8 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2292,6 +2288,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -3105,10 +3105,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -3154,6 +3150,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-create-cross-repo-pr.lock.yml b/.github/workflows/smoke-create-cross-repo-pr.lock.yml index a1c1fb392b3..aeb1b9b083c 100644 --- a/.github/workflows/smoke-create-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-create-cross-repo-pr.lock.yml @@ -1056,10 +1056,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1100,6 +1096,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1763,10 +1763,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1812,6 +1808,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 548a27e2efd..0ab0d1cbe4e 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -1998,10 +1998,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2047,6 +2043,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 2688f6a2779..0e19a8cdf1f 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -1878,10 +1878,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1927,6 +1923,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index 5d9c673d364..c07916b6e31 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -1788,10 +1788,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1837,6 +1833,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-drive.lock.yml b/.github/workflows/smoke-drive.lock.yml index 81a6ea88261..f2ae5651c2e 100644 --- a/.github/workflows/smoke-drive.lock.yml +++ b/.github/workflows/smoke-drive.lock.yml @@ -1095,10 +1095,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1124,6 +1120,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1891,10 +1891,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1921,6 +1917,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index dd2eef5fe8d..2cab9f779fc 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -1104,10 +1104,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1128,6 +1124,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=gemini \ GH_AW_AWF_HARNESS_MARKER='[gemini-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/smoke-github-claude.lock.yml b/.github/workflows/smoke-github-claude.lock.yml index 0ed007f4bbf..aa53e1ed097 100644 --- a/.github/workflows/smoke-github-claude.lock.yml +++ b/.github/workflows/smoke-github-claude.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1008,6 +1004,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 2f993dec3c9..59d3b6a22a5 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -1970,10 +1970,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2019,6 +2015,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-issues.lock.yml b/.github/workflows/smoke-issues.lock.yml index 2befde32dc6..68fa78479bd 100644 --- a/.github/workflows/smoke-issues.lock.yml +++ b/.github/workflows/smoke-issues.lock.yml @@ -882,10 +882,6 @@ jobs: timeout-minutes: 5 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -931,6 +927,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index d036052195d..42b5436deeb 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -1787,10 +1787,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1836,6 +1832,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-multi-pr.lock.yml b/.github/workflows/smoke-multi-pr.lock.yml index 9df2e5510ff..ee0c8a4a446 100644 --- a/.github/workflows/smoke-multi-pr.lock.yml +++ b/.github/workflows/smoke-multi-pr.lock.yml @@ -1020,10 +1020,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1064,6 +1060,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1727,10 +1727,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1776,6 +1772,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 2ae4e3f7861..4db3748d873 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -1824,10 +1824,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1873,6 +1869,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-otel-backends.lock.yml b/.github/workflows/smoke-otel-backends.lock.yml index ac42649cc29..c9ecbf7914f 100644 --- a/.github/workflows/smoke-otel-backends.lock.yml +++ b/.github/workflows/smoke-otel-backends.lock.yml @@ -1163,10 +1163,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1192,6 +1188,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1942,10 +1942,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md && mkdir -p /tmp/gh-aw/threat-detection && printf '%s' '{"type":"object","properties":{"prompt_injection":{"type":"boolean"},"secret_leak":{"type":"boolean"},"malicious_patch":{"type":"boolean"},"reasons":{"type":"array","items":{"type":"string"}}},"required":["prompt_injection","secret_leak","malicious_patch","reasons"],"additionalProperties":false}' > /tmp/gh-aw/threat-detection/detection_schema.json (umask 177 && touch /tmp/gh-aw/threat-detection/detection.log) @@ -1972,6 +1968,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index 45e5cd95fbd..7e6c80bae9c 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -1013,10 +1013,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1044,6 +1040,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1694,10 +1694,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1743,6 +1739,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-project.lock.yml b/.github/workflows/smoke-project.lock.yml index fbf2dca0f6d..3afcee04fc0 100644 --- a/.github/workflows/smoke-project.lock.yml +++ b/.github/workflows/smoke-project.lock.yml @@ -1248,10 +1248,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1292,6 +1288,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -2067,10 +2067,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2116,6 +2112,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-pydantic.lock.yml b/.github/workflows/smoke-pydantic.lock.yml index e88b57d064f..ca8a9c5984c 100644 --- a/.github/workflows/smoke-pydantic.lock.yml +++ b/.github/workflows/smoke-pydantic.lock.yml @@ -2053,10 +2053,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -2102,6 +2098,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-service-ports.lock.yml b/.github/workflows/smoke-service-ports.lock.yml index 02fb4b3178f..d1e986bb4a8 100644 --- a/.github/workflows/smoke-service-ports.lock.yml +++ b/.github/workflows/smoke-service-ports.lock.yml @@ -904,10 +904,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -935,6 +931,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1627,10 +1627,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1676,6 +1672,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-temporary-id.lock.yml b/.github/workflows/smoke-temporary-id.lock.yml index 76fb2295276..cc6bb675b04 100644 --- a/.github/workflows/smoke-temporary-id.lock.yml +++ b/.github/workflows/smoke-temporary-id.lock.yml @@ -1008,10 +1008,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1039,6 +1035,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1751,10 +1751,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1800,6 +1796,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-test-tools.lock.yml b/.github/workflows/smoke-test-tools.lock.yml index c45f2ae52eb..1c655d571a1 100644 --- a/.github/workflows/smoke-test-tools.lock.yml +++ b/.github/workflows/smoke-test-tools.lock.yml @@ -958,10 +958,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -989,6 +985,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1689,10 +1689,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1738,6 +1734,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-update-cross-repo-pr.lock.yml b/.github/workflows/smoke-update-cross-repo-pr.lock.yml index c8abcf4e870..cd028fd4fb2 100644 --- a/.github/workflows/smoke-update-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-update-cross-repo-pr.lock.yml @@ -1053,10 +1053,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1097,6 +1093,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1782,10 +1782,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1831,6 +1827,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml index 596d29e3fec..bb8090ed8dd 100644 --- a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml +++ b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml @@ -980,10 +980,6 @@ jobs: timeout-minutes: 5 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1024,6 +1020,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1648,10 +1648,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1697,6 +1693,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/smoke-workflow-call.lock.yml b/.github/workflows/smoke-workflow-call.lock.yml index 857e9b587ff..263e5e91151 100644 --- a/.github/workflows/smoke-workflow-call.lock.yml +++ b/.github/workflows/smoke-workflow-call.lock.yml @@ -976,10 +976,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1020,6 +1016,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ @@ -1658,10 +1658,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw/threat-detection" - evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" - printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1707,6 +1703,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw/threat-detection" + evidence_tmp="/tmp/gh-aw/threat-detection/execution.json.tmp" + printf '{"version":1,"component":"detection","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/threat-detection/execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/threat-detection/detection.log \ diff --git a/.github/workflows/spec-enforcer.lock.yml b/.github/workflows/spec-enforcer.lock.yml index 20d03ee9dec..e0ca3962128 100644 --- a/.github/workflows/spec-enforcer.lock.yml +++ b/.github/workflows/spec-enforcer.lock.yml @@ -1045,10 +1045,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1069,6 +1065,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index 7e3b704e967..e077b2821ce 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -1005,10 +1005,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1054,6 +1050,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 0db3b7d7eaf..45c4d3b73fb 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -950,10 +950,6 @@ jobs: timeout-minutes: 25 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -999,6 +995,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/squad-game-planner.lock.yml b/.github/workflows/squad-game-planner.lock.yml index 6c54ed00663..935706ef0ba 100644 --- a/.github/workflows/squad-game-planner.lock.yml +++ b/.github/workflows/squad-game-planner.lock.yml @@ -910,10 +910,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -959,6 +955,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/squad-implement-worker.lock.yml b/.github/workflows/squad-implement-worker.lock.yml index 037e84020e1..85bbddb2048 100644 --- a/.github/workflows/squad-implement-worker.lock.yml +++ b/.github/workflows/squad-implement-worker.lock.yml @@ -1062,10 +1062,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1111,6 +1107,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/squad-plan.lock.yml b/.github/workflows/squad-plan.lock.yml index a111223a0a4..449a76bc12e 100644 --- a/.github/workflows/squad-plan.lock.yml +++ b/.github/workflows/squad-plan.lock.yml @@ -967,10 +967,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1016,6 +1012,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/squad.lock.yml b/.github/workflows/squad.lock.yml index acae4fc100f..19ef1a84c0e 100644 --- a/.github/workflows/squad.lock.yml +++ b/.github/workflows/squad.lock.yml @@ -1598,10 +1598,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1647,6 +1643,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/stale-pr-cleanup.lock.yml b/.github/workflows/stale-pr-cleanup.lock.yml index 000cec4eb1f..e30e0f4975c 100644 --- a/.github/workflows/stale-pr-cleanup.lock.yml +++ b/.github/workflows/stale-pr-cleanup.lock.yml @@ -914,10 +914,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -958,6 +954,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index c61dc539acf..31b77a4cd08 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -1093,10 +1093,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1124,6 +1120,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/static-analysis-report.lock.yml b/.github/workflows/static-analysis-report.lock.yml index ea4af6eed3d..cd982c1b90d 100644 --- a/.github/workflows/static-analysis-report.lock.yml +++ b/.github/workflows/static-analysis-report.lock.yml @@ -1110,10 +1110,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1134,6 +1130,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/step-name-alignment.lock.yml b/.github/workflows/step-name-alignment.lock.yml index 88593044c0a..c3ae80a4554 100644 --- a/.github/workflows/step-name-alignment.lock.yml +++ b/.github/workflows/step-name-alignment.lock.yml @@ -979,10 +979,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1008,6 +1004,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/sub-issue-closer.lock.yml b/.github/workflows/sub-issue-closer.lock.yml index ddaf1296836..2d5a2c6eead 100644 --- a/.github/workflows/sub-issue-closer.lock.yml +++ b/.github/workflows/sub-issue-closer.lock.yml @@ -886,10 +886,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -917,6 +913,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/super-linter.lock.yml b/.github/workflows/super-linter.lock.yml index 2f31f44f7cd..d25db02a881 100644 --- a/.github/workflows/super-linter.lock.yml +++ b/.github/workflows/super-linter.lock.yml @@ -875,10 +875,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -906,6 +902,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/technical-doc-writer.lock.yml b/.github/workflows/technical-doc-writer.lock.yml index f4e0f964064..4c59fa4b21b 100644 --- a/.github/workflows/technical-doc-writer.lock.yml +++ b/.github/workflows/technical-doc-writer.lock.yml @@ -1047,10 +1047,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1096,6 +1092,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index e64633257ea..fb17d05ca1d 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -867,10 +867,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -898,6 +894,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index 28c34790143..f11ad7e4355 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -1029,10 +1029,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1078,6 +1074,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/tidy.lock.yml b/.github/workflows/tidy.lock.yml index 912324250ad..09266a3f391 100644 --- a/.github/workflows/tidy.lock.yml +++ b/.github/workflows/tidy.lock.yml @@ -1030,10 +1030,6 @@ jobs: timeout-minutes: 20 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1074,6 +1070,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index bc0a8983007..59a8c2ab4ed 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -1048,10 +1048,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1072,6 +1068,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index ec5c43445ce..f9201b9d07e 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -932,10 +932,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -981,6 +977,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index efc0153cf12..0c006204ee4 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -917,10 +917,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -966,6 +962,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index a63b263ac24..b26ae83229b 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -1039,10 +1039,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -1070,6 +1066,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/update-astro.lock.yml b/.github/workflows/update-astro.lock.yml index b29b89e3179..31aaa59f520 100644 --- a/.github/workflows/update-astro.lock.yml +++ b/.github/workflows/update-astro.lock.yml @@ -1003,10 +1003,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1027,6 +1023,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/video-analyzer.lock.yml b/.github/workflows/video-analyzer.lock.yml index ef7254d076e..7ad7858765d 100644 --- a/.github/workflows/video-analyzer.lock.yml +++ b/.github/workflows/video-analyzer.lock.yml @@ -844,10 +844,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -875,6 +871,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/visual-regression-checker.lock.yml b/.github/workflows/visual-regression-checker.lock.yml index 064384b5fe0..2b93dd6a196 100644 --- a/.github/workflows/visual-regression-checker.lock.yml +++ b/.github/workflows/visual-regression-checker.lock.yml @@ -950,10 +950,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -994,6 +990,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/weekly-blog-post-writer.lock.yml b/.github/workflows/weekly-blog-post-writer.lock.yml index 58ea5402cff..a40b61e76f5 100644 --- a/.github/workflows/weekly-blog-post-writer.lock.yml +++ b/.github/workflows/weekly-blog-post-writer.lock.yml @@ -1096,10 +1096,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1145,6 +1141,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/weekly-editors-health-check.lock.yml b/.github/workflows/weekly-editors-health-check.lock.yml index 95431991c4c..0f6bbe8e0a1 100644 --- a/.github/workflows/weekly-editors-health-check.lock.yml +++ b/.github/workflows/weekly-editors-health-check.lock.yml @@ -969,10 +969,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1013,6 +1009,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index a86db029c23..103412d4988 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -883,10 +883,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -914,6 +910,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/weekly-network-domains-audit.lock.yml b/.github/workflows/weekly-network-domains-audit.lock.yml index c8f4037ad7b..478dddaf14f 100644 --- a/.github/workflows/weekly-network-domains-audit.lock.yml +++ b/.github/workflows/weekly-network-domains-audit.lock.yml @@ -850,10 +850,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -881,6 +877,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml index fd4195a1023..1beff1f22f4 100644 --- a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml +++ b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml @@ -883,10 +883,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -914,6 +910,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/windows-grower.lock.yml b/.github/workflows/windows-grower.lock.yml index af90ba7e6f0..d5caa9897b8 100644 --- a/.github/workflows/windows-grower.lock.yml +++ b/.github/workflows/windows-grower.lock.yml @@ -927,10 +927,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -956,6 +952,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/windows.lock.yml b/.github/workflows/windows.lock.yml index 0ad0814f740..eae06a8c419 100644 --- a/.github/workflows/windows.lock.yml +++ b/.github/workflows/windows.lock.yml @@ -1046,10 +1046,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1075,6 +1071,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/workflow-generator.lock.yml b/.github/workflows/workflow-generator.lock.yml index 34fddcb0234..97727939c77 100644 --- a/.github/workflows/workflow-generator.lock.yml +++ b/.github/workflows/workflow-generator.lock.yml @@ -960,10 +960,6 @@ jobs: timeout-minutes: 5 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1009,6 +1005,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/workflow-health-manager.lock.yml b/.github/workflows/workflow-health-manager.lock.yml index a9a02a981eb..fa9d322900d 100644 --- a/.github/workflows/workflow-health-manager.lock.yml +++ b/.github/workflows/workflow-health-manager.lock.yml @@ -986,10 +986,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -1032,6 +1028,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/workflow-normalizer.lock.yml b/.github/workflows/workflow-normalizer.lock.yml index 447630f91fe..9f5cf40fa9a 100644 --- a/.github/workflows/workflow-normalizer.lock.yml +++ b/.github/workflows/workflow-normalizer.lock.yml @@ -1040,10 +1040,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -1064,6 +1060,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/.github/workflows/workflow-skill-extractor.lock.yml b/.github/workflows/workflow-skill-extractor.lock.yml index 90f65cac0f5..f8f2f964bcb 100644 --- a/.github/workflows/workflow-skill-extractor.lock.yml +++ b/.github/workflows/workflow-skill-extractor.lock.yml @@ -917,10 +917,6 @@ jobs: timeout-minutes: 30 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -961,6 +957,10 @@ jobs: fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/compiler_yaml_ai_execution.go b/pkg/workflow/compiler_yaml_ai_execution.go index 819b1c9122d..471f79f0a90 100644 --- a/pkg/workflow/compiler_yaml_ai_execution.go +++ b/pkg/workflow/compiler_yaml_ai_execution.go @@ -43,6 +43,19 @@ func componentExecutionEvidenceShellLines(component, state, filePath string) []s } } +func injectComponentExecutionStartedInShellScript(command, component, filePath string) string { + var started strings.Builder + for _, line := range componentExecutionEvidenceShellLines(component, "started", filePath) { + started.WriteString(line) + started.WriteByte('\n') + } + + if awfInvocation := strings.Index(command, "GH_AW_AWF_ENGINE_NAME="); awfInvocation >= 0 { + return command[:awfInvocation] + started.String() + command[awfInvocation:] + } + return started.String() + command +} + func injectComponentExecutionStarted(step GitHubActionStep, component, filePath string) GitHubActionStep { runIndex := -1 for i, line := range step { @@ -55,14 +68,23 @@ func injectComponentExecutionStarted(step GitHubActionStep, component, filePath return step } - insertIndex := runIndex + 1 - for insertIndex < len(step) { - trimmed := strings.TrimSpace(step[insertIndex]) - if trimmed == "set -o pipefail" || strings.HasPrefix(trimmed, "trap 'gh_aw_exit_code=") { - insertIndex++ - continue + insertIndex := -1 + for i := runIndex + 1; i < len(step); i++ { + if strings.HasPrefix(strings.TrimSpace(step[i]), "GH_AW_AWF_ENGINE_NAME=") { + insertIndex = i + break + } + } + if insertIndex < 0 { + insertIndex = runIndex + 1 + for insertIndex < len(step) { + trimmed := strings.TrimSpace(step[insertIndex]) + if trimmed == "set -o pipefail" || strings.HasPrefix(trimmed, "trap 'gh_aw_exit_code=") { + insertIndex++ + continue + } + break } - break } startedLines := componentExecutionEvidenceShellLines(component, "started", filePath) diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden index b71f597950c..a2020b8d7e7 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden @@ -591,10 +591,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p /tmp/gh-aw && (umask 177 && touch /tmp/gh-aw/claude-debug.log) && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -620,6 +616,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=claude \ GH_AW_AWF_HARNESS_MARKER='[claude-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden index 4f19611ab67..97568ea5875 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden @@ -578,10 +578,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt mkdir -p "$CODEX_HOME/logs" && touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -607,6 +603,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=codex \ GH_AW_AWF_HARNESS_MARKER='[codex-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden index 409bc5cee5e..20fd7f1b5e5 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden @@ -525,10 +525,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -574,6 +570,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden index 602eb08222d..1ab7a7d1380 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden @@ -529,10 +529,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md (umask 177 && touch /tmp/gh-aw/agent-stdio.log) @@ -558,6 +554,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=gemini \ GH_AW_AWF_HARNESS_MARKER='[gemini-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden index d88d7517481..05e5e380b1e 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden @@ -459,10 +459,6 @@ jobs: run: | set -o pipefail trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt touch /tmp/gh-aw/agent-step-summary.md GH_AW_NODE_BIN=$(command -v node 2>/dev/null || true) @@ -490,6 +486,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=pi \ GH_AW_AWF_HARNESS_MARKER='[pi-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden index 23d29368ee9..fd81b27dc9f 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden @@ -525,10 +525,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -574,6 +570,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden index 0823e5f613a..fae0477dfbb 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden @@ -558,10 +558,6 @@ jobs: timeout-minutes: ${{ fromJSON(vars.GH_AW_DEFAULT_TIMEOUT_MINUTES || '20') }} run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -607,6 +603,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden index 73c22f568e4..6a73b1b696c 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden @@ -687,10 +687,6 @@ jobs: timeout-minutes: 15 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -736,6 +732,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden index 6a0372aea4e..9ba52f1f7a5 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden @@ -526,10 +526,6 @@ jobs: timeout-minutes: 10 run: | set -o pipefail - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" printf '%s' "$(date +%s%3N)" > /tmp/gh-aw/agent_cli_start_ms.txt trap 'gh_aw_exit_code=$?; mkdir -p /tmp/gh-aw >/dev/null 2>&1 || true; printf "%s" "$gh_aw_exit_code" > /tmp/gh-aw/agent_execution_exit_code.txt || true; rm -f "$HOME/.copilot/settings.json"; if [ "$gh_aw_exit_code" -ne 0 ]; then echo "::error::Agent execution exited with code $gh_aw_exit_code"; fi' EXIT mkdir -p "$HOME/.copilot" @@ -575,6 +571,10 @@ jobs: fi fi # shellcheck disable=SC1003,SC2016,SC2086 + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" GH_AW_AWF_ENGINE_NAME=copilot \ GH_AW_AWF_HARNESS_MARKER='[copilot-harness]' \ GH_AW_AWF_LOG_FILE=/tmp/gh-aw/agent-stdio.log \ diff --git a/pkg/workflow/threat_detection_external.go b/pkg/workflow/threat_detection_external.go index 74186961164..f766330c5ab 100644 --- a/pkg/workflow/threat_detection_external.go +++ b/pkg/workflow/threat_detection_external.go @@ -488,6 +488,7 @@ func (c *Compiler) buildExternalDetectorExecutionStep(data *WorkflowData) []stri PathSetup: pathSetup.hostSetup, } command := BuildAWFCommand(awfConfig) + command = injectComponentExecutionStartedInShellScript(command, "detection", detectionExecutionEvidencePath) // Reuse the engine's own execution env block so the external detector path // gets the same token/model/runtime environment configuration as the agent job. @@ -531,9 +532,6 @@ func (c *Compiler) buildExternalDetectorExecutionStep(data *WorkflowData) []stri // threat-detect without interpolating user-controlled prompt text into a command. steps = append(steps, c.buildThreatDetectionContextEnvVars(data, continueOnError, continueOnErrorExpr)...) steps = append(steps, " run: |\n") - for _, line := range componentExecutionEvidenceShellLines("detection", "started", detectionExecutionEvidencePath) { - steps = append(steps, " "+line+"\n") - } for _, line := range strings.SplitAfter(command, "\n") { if line == "" { continue From 8454ccb2e84d141e67b5d59e433ebf639b853e0e Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Sat, 12 Sep 2026 03:24:54 +0000 Subject: [PATCH 5/5] Preserve checkout before evidence initialization Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 12 ++++++------ .github/workflows/ace-editor.lock.yml | 12 ++++++------ .github/workflows/agent-job-health.lock.yml | 12 ++++++------ .../workflows/agent-performance-analyzer.lock.yml | 12 ++++++------ .github/workflows/agent-persona-explorer.lock.yml | 12 ++++++------ .github/workflows/agentic-token-audit.lock.yml | 12 ++++++------ .github/workflows/agentic-token-optimizer.lock.yml | 12 ++++++------ .../workflows/agentic-token-trend-audit.lock.yml | 12 ++++++------ .github/workflows/ai-moderator.lock.yml | 4 ++-- .github/workflows/api-consumption-report.lock.yml | 12 ++++++------ .github/workflows/approach-validator.lock.yml | 12 ++++++------ .github/workflows/archie.lock.yml | 12 ++++++------ .github/workflows/architecture-guardian.lock.yml | 12 ++++++------ .../archivx-agentic-workflows-analyzer.lock.yml | 12 ++++++------ .github/workflows/artifacts-summary.lock.yml | 12 ++++++------ .github/workflows/audit-workflows.lock.yml | 12 ++++++------ .github/workflows/auto-triage-issues.lock.yml | 12 ++++++------ .github/workflows/avenger.lock.yml | 12 ++++++------ .github/workflows/aw-failure-investigator.lock.yml | 12 ++++++------ .github/workflows/blog-auditor.lock.yml | 12 ++++++------ .github/workflows/bot-detection.lock.yml | 12 ++++++------ .github/workflows/breaking-change-checker.lock.yml | 12 ++++++------ .github/workflows/changeset.lock.yml | 12 ++++++------ .github/workflows/chaos-pr-bundle-fuzzer.lock.yml | 12 ++++++------ .github/workflows/ci-coach.lock.yml | 12 ++++++------ .github/workflows/ci-doctor.lock.yml | 12 ++++++------ .../claude-code-user-docs-review.lock.yml | 12 ++++++------ .github/workflows/cli-consistency-checker.lock.yml | 12 ++++++------ .github/workflows/cli-version-checker.lock.yml | 12 ++++++------ .github/workflows/cloclo.lock.yml | 12 ++++++------ .github/workflows/code-scanning-fixer.lock.yml | 12 ++++++------ .github/workflows/code-simplifier.lock.yml | 12 ++++++------ .../codex-github-remote-mcp-test.lock.yml | 12 ++++++------ .github/workflows/commit-changes-analyzer.lock.yml | 12 ++++++------ .github/workflows/constraint-solving-potd.lock.yml | 12 ++++++------ .github/workflows/contribution-check.lock.yml | 12 ++++++------ .github/workflows/copilot-agent-analysis.lock.yml | 12 ++++++------ .../copilot-centralization-drilldown.lock.yml | 12 ++++++------ .../copilot-centralization-optimizer.lock.yml | 12 ++++++------ .../workflows/copilot-cli-deep-research.lock.yml | 12 ++++++------ .github/workflows/copilot-opt.lock.yml | 12 ++++++------ .../workflows/copilot-pr-merged-report.lock.yml | 12 ++++++------ .github/workflows/copilot-pr-nlp-analysis.lock.yml | 12 ++++++------ .../workflows/copilot-pr-prompt-analysis.lock.yml | 12 ++++++------ .../workflows/copilot-session-insights.lock.yml | 12 ++++++------ .github/workflows/craft.lock.yml | 12 ++++++------ .../daily-action-setup-security-audit.lock.yml | 12 ++++++------ .../daily-agent-of-the-day-blog-writer.lock.yml | 12 ++++++------ .../daily-agentrx-trace-optimizer.lock.yml | 12 ++++++------ .../daily-ambient-context-optimizer.lock.yml | 12 ++++++------ .../workflows/daily-architecture-diagram.lock.yml | 12 ++++++------ .github/workflows/daily-arxiv-researcher.lock.yml | 12 ++++++------ .../workflows/daily-assign-issue-to-user.lock.yml | 12 ++++++------ ...ily-astrostylelite-markdown-spellcheck.lock.yml | 12 ++++++------ .../daily-aw-cross-repo-compile-check.lock.yml | 12 ++++++------ .../daily-awf-spec-compiler-surfacing.lock.yml | 12 ++++++------ .github/workflows/daily-byok-ollama-test.lock.yml | 12 ++++++------ .../daily-cache-strategy-analyzer.lock.yml | 12 ++++++------ .github/workflows/daily-caveman-optimizer.lock.yml | 12 ++++++------ .github/workflows/daily-choice-test.lock.yml | 12 ++++++------ .github/workflows/daily-cli-performance.lock.yml | 12 ++++++------ .github/workflows/daily-cli-tools-tester.lock.yml | 12 ++++++------ .github/workflows/daily-code-debt-aider.lock.yml | 12 ++++++------ .github/workflows/daily-code-metrics.lock.yml | 12 ++++++------ .../workflows/daily-community-attribution.lock.yml | 12 ++++++------ .github/workflows/daily-compiler-quality.lock.yml | 12 ++++++------ .../daily-compiler-threat-spec-optimizer.lock.yml | 12 ++++++------ .github/workflows/daily-credit-limit-test.lock.yml | 12 ++++++------ .github/workflows/daily-doc-healer.lock.yml | 12 ++++++------ .github/workflows/daily-doc-updater.lock.yml | 12 ++++++------ .../workflows/daily-documentation-diagram.lock.yml | 12 ++++++------ .../daily-elixir-credo-snippet-audit.lock.yml | 12 ++++++------ .github/workflows/daily-evals-report.lock.yml | 12 ++++++------ .github/workflows/daily-experiment-report.lock.yml | 12 ++++++------ .github/workflows/daily-fact.lock.yml | 12 ++++++------ .github/workflows/daily-file-diet.lock.yml | 12 ++++++------ .github/workflows/daily-firewall-report.lock.yml | 12 ++++++------ .../workflows/daily-formal-spec-verifier.lock.yml | 12 ++++++------ .github/workflows/daily-function-namer.lock.yml | 12 ++++++------ .github/workflows/daily-geo-optimizer.lock.yml | 12 ++++++------ .../daily-github-docs-seo-optimizer.lock.yml | 12 ++++++------ .../workflows/daily-go-test-parallelizer.lock.yml | 12 ++++++------ .../workflows/daily-go-test-stubs-aider.lock.yml | 12 ++++++------ .github/workflows/daily-grader-audit.lock.yml | 12 ++++++------ .../workflows/daily-graft-intelligence.lock.yml | 12 ++++++------ .../daily-harness-experiment-proposer.lock.yml | 12 ++++++------ .github/workflows/daily-hippo-learn.lock.yml | 12 ++++++------ .github/workflows/daily-issues-report.lock.yml | 12 ++++++------ .../workflows/daily-malicious-code-scan.lock.yml | 12 ++++++------ .../workflows/daily-max-ai-credits-test.lock.yml | 12 ++++++------ .../daily-mcp-concurrency-analysis.lock.yml | 12 ++++++------ .github/workflows/daily-model-inventory.lock.yml | 12 ++++++------ .github/workflows/daily-model-resolution.lock.yml | 12 ++++++------ .../daily-multi-device-docs-tester.lock.yml | 12 ++++++------ .github/workflows/daily-news.lock.yml | 12 ++++++------ .../workflows/daily-observability-report.lock.yml | 12 ++++++------ .../workflows/daily-performance-summary.lock.yml | 12 ++++++------ .github/workflows/daily-pr-review-cursor.lock.yml | 12 ++++++------ .../workflows/daily-regression-audit-kiro.lock.yml | 12 ++++++------ .github/workflows/daily-regulatory.lock.yml | 12 ++++++------ .../workflows/daily-reliability-review.lock.yml | 12 ++++++------ .../daily-rendering-scripts-verifier.lock.yml | 12 ++++++------ .github/workflows/daily-repo-chronicle.lock.yml | 12 ++++++------ .../daily-safe-output-integrator.lock.yml | 12 ++++++------ .../workflows/daily-safe-output-optimizer.lock.yml | 12 ++++++------ .../daily-safe-outputs-conformance.lock.yml | 12 ++++++------ .../daily-safeoutputs-git-simulator.lock.yml | 12 ++++++------ .../workflows/daily-schema-audit-cursor.lock.yml | 12 ++++++------ .github/workflows/daily-secrets-analysis.lock.yml | 12 ++++++------ .../daily-security-observability.lock.yml | 12 ++++++------ .github/workflows/daily-security-red-team.lock.yml | 12 ++++++------ .github/workflows/daily-semgrep-scan.lock.yml | 12 ++++++------ .github/workflows/daily-spdd-spec-planner.lock.yml | 12 ++++++------ .../workflows/daily-spec-coverage-kiro.lock.yml | 12 ++++++------ .github/workflows/daily-spending-forecast.lock.yml | 12 ++++++------ .github/workflows/daily-squid-image-scan.lock.yml | 12 ++++++------ .github/workflows/daily-storify.lock.yml | 12 ++++++------ .../workflows/daily-syntax-error-quality.lock.yml | 12 ++++++------ .../daily-team-evolution-insights.lock.yml | 12 ++++++------ .github/workflows/daily-team-status.lock.yml | 12 ++++++------ .../daily-testify-uber-super-expert.lock.yml | 12 ++++++------ .../daily-token-consumption-report.lock.yml | 12 ++++++------ .../daily-trajectory-grader-implementer.lock.yml | 12 ++++++------ .github/workflows/daily-vulnhunter-scan.lock.yml | 12 ++++++------ .../workflows/daily-windows-defender-scan.lock.yml | 12 ++++++------ ...y-windows-terminal-integration-builder.lock.yml | 12 ++++++------ .github/workflows/daily-workflow-updater.lock.yml | 12 ++++++------ .github/workflows/daily-yamllint-fixer.lock.yml | 12 ++++++------ .../dataflow-pr-discussion-dataset.lock.yml | 12 ++++++------ .github/workflows/dead-code-remover.lock.yml | 12 ++++++------ .github/workflows/deep-report.lock.yml | 12 ++++++------ .github/workflows/deepsec-security-scan.lock.yml | 4 ++-- .github/workflows/delight.lock.yml | 12 ++++++------ .github/workflows/dependabot-burner.lock.yml | 12 ++++++------ .github/workflows/dependabot-go-checker.lock.yml | 12 ++++++------ .../workflows/deployment-incident-monitor.lock.yml | 12 ++++++------ .github/workflows/design-decision-gate.lock.yml | 12 ++++++------ .github/workflows/designer-drift-audit.lock.yml | 12 ++++++------ .../workflows/detection-analysis-report.lock.yml | 12 ++++++------ .github/workflows/dev-hawk.lock.yml | 12 ++++++------ .github/workflows/dev.lock.yml | 12 ++++++------ .../workflows/developer-docs-consolidator.lock.yml | 12 ++++++------ .github/workflows/dictation-prompt.lock.yml | 12 ++++++------ .github/workflows/docs-noob-tester.lock.yml | 12 ++++++------ .github/workflows/draft-pr-cleanup.lock.yml | 12 ++++++------ .github/workflows/duplicate-code-detector.lock.yml | 12 ++++++------ .github/workflows/eslint-miner.lock.yml | 12 ++++++------ .github/workflows/eslint-monster.lock.yml | 12 ++++++------ .github/workflows/eslint-refiner.lock.yml | 12 ++++++------ .github/workflows/evoskill-evolver.lock.yml | 12 ++++++------ .../example-failure-category-filter.lock.yml | 12 ++++++------ .../workflows/example-permissions-warning.lock.yml | 12 ++++++------ .../workflows/example-workflow-analyzer.lock.yml | 12 ++++++------ .github/workflows/feature-grower.lock.yml | 12 ++++++------ .github/workflows/firewall-escape.lock.yml | 12 ++++++------ .github/workflows/firewall.lock.yml | 12 ++++++------ .github/workflows/front-page-copy-guard.lock.yml | 12 ++++++------ .github/workflows/functional-pragmatist.lock.yml | 12 ++++++------ .../github-mcp-structural-analysis.lock.yml | 12 ++++++------ .github/workflows/github-mcp-tools-report.lock.yml | 12 ++++++------ .../workflows/github-remote-mcp-auth-test.lock.yml | 12 ++++++------ .github/workflows/glossary-maintainer.lock.yml | 12 ++++++------ .github/workflows/go-fan.lock.yml | 12 ++++++------ .github/workflows/go-logger.lock.yml | 12 ++++++------ .github/workflows/go-pattern-detector.lock.yml | 12 ++++++------ .github/workflows/gpclean.lock.yml | 12 ++++++------ .github/workflows/grumpy-reviewer.lock.yml | 12 ++++++------ .github/workflows/hippo-embed.lock.yml | 12 ++++++------ .github/workflows/hourly-ci-cleaner.lock.yml | 12 ++++++------ .../workflows/impeccable-skills-reviewer.lock.yml | 12 ++++++------ .github/workflows/instructions-janitor.lock.yml | 12 ++++++------ .github/workflows/issue-arborist.lock.yml | 12 ++++++------ .github/workflows/issue-monster.lock.yml | 12 ++++++------ .github/workflows/issue-triage-agent.lock.yml | 12 ++++++------ .github/workflows/jsweep.lock.yml | 12 ++++++------ .github/workflows/layout-spec-maintainer.lock.yml | 12 ++++++------ .github/workflows/lint-monster.lock.yml | 12 ++++++------ .github/workflows/linter-miner.lock.yml | 12 ++++++------ .github/workflows/lockfile-stats.lock.yml | 12 ++++++------ .../workflows/mattpocock-skills-reviewer.lock.yml | 12 ++++++------ .github/workflows/mcp-inspector.lock.yml | 12 ++++++------ .github/workflows/mergefest.lock.yml | 12 ++++++------ .github/workflows/metrics-collector.lock.yml | 12 ++++++------ .github/workflows/necromancer.lock.yml | 12 ++++++------ .github/workflows/notion-issue-summary.lock.yml | 12 ++++++------ .github/workflows/objective-impact-report.lock.yml | 12 ++++++------ .github/workflows/org-health-report.lock.yml | 12 ++++++------ .github/workflows/outcome-collector.lock.yml | 12 ++++++------ .github/workflows/pdf-summary.lock.yml | 12 ++++++------ .github/workflows/plan.lock.yml | 12 ++++++------ .github/workflows/poem-bot.lock.yml | 12 ++++++------ .github/workflows/ponytail-reviewer.lock.yml | 12 ++++++------ .github/workflows/portfolio-analyst.lock.yml | 12 ++++++------ .../workflows/pr-code-quality-reviewer.lock.yml | 12 ++++++------ .github/workflows/pr-description-caveman.lock.yml | 12 ++++++------ .github/workflows/pr-nitpick-reviewer.lock.yml | 12 ++++++------ .github/workflows/pr-sous-chef.lock.yml | 12 ++++++------ .github/workflows/pr-triage-agent.lock.yml | 12 ++++++------ .../workflows/prompt-clustering-analysis.lock.yml | 12 ++++++------ .github/workflows/purelock.lock.yml | 12 ++++++------ .github/workflows/python-data-charts.lock.yml | 12 ++++++------ .github/workflows/q.lock.yml | 12 ++++++------ .github/workflows/refactoring-cadence.lock.yml | 12 ++++++------ .github/workflows/refiner.lock.yml | 12 ++++++------ .github/workflows/release.lock.yml | 12 ++++++------ .github/workflows/repo-audit-analyzer.lock.yml | 12 ++++++------ .github/workflows/repo-tree-map.lock.yml | 12 ++++++------ .../workflows/repository-quality-improver.lock.yml | 12 ++++++------ .github/workflows/research.lock.yml | 12 ++++++------ .github/workflows/ruflo-backed-task.lock.yml | 12 ++++++------ .github/workflows/safe-output-health.lock.yml | 12 ++++++------ .../workflows/schema-consistency-checker.lock.yml | 12 ++++++------ .github/workflows/schema-feature-coverage.lock.yml | 12 ++++++------ .github/workflows/scout.lock.yml | 12 ++++++------ .github/workflows/security-compliance.lock.yml | 12 ++++++------ .github/workflows/security-review.lock.yml | 12 ++++++------ .../workflows/semantic-function-refactor.lock.yml | 12 ++++++------ .github/workflows/sergo.lock.yml | 12 ++++++------ .../workflows/sighthound-security-scan.lock.yml | 12 ++++++------ .github/workflows/skillet.lock.yml | 12 ++++++------ .github/workflows/slide-deck-maintainer.lock.yml | 12 ++++++------ .github/workflows/smoke-agent-all-merged.lock.yml | 12 ++++++------ .github/workflows/smoke-agent-all-none.lock.yml | 12 ++++++------ .../workflows/smoke-agent-public-approved.lock.yml | 12 ++++++------ .github/workflows/smoke-agent-public-none.lock.yml | 12 ++++++------ .../workflows/smoke-agent-scoped-approved.lock.yml | 12 ++++++------ .github/workflows/smoke-aider.lock.yml | 12 ++++++------ .github/workflows/smoke-call-workflow.lock.yml | 12 ++++++------ .../workflows/smoke-checkout-pr-dispatch.lock.yml | 12 ++++++------ .github/workflows/smoke-ci.lock.yml | 12 ++++++------ .github/workflows/smoke-claude-on-copilot.lock.yml | 12 ++++++------ .github/workflows/smoke-claude.lock.yml | 12 ++++++------ .github/workflows/smoke-codex.lock.yml | 12 ++++++------ .../workflows/smoke-copilot-aoai-apikey.lock.yml | 12 ++++++------ .../workflows/smoke-copilot-aoai-entra.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot-arm.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot-auto.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot-mai.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot-sdk.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot-small.lock.yml | 12 ++++++------ .../workflows/smoke-copilot-sub-agents.lock.yml | 12 ++++++------ .github/workflows/smoke-copilot.lock.yml | 12 ++++++------ .../workflows/smoke-create-cross-repo-pr.lock.yml | 12 ++++++------ .github/workflows/smoke-crush.lock.yml | 12 ++++++------ .github/workflows/smoke-cursor.lock.yml | 12 ++++++------ .github/workflows/smoke-deepseek-harness.lock.yml | 12 ++++++------ .github/workflows/smoke-drive.lock.yml | 12 ++++++------ .github/workflows/smoke-gemini.lock.yml | 12 ++++++------ .github/workflows/smoke-github-claude.lock.yml | 12 ++++++------ .github/workflows/smoke-goose.lock.yml | 12 ++++++------ .github/workflows/smoke-issues.lock.yml | 12 ++++++------ .github/workflows/smoke-kiro.lock.yml | 12 ++++++------ .github/workflows/smoke-multi-pr.lock.yml | 12 ++++++------ .github/workflows/smoke-opencode.lock.yml | 12 ++++++------ .github/workflows/smoke-otel-backends.lock.yml | 12 ++++++------ .github/workflows/smoke-pi.lock.yml | 12 ++++++------ .github/workflows/smoke-project.lock.yml | 12 ++++++------ .github/workflows/smoke-pydantic.lock.yml | 12 ++++++------ .github/workflows/smoke-service-ports.lock.yml | 12 ++++++------ .github/workflows/smoke-temporary-id.lock.yml | 12 ++++++------ .github/workflows/smoke-test-tools.lock.yml | 12 ++++++------ .../workflows/smoke-update-cross-repo-pr.lock.yml | 12 ++++++------ .../smoke-workflow-call-with-inputs.lock.yml | 12 ++++++------ .github/workflows/smoke-workflow-call.lock.yml | 12 ++++++------ .github/workflows/spec-enforcer.lock.yml | 12 ++++++------ .github/workflows/spec-extractor.lock.yml | 12 ++++++------ .github/workflows/spec-librarian.lock.yml | 12 ++++++------ .github/workflows/squad-game-planner.lock.yml | 12 ++++++------ .github/workflows/squad-implement-worker.lock.yml | 12 ++++++------ .github/workflows/squad-plan.lock.yml | 12 ++++++------ .github/workflows/squad.lock.yml | 12 ++++++------ .github/workflows/stale-pr-cleanup.lock.yml | 12 ++++++------ .github/workflows/stale-repo-identifier.lock.yml | 12 ++++++------ .github/workflows/static-analysis-report.lock.yml | 12 ++++++------ .github/workflows/step-name-alignment.lock.yml | 12 ++++++------ .github/workflows/sub-issue-closer.lock.yml | 12 ++++++------ .github/workflows/super-linter.lock.yml | 12 ++++++------ .github/workflows/technical-doc-writer.lock.yml | 12 ++++++------ .github/workflows/terminal-stylist.lock.yml | 12 ++++++------ .github/workflows/test-quality-sentinel.lock.yml | 12 ++++++------ .github/workflows/tidy.lock.yml | 12 ++++++------ .github/workflows/typist.lock.yml | 12 ++++++------ .github/workflows/ubuntu-image-analyzer.lock.yml | 12 ++++++------ .../uk-ai-operational-resilience.lock.yml | 12 ++++++------ .github/workflows/unbloat-docs.lock.yml | 4 ++-- .github/workflows/update-astro.lock.yml | 12 ++++++------ .github/workflows/video-analyzer.lock.yml | 12 ++++++------ .../workflows/visual-regression-checker.lock.yml | 4 ++-- .github/workflows/weekly-blog-post-writer.lock.yml | 12 ++++++------ .../workflows/weekly-editors-health-check.lock.yml | 12 ++++++------ .github/workflows/weekly-issue-summary.lock.yml | 12 ++++++------ .../weekly-network-domains-audit.lock.yml | 12 ++++++------ .../weekly-safe-outputs-spec-review.lock.yml | 12 ++++++------ .github/workflows/windows-grower.lock.yml | 12 ++++++------ .github/workflows/windows.lock.yml | 14 +++++++------- .github/workflows/workflow-generator.lock.yml | 12 ++++++------ .github/workflows/workflow-health-manager.lock.yml | 12 ++++++------ .github/workflows/workflow-normalizer.lock.yml | 12 ++++++------ .../workflows/workflow-skill-extractor.lock.yml | 12 ++++++------ pkg/workflow/compiler_yaml_main_job.go | 8 ++++---- .../TestWasmGolden_AllEngines/claude.golden | 8 ++++---- .../TestWasmGolden_AllEngines/codex.golden | 8 ++++---- .../TestWasmGolden_AllEngines/copilot.golden | 8 ++++---- .../TestWasmGolden_AllEngines/gemini.golden | 8 ++++---- .../testdata/TestWasmGolden_AllEngines/pi.golden | 8 ++++---- .../basic-copilot.golden | 8 ++++---- .../playwright-cli-mode.golden | 8 ++++---- .../smoke-copilot.golden | 12 ++++++------ .../with-imports.golden | 8 ++++---- 309 files changed, 1821 insertions(+), 1821 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index 36706d0b181..7c1340aa3eb 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -495,18 +495,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/ace-editor.lock.yml b/.github/workflows/ace-editor.lock.yml index 9ce37d6967d..8619f59d055 100644 --- a/.github/workflows/ace-editor.lock.yml +++ b/.github/workflows/ace-editor.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index 7e499a95f0e..8b02fafc0fd 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -498,12 +498,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -540,6 +534,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index 57c2756579a..70aa35b84f2 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -534,12 +534,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -576,6 +570,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index 65a6f7c14ae..71f988e1401 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -537,12 +537,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -579,6 +573,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/agentic-token-audit.lock.yml b/.github/workflows/agentic-token-audit.lock.yml index 0abe9430f9c..3479e6cc462 100644 --- a/.github/workflows/agentic-token-audit.lock.yml +++ b/.github/workflows/agentic-token-audit.lock.yml @@ -481,12 +481,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -525,6 +519,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Build and install gh-aw CLI from source run: | gh extension remove aw || true diff --git a/.github/workflows/agentic-token-optimizer.lock.yml b/.github/workflows/agentic-token-optimizer.lock.yml index 17a8178bb28..d98bbbd5201 100644 --- a/.github/workflows/agentic-token-optimizer.lock.yml +++ b/.github/workflows/agentic-token-optimizer.lock.yml @@ -477,12 +477,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -491,6 +485,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Build and install gh-aw CLI from source run: | gh extension remove aw || true diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index 095b957a037..8c49d4722b4 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -480,12 +480,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -524,6 +518,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Build and install gh-aw CLI from source run: | gh extension remove aw || true diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index d2850bf30d8..5d3e7a1e80e 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -542,14 +542,14 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Mask OTLP telemetry headers + run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Mask OTLP telemetry headers - run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index a1793376baa..2ce29944f81 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -501,12 +501,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -543,6 +537,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index 8eb5bec3d2c..ca907e14490 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -580,18 +580,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 9df6326d260..6d14075d796 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -540,18 +540,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index e0adb2e83fb..c0ac4bd9a3d 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index c1f00f8e6a6..c79bbed1d12 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -546,12 +546,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -590,6 +584,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index a547e7821fb..20078842e1e 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index a0b666588ac..9614e416aeb 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -564,12 +564,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -606,6 +600,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index a1f9985e76d..44df35f9a56 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -502,18 +502,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index cdcaf910b77..b9f920b6d88 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -522,18 +522,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index d942e64044c..8e090f34b0c 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -539,12 +539,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -581,6 +575,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 33e1c07f8b1..a2cfe86ee5e 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -534,18 +534,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/bot-detection.lock.yml b/.github/workflows/bot-detection.lock.yml index 011dbe26e76..20a9271d374 100644 --- a/.github/workflows/bot-detection.lock.yml +++ b/.github/workflows/bot-detection.lock.yml @@ -500,18 +500,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index a6d2ded893d..d0793d3a691 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -525,18 +525,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index b35d5e53fb1..378a4d3b28d 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -538,18 +538,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index dc48e582d3e..150229859bd 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -488,18 +488,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index 393c528b304..9a9de572577 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -557,18 +557,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index 29cb72cf860..3d12c160e1f 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -580,18 +580,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index efbf131d734..3a192c45b8e 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -491,18 +491,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index e5d23fce484..93318e299ea 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index 0b9901a2e4e..c844329e155 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index d18741774e2..edc5cebc316 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -633,12 +633,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -675,6 +669,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index a0c582f2b2a..44911b60027 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -515,18 +515,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index 8b093e25515..193bbb51d27 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -508,18 +508,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Java uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 with: diff --git a/.github/workflows/codex-github-remote-mcp-test.lock.yml b/.github/workflows/codex-github-remote-mcp-test.lock.yml index 6e73ee20560..25e659fd100 100644 --- a/.github/workflows/codex-github-remote-mcp-test.lock.yml +++ b/.github/workflows/codex-github-remote-mcp-test.lock.yml @@ -466,18 +466,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 2683ada795b..5f22a6ae5b8 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -474,18 +474,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index afc215d47ac..8d2b2b3b3a0 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -472,18 +472,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index c768be2cb6a..4857ea72c89 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 33b1e83c57b..25918c4042d 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -545,18 +545,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-centralization-drilldown.lock.yml b/.github/workflows/copilot-centralization-drilldown.lock.yml index 6a70bec02cc..4350323de3f 100644 --- a/.github/workflows/copilot-centralization-drilldown.lock.yml +++ b/.github/workflows/copilot-centralization-drilldown.lock.yml @@ -461,12 +461,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -475,6 +469,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-centralization-optimizer.lock.yml b/.github/workflows/copilot-centralization-optimizer.lock.yml index baa645f62fc..262e20ab76c 100644 --- a/.github/workflows/copilot-centralization-optimizer.lock.yml +++ b/.github/workflows/copilot-centralization-optimizer.lock.yml @@ -471,12 +471,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -485,6 +479,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index 51db75ef314..52cdb810de0 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index d8038d50af8..7f5aea8eeac 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -485,18 +485,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 94b3ca4e1b0..d85482de492 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -465,18 +465,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index cd3687980cf..6b5249cdc55 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -500,18 +500,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 007bda4c274..44b98776f02 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -493,18 +493,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index fe7406278ff..98855a3965a 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -517,18 +517,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index 2d2b0dedf9e..b8f97744bd6 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -526,18 +526,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-action-setup-security-audit.lock.yml b/.github/workflows/daily-action-setup-security-audit.lock.yml index 97d34fef250..372ac4a701c 100644 --- a/.github/workflows/daily-action-setup-security-audit.lock.yml +++ b/.github/workflows/daily-action-setup-security-audit.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 8076ff9eb45..2125249708f 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -515,12 +515,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -557,6 +551,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index f02aded35cc..ffabac6fdde 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -533,12 +533,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -575,6 +569,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index 2802ffbb8ed..4e9aa79fff6 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -466,12 +466,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -508,6 +502,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 8064ff34ea7..241fe09477c 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -541,18 +541,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-arxiv-researcher.lock.yml b/.github/workflows/daily-arxiv-researcher.lock.yml index 237118ac632..e26b1f9f598 100644 --- a/.github/workflows/daily-arxiv-researcher.lock.yml +++ b/.github/workflows/daily-arxiv-researcher.lock.yml @@ -478,12 +478,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -492,6 +486,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index c7e23fcb5db..3f7e09cf770 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -458,18 +458,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index 1272741b1d2..f0ded07e879 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -534,18 +534,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index 325bf15dcdf..de5cbe73594 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index b689adb187d..6dd4d6ffde1 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index 30458b0c145..e1e3650520b 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -460,12 +460,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -474,6 +468,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index 6c31bad8689..6fa40f2a62e 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -536,12 +536,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -578,6 +572,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index 2b21a72f025..605992fda64 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -543,18 +543,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index 49f4d201d97..d429f2805f5 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -465,18 +465,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index e967d692e46..9e8644b13a6 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -525,18 +525,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index e0b587b8c07..25895296341 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -477,12 +477,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -519,6 +513,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-code-debt-aider.lock.yml b/.github/workflows/daily-code-debt-aider.lock.yml index 0901f9a7d4f..6a543d52308 100644 --- a/.github/workflows/daily-code-debt-aider.lock.yml +++ b/.github/workflows/daily-code-debt-aider.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index e05077a19bf..9b8479d4016 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -537,18 +537,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index c55fbbb80cd..6f8f38e6222 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -547,18 +547,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 04bdd33bc22..f497c531cf0 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -528,18 +528,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index e15a7c0cbcb..2100b4b4de1 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -491,18 +491,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index e07c3a07a8f..66fd74e42be 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -444,12 +444,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -458,6 +452,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 1396530d3d1..afca4d40756 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -549,18 +549,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index ace81ff8d49..5b1cc8dd75a 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -550,18 +550,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-documentation-diagram.lock.yml b/.github/workflows/daily-documentation-diagram.lock.yml index 833ce8369e0..af995cf5792 100644 --- a/.github/workflows/daily-documentation-diagram.lock.yml +++ b/.github/workflows/daily-documentation-diagram.lock.yml @@ -522,12 +522,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -536,6 +530,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index 120537524f8..a61d130ece3 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -490,12 +490,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -504,6 +498,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Elixir # zizmor: ignore[github_action_from_unverified_creator_used] uses: erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124 # v1.24.1 diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index fd4f56c72a4..25fc89f34a3 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -479,12 +479,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -521,6 +515,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 194630d21b6..f930609b780 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -483,18 +483,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index 0cff6df16b2..31d5151444e 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -537,18 +537,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index b869ae8f6fe..010320aac86 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -483,18 +483,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-firewall-report.lock.yml b/.github/workflows/daily-firewall-report.lock.yml index be2160f2dc5..b821568bee6 100644 --- a/.github/workflows/daily-firewall-report.lock.yml +++ b/.github/workflows/daily-firewall-report.lock.yml @@ -486,12 +486,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -528,6 +522,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index a03ade84078..f09137e099a 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -494,18 +494,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index 86eabbee3fd..7fb309baff1 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -482,18 +482,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index feef272563c..eac4ab15cc7 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -473,18 +473,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml index 07b08994bf5..9332863a7a5 100644 --- a/.github/workflows/daily-github-docs-seo-optimizer.lock.yml +++ b/.github/workflows/daily-github-docs-seo-optimizer.lock.yml @@ -432,12 +432,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -446,6 +440,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-go-test-parallelizer.lock.yml b/.github/workflows/daily-go-test-parallelizer.lock.yml index d1fb10339b8..7790ee1bf85 100644 --- a/.github/workflows/daily-go-test-parallelizer.lock.yml +++ b/.github/workflows/daily-go-test-parallelizer.lock.yml @@ -494,12 +494,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -508,6 +502,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-go-test-stubs-aider.lock.yml b/.github/workflows/daily-go-test-stubs-aider.lock.yml index 8b258b805a2..45be2840653 100644 --- a/.github/workflows/daily-go-test-stubs-aider.lock.yml +++ b/.github/workflows/daily-go-test-stubs-aider.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-grader-audit.lock.yml b/.github/workflows/daily-grader-audit.lock.yml index d54fce25e27..cc8043dfdd7 100644 --- a/.github/workflows/daily-grader-audit.lock.yml +++ b/.github/workflows/daily-grader-audit.lock.yml @@ -467,12 +467,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -511,6 +505,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 16b8ae38c4e..efc414155f3 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -465,12 +465,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -479,6 +473,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-harness-experiment-proposer.lock.yml b/.github/workflows/daily-harness-experiment-proposer.lock.yml index 4e8f41356f7..9b702c136ff 100644 --- a/.github/workflows/daily-harness-experiment-proposer.lock.yml +++ b/.github/workflows/daily-harness-experiment-proposer.lock.yml @@ -490,18 +490,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index 6fbc474d9f7..b163677e7c5 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 4ca4346a81e..53bfb9b1e0b 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -545,18 +545,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-malicious-code-scan.lock.yml b/.github/workflows/daily-malicious-code-scan.lock.yml index f0ca666d1a0..afe97cd1230 100644 --- a/.github/workflows/daily-malicious-code-scan.lock.yml +++ b/.github/workflows/daily-malicious-code-scan.lock.yml @@ -465,18 +465,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index 418173926d8..4c7af60bf81 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -400,12 +400,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -414,6 +408,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index 733944b0b50..5b42462183b 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -481,18 +481,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 83cb6258df7..589cf27dc54 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -470,18 +470,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 13c582ac9c3..c2d791a382a 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -475,12 +475,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -517,6 +511,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 221a8f8fd2f..103a620336f 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -476,18 +476,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 0d489f2a8f3..15d5e7949c4 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -546,18 +546,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index cc8cdd4bf23..4860729e9ea 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -481,12 +481,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -523,6 +517,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 2a5a98ea5ab..5cb93cfe3fe 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -485,18 +485,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-pr-review-cursor.lock.yml b/.github/workflows/daily-pr-review-cursor.lock.yml index fc96a0d1a1f..7309f9d4881 100644 --- a/.github/workflows/daily-pr-review-cursor.lock.yml +++ b/.github/workflows/daily-pr-review-cursor.lock.yml @@ -468,18 +468,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-regression-audit-kiro.lock.yml b/.github/workflows/daily-regression-audit-kiro.lock.yml index 5885e34b757..01a15f45452 100644 --- a/.github/workflows/daily-regression-audit-kiro.lock.yml +++ b/.github/workflows/daily-regression-audit-kiro.lock.yml @@ -469,18 +469,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 81cb84ce1a9..8397c43d6f7 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -477,18 +477,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index e10b45b26b6..67a4648ea39 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -462,18 +462,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index b26d880edba..4e7999e8dfa 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -566,12 +566,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -608,6 +602,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index dde597e0bf5..32bd8f9ee25 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -481,18 +481,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 075863b3ff7..d1acff4bcf9 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -486,18 +486,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index 2e0d6881b88..a19f38651cb 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -543,12 +543,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -585,6 +579,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 6c6eb87bb73..ea687210a47 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -471,18 +471,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml index 0e9adc28f1a..e110d186241 100644 --- a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml +++ b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml @@ -495,12 +495,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -516,6 +510,12 @@ jobs: run: | header=$(printf "x-access-token:%s" "${GH_AW_FETCH_TOKEN}" | base64 -w 0) git -c "http.extraheader=Authorization: Basic ${header}" fetch origin '+refs/heads/*:refs/remotes/origin/*' + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-schema-audit-cursor.lock.yml b/.github/workflows/daily-schema-audit-cursor.lock.yml index 5b1962fc90d..c3863e2ad99 100644 --- a/.github/workflows/daily-schema-audit-cursor.lock.yml +++ b/.github/workflows/daily-schema-audit-cursor.lock.yml @@ -467,18 +467,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 179c53efda7..3def8a2fa83 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -464,18 +464,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index 976e6985052..e4f96365d09 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -502,12 +502,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -544,6 +538,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index 1eb211e6e31..647a69b340e 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -506,18 +506,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-semgrep-scan.lock.yml b/.github/workflows/daily-semgrep-scan.lock.yml index 4341ddfb021..d8cb19b8adb 100644 --- a/.github/workflows/daily-semgrep-scan.lock.yml +++ b/.github/workflows/daily-semgrep-scan.lock.yml @@ -512,18 +512,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 8a782d0e4ac..838124b84cf 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -475,18 +475,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-spec-coverage-kiro.lock.yml b/.github/workflows/daily-spec-coverage-kiro.lock.yml index 73b8649f33e..aae3df15404 100644 --- a/.github/workflows/daily-spec-coverage-kiro.lock.yml +++ b/.github/workflows/daily-spec-coverage-kiro.lock.yml @@ -468,18 +468,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-spending-forecast.lock.yml b/.github/workflows/daily-spending-forecast.lock.yml index f4c7b5b3c4f..0b8b673628f 100644 --- a/.github/workflows/daily-spending-forecast.lock.yml +++ b/.github/workflows/daily-spending-forecast.lock.yml @@ -482,12 +482,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -526,6 +520,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/daily-squid-image-scan.lock.yml b/.github/workflows/daily-squid-image-scan.lock.yml index 0919ef746f7..0e91388991b 100644 --- a/.github/workflows/daily-squid-image-scan.lock.yml +++ b/.github/workflows/daily-squid-image-scan.lock.yml @@ -449,12 +449,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -463,6 +457,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-storify.lock.yml b/.github/workflows/daily-storify.lock.yml index b3d32ff0a65..7b7527b805e 100644 --- a/.github/workflows/daily-storify.lock.yml +++ b/.github/workflows/daily-storify.lock.yml @@ -494,12 +494,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -536,6 +530,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-syntax-error-quality.lock.yml b/.github/workflows/daily-syntax-error-quality.lock.yml index b9ec9a4ddc4..32191acc826 100644 --- a/.github/workflows/daily-syntax-error-quality.lock.yml +++ b/.github/workflows/daily-syntax-error-quality.lock.yml @@ -462,18 +462,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 728a2ff6836..65fdb2fc28c 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -462,18 +462,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-team-status.lock.yml b/.github/workflows/daily-team-status.lock.yml index c0866ad336e..e9b5b704582 100644 --- a/.github/workflows/daily-team-status.lock.yml +++ b/.github/workflows/daily-team-status.lock.yml @@ -464,12 +464,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -478,6 +472,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index a6e3f4ff76f..cb5fbba5295 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -495,18 +495,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 50cb67c75e3..87d6554df6d 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -459,18 +459,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-trajectory-grader-implementer.lock.yml b/.github/workflows/daily-trajectory-grader-implementer.lock.yml index ceab7f37283..6582ccbf72a 100644 --- a/.github/workflows/daily-trajectory-grader-implementer.lock.yml +++ b/.github/workflows/daily-trajectory-grader-implementer.lock.yml @@ -491,12 +491,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -505,6 +499,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index 2b7a600a038..d424e42c3f2 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -470,18 +470,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-windows-defender-scan.lock.yml b/.github/workflows/daily-windows-defender-scan.lock.yml index 48b90b9edf3..c2859c04187 100644 --- a/.github/workflows/daily-windows-defender-scan.lock.yml +++ b/.github/workflows/daily-windows-defender-scan.lock.yml @@ -466,12 +466,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -480,6 +474,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml index c4361e733c2..ff31bf704d2 100644 --- a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml +++ b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml @@ -456,12 +456,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -470,6 +464,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-workflow-updater.lock.yml b/.github/workflows/daily-workflow-updater.lock.yml index ac856525c7e..8708ad0c98d 100644 --- a/.github/workflows/daily-workflow-updater.lock.yml +++ b/.github/workflows/daily-workflow-updater.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/daily-yamllint-fixer.lock.yml b/.github/workflows/daily-yamllint-fixer.lock.yml index becfb180ee7..ef54adb197b 100644 --- a/.github/workflows/daily-yamllint-fixer.lock.yml +++ b/.github/workflows/daily-yamllint-fixer.lock.yml @@ -499,18 +499,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index 315a4eff23e..9448b41421e 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -536,12 +536,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) @@ -552,6 +546,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index c20748e86b6..e3ad9e77222 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -508,18 +508,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index abca4245f62..5d6c0d9952d 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -561,12 +561,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -603,6 +597,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/deepsec-security-scan.lock.yml b/.github/workflows/deepsec-security-scan.lock.yml index bda48c6d54a..6561ad9c1a9 100644 --- a/.github/workflows/deepsec-security-scan.lock.yml +++ b/.github/workflows/deepsec-security-scan.lock.yml @@ -499,14 +499,14 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Mask OTLP telemetry headers + run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Mask OTLP telemetry headers - run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index 98616ad4e2b..9bbc5a5c9d1 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -479,18 +479,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index 76e4624d9fd..b627b80cd5d 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -565,18 +565,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/dependabot-go-checker.lock.yml b/.github/workflows/dependabot-go-checker.lock.yml index 7914c0a3a92..b6c54795d6f 100644 --- a/.github/workflows/dependabot-go-checker.lock.yml +++ b/.github/workflows/dependabot-go-checker.lock.yml @@ -518,18 +518,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index f0a47c814fb..55001ad6f56 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -482,18 +482,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index 5e7fdf133d9..fdacbf3462c 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -557,12 +557,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -582,6 +576,12 @@ jobs: setupGlobals(core, github, context, exec, io, getOctokit); const { main } = require(path.join(actionsDir, 'merge_remote_agent_github_folder.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/designer-drift-audit.lock.yml b/.github/workflows/designer-drift-audit.lock.yml index 259e06c2952..42ce5a2dab7 100644 --- a/.github/workflows/designer-drift-audit.lock.yml +++ b/.github/workflows/designer-drift-audit.lock.yml @@ -460,12 +460,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -474,6 +468,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index aaf08330b52..8c0edf13770 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -493,12 +493,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -535,6 +529,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/dev-hawk.lock.yml b/.github/workflows/dev-hawk.lock.yml index 9f3cd7f09f5..336ad2b1ced 100644 --- a/.github/workflows/dev-hawk.lock.yml +++ b/.github/workflows/dev-hawk.lock.yml @@ -503,12 +503,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -545,6 +539,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/dev.lock.yml b/.github/workflows/dev.lock.yml index aa2480f24d5..78aa88133e9 100644 --- a/.github/workflows/dev.lock.yml +++ b/.github/workflows/dev.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index 69384ad9e46..7d53c9c2bc0 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -523,18 +523,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/dictation-prompt.lock.yml b/.github/workflows/dictation-prompt.lock.yml index dd214204db9..22e85847721 100644 --- a/.github/workflows/dictation-prompt.lock.yml +++ b/.github/workflows/dictation-prompt.lock.yml @@ -481,18 +481,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 07aebe47c8a..956474235d2 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -469,18 +469,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/draft-pr-cleanup.lock.yml b/.github/workflows/draft-pr-cleanup.lock.yml index f3369af5c06..ae3fb445ca5 100644 --- a/.github/workflows/draft-pr-cleanup.lock.yml +++ b/.github/workflows/draft-pr-cleanup.lock.yml @@ -459,18 +459,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 5bd6dc99dad..f435b716329 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -466,18 +466,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/eslint-miner.lock.yml b/.github/workflows/eslint-miner.lock.yml index 8c625ceb51d..2f2543c840c 100644 --- a/.github/workflows/eslint-miner.lock.yml +++ b/.github/workflows/eslint-miner.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -502,6 +496,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index f41e50405f6..35cf130faa0 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -471,18 +471,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index f00b7cae6f3..0fc9b010f77 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -483,18 +483,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/evoskill-evolver.lock.yml b/.github/workflows/evoskill-evolver.lock.yml index a90653a2332..d82b4a7af09 100644 --- a/.github/workflows/evoskill-evolver.lock.yml +++ b/.github/workflows/evoskill-evolver.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -502,6 +496,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/example-failure-category-filter.lock.yml b/.github/workflows/example-failure-category-filter.lock.yml index 6c28dcddfd5..0823cda3f47 100644 --- a/.github/workflows/example-failure-category-filter.lock.yml +++ b/.github/workflows/example-failure-category-filter.lock.yml @@ -454,12 +454,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -468,6 +462,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/example-permissions-warning.lock.yml b/.github/workflows/example-permissions-warning.lock.yml index aa2606e7984..111ddb8b495 100644 --- a/.github/workflows/example-permissions-warning.lock.yml +++ b/.github/workflows/example-permissions-warning.lock.yml @@ -466,18 +466,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index 7f95dea5447..298468b74c9 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -475,12 +475,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -517,6 +511,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/feature-grower.lock.yml b/.github/workflows/feature-grower.lock.yml index d0516e432c7..37d9534ad54 100644 --- a/.github/workflows/feature-grower.lock.yml +++ b/.github/workflows/feature-grower.lock.yml @@ -464,12 +464,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -478,6 +472,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/firewall-escape.lock.yml b/.github/workflows/firewall-escape.lock.yml index 4e047a53cf0..b24f3b0af67 100644 --- a/.github/workflows/firewall-escape.lock.yml +++ b/.github/workflows/firewall-escape.lock.yml @@ -514,18 +514,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/firewall.lock.yml b/.github/workflows/firewall.lock.yml index bb553f28c95..fa6c17e5d7a 100644 --- a/.github/workflows/firewall.lock.yml +++ b/.github/workflows/firewall.lock.yml @@ -459,18 +459,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/front-page-copy-guard.lock.yml b/.github/workflows/front-page-copy-guard.lock.yml index ec6db9bff5c..25dce35a30b 100644 --- a/.github/workflows/front-page-copy-guard.lock.yml +++ b/.github/workflows/front-page-copy-guard.lock.yml @@ -481,18 +481,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/functional-pragmatist.lock.yml b/.github/workflows/functional-pragmatist.lock.yml index e42eb7eed4d..78825221741 100644 --- a/.github/workflows/functional-pragmatist.lock.yml +++ b/.github/workflows/functional-pragmatist.lock.yml @@ -492,18 +492,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 62e1203b3f1..e22490b22bf 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -495,18 +495,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index cb8bc7eac85..46237487a66 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -504,18 +504,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 0b6a99feb2a..4df4a8138c8 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -466,18 +466,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index c2cb548e613..b5d86ac3fb5 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -524,12 +524,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -550,6 +544,12 @@ jobs: setupGlobals(core, github, context, exec, io, getOctokit); const { main } = require(path.join(actionsDir, 'merge_remote_agent_github_folder.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index 7353e613a76..3e5a4c926e9 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -492,18 +492,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/go-logger.lock.yml b/.github/workflows/go-logger.lock.yml index 82f6eae8049..923262628ae 100644 --- a/.github/workflows/go-logger.lock.yml +++ b/.github/workflows/go-logger.lock.yml @@ -505,18 +505,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/go-pattern-detector.lock.yml b/.github/workflows/go-pattern-detector.lock.yml index a7e415f206e..6ad3eba2473 100644 --- a/.github/workflows/go-pattern-detector.lock.yml +++ b/.github/workflows/go-pattern-detector.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/gpclean.lock.yml b/.github/workflows/gpclean.lock.yml index 2a54be5ea18..3cfbca04365 100644 --- a/.github/workflows/gpclean.lock.yml +++ b/.github/workflows/gpclean.lock.yml @@ -529,18 +529,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index 44c6f8464ed..bed1aec7035 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -535,18 +535,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/hippo-embed.lock.yml b/.github/workflows/hippo-embed.lock.yml index 199878f2824..5b2c4f88f21 100644 --- a/.github/workflows/hippo-embed.lock.yml +++ b/.github/workflows/hippo-embed.lock.yml @@ -465,12 +465,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Install PMG (Package Manager Guard) @@ -481,6 +475,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/hourly-ci-cleaner.lock.yml b/.github/workflows/hourly-ci-cleaner.lock.yml index 316da1450ea..8e5f47b7a74 100644 --- a/.github/workflows/hourly-ci-cleaner.lock.yml +++ b/.github/workflows/hourly-ci-cleaner.lock.yml @@ -509,12 +509,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -534,6 +528,12 @@ jobs: setupGlobals(core, github, context, exec, io, getOctokit); const { main } = require(path.join(actionsDir, 'merge_remote_agent_github_folder.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index ec89cb656f9..0295b024a34 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -540,18 +540,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/instructions-janitor.lock.yml b/.github/workflows/instructions-janitor.lock.yml index 7681b6e715d..5232567ae9c 100644 --- a/.github/workflows/instructions-janitor.lock.yml +++ b/.github/workflows/instructions-janitor.lock.yml @@ -499,18 +499,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/issue-arborist.lock.yml b/.github/workflows/issue-arborist.lock.yml index 0c069da6542..740f8fd663e 100644 --- a/.github/workflows/issue-arborist.lock.yml +++ b/.github/workflows/issue-arborist.lock.yml @@ -514,18 +514,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index f378ce3be23..134bb1c7374 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -973,18 +973,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/issue-triage-agent.lock.yml b/.github/workflows/issue-triage-agent.lock.yml index 1d92defbead..d1938bf5818 100644 --- a/.github/workflows/issue-triage-agent.lock.yml +++ b/.github/workflows/issue-triage-agent.lock.yml @@ -458,18 +458,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/jsweep.lock.yml b/.github/workflows/jsweep.lock.yml index 867ef4728a7..69e9ee5e442 100644 --- a/.github/workflows/jsweep.lock.yml +++ b/.github/workflows/jsweep.lock.yml @@ -478,18 +478,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/layout-spec-maintainer.lock.yml b/.github/workflows/layout-spec-maintainer.lock.yml index c17bf1b785b..a728592e098 100644 --- a/.github/workflows/layout-spec-maintainer.lock.yml +++ b/.github/workflows/layout-spec-maintainer.lock.yml @@ -491,18 +491,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/lint-monster.lock.yml b/.github/workflows/lint-monster.lock.yml index f04de3db8e7..34d6c90cae3 100644 --- a/.github/workflows/lint-monster.lock.yml +++ b/.github/workflows/lint-monster.lock.yml @@ -470,18 +470,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index c070ad78a84..077e521de27 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -505,18 +505,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 4f7844ab1ed..23d0e7c3130 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -479,18 +479,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index c3b1fb4d16b..7ce7416d7db 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -642,18 +642,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 34a3f70608b..b3659b4ae88 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -517,12 +517,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -559,6 +553,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/mergefest.lock.yml b/.github/workflows/mergefest.lock.yml index 906ce08109e..8a8e8330a95 100644 --- a/.github/workflows/mergefest.lock.yml +++ b/.github/workflows/mergefest.lock.yml @@ -527,18 +527,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/metrics-collector.lock.yml b/.github/workflows/metrics-collector.lock.yml index 34474829c97..e449f0fc96c 100644 --- a/.github/workflows/metrics-collector.lock.yml +++ b/.github/workflows/metrics-collector.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -530,6 +524,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/necromancer.lock.yml b/.github/workflows/necromancer.lock.yml index 4cf33ab4ade..497b934e9ab 100644 --- a/.github/workflows/necromancer.lock.yml +++ b/.github/workflows/necromancer.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/notion-issue-summary.lock.yml b/.github/workflows/notion-issue-summary.lock.yml index 7f0690e8fe4..1b81528fd0d 100644 --- a/.github/workflows/notion-issue-summary.lock.yml +++ b/.github/workflows/notion-issue-summary.lock.yml @@ -473,18 +473,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/objective-impact-report.lock.yml b/.github/workflows/objective-impact-report.lock.yml index dff49b5d3e4..825137062f3 100644 --- a/.github/workflows/objective-impact-report.lock.yml +++ b/.github/workflows/objective-impact-report.lock.yml @@ -460,12 +460,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -474,6 +468,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/org-health-report.lock.yml b/.github/workflows/org-health-report.lock.yml index c6eb8d30d7c..ec8b2d271cb 100644 --- a/.github/workflows/org-health-report.lock.yml +++ b/.github/workflows/org-health-report.lock.yml @@ -490,18 +490,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/outcome-collector.lock.yml b/.github/workflows/outcome-collector.lock.yml index d4c9ac14fb9..4c72b6abb30 100644 --- a/.github/workflows/outcome-collector.lock.yml +++ b/.github/workflows/outcome-collector.lock.yml @@ -479,18 +479,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/pdf-summary.lock.yml b/.github/workflows/pdf-summary.lock.yml index adf7fe507c5..d6cf0aa58f5 100644 --- a/.github/workflows/pdf-summary.lock.yml +++ b/.github/workflows/pdf-summary.lock.yml @@ -563,18 +563,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/plan.lock.yml b/.github/workflows/plan.lock.yml index eceb1178ea1..fb6f3961b6b 100644 --- a/.github/workflows/plan.lock.yml +++ b/.github/workflows/plan.lock.yml @@ -579,18 +579,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/poem-bot.lock.yml b/.github/workflows/poem-bot.lock.yml index 127292cb2f5..b825c3a25e7 100644 --- a/.github/workflows/poem-bot.lock.yml +++ b/.github/workflows/poem-bot.lock.yml @@ -553,18 +553,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index c37e1140801..a4197a97078 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -573,18 +573,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index 6fed2f7f5f6..debeba57cc5 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -490,12 +490,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -504,6 +498,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 0e2171ca948..94e49bd084d 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -542,18 +542,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index 429b545a576..fe0735a976f 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -502,6 +496,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index 012a666b07b..f7b4d970d38 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -537,18 +537,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index 7c2f2dba12b..0be3e3a013a 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -579,12 +579,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -598,6 +592,12 @@ jobs: run: | header=$(printf "x-access-token:%s" "${GH_AW_FETCH_TOKEN}" | base64 -w 0) git -c "http.extraheader=Authorization: Basic ${header}" fetch origin '+refs/pull/*/head:refs/remotes/origin/pull/*/head' + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 33e7555b1bc..366d48f70ec 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -486,18 +486,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 4d76740781d..3fbb77a2f06 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -501,12 +501,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -543,6 +537,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index 2b6044a3fd8..89380b0bcd7 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -510,18 +510,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index e0a8e5f1a5a..9ee60a54cde 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -530,6 +524,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index 7110fb8a848..bad3a4c1af5 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -587,12 +587,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -629,6 +623,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index 3dd01236550..8db11996681 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -472,18 +472,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index e74b419477a..f8d5e5f20d6 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/release.lock.yml b/.github/workflows/release.lock.yml index 1db1c6b7b78..ee8aebee24b 100644 --- a/.github/workflows/release.lock.yml +++ b/.github/workflows/release.lock.yml @@ -488,18 +488,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index 8a52f2cfcdd..f6edac4d2c0 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -488,18 +488,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/repo-tree-map.lock.yml b/.github/workflows/repo-tree-map.lock.yml index ff13ef5df1c..39ec11f2c38 100644 --- a/.github/workflows/repo-tree-map.lock.yml +++ b/.github/workflows/repo-tree-map.lock.yml @@ -449,18 +449,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index 036931ff79b..ce3976e3c99 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -488,18 +488,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/research.lock.yml b/.github/workflows/research.lock.yml index 3653ff61113..8d80491e529 100644 --- a/.github/workflows/research.lock.yml +++ b/.github/workflows/research.lock.yml @@ -457,18 +457,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/ruflo-backed-task.lock.yml b/.github/workflows/ruflo-backed-task.lock.yml index a374c809373..9cb62ef7623 100644 --- a/.github/workflows/ruflo-backed-task.lock.yml +++ b/.github/workflows/ruflo-backed-task.lock.yml @@ -551,12 +551,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -565,6 +559,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 3faad88abf2..45563d324da 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -488,12 +488,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -530,6 +524,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index 8878a1cab82..2f46b743fe1 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -482,12 +482,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -495,6 +489,12 @@ jobs: with: persist-credentials: false fetch-depth: 1 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/schema-feature-coverage.lock.yml b/.github/workflows/schema-feature-coverage.lock.yml index 80cab34f44f..b285545317c 100644 --- a/.github/workflows/schema-feature-coverage.lock.yml +++ b/.github/workflows/schema-feature-coverage.lock.yml @@ -471,12 +471,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -484,6 +478,12 @@ jobs: with: persist-credentials: false fetch-depth: 1 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/scout.lock.yml b/.github/workflows/scout.lock.yml index d5d3918a938..c9d4761d82b 100644 --- a/.github/workflows/scout.lock.yml +++ b/.github/workflows/scout.lock.yml @@ -576,18 +576,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/security-compliance.lock.yml b/.github/workflows/security-compliance.lock.yml index f1e99bc53b0..b9f325e8e8e 100644 --- a/.github/workflows/security-compliance.lock.yml +++ b/.github/workflows/security-compliance.lock.yml @@ -497,18 +497,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index ccfc7c1acae..13351d6b918 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -535,12 +535,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -577,6 +571,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index ff557261023..9f53ffb9256 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -477,18 +477,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index af7f84cf0bb..707abf483d1 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -492,18 +492,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/sighthound-security-scan.lock.yml b/.github/workflows/sighthound-security-scan.lock.yml index 1bfd3f1b451..f9ffc479414 100644 --- a/.github/workflows/sighthound-security-scan.lock.yml +++ b/.github/workflows/sighthound-security-scan.lock.yml @@ -458,12 +458,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -472,6 +466,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index 83fd6854ad3..0f051048415 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -550,18 +550,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index feff2c0705c..98c857b5e07 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -524,18 +524,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-agent-all-merged.lock.yml b/.github/workflows/smoke-agent-all-merged.lock.yml index 0af7e04c383..8c383ea4901 100644 --- a/.github/workflows/smoke-agent-all-merged.lock.yml +++ b/.github/workflows/smoke-agent-all-merged.lock.yml @@ -536,18 +536,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-agent-all-none.lock.yml b/.github/workflows/smoke-agent-all-none.lock.yml index f6f042e0337..693466d9919 100644 --- a/.github/workflows/smoke-agent-all-none.lock.yml +++ b/.github/workflows/smoke-agent-all-none.lock.yml @@ -534,18 +534,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-agent-public-approved.lock.yml b/.github/workflows/smoke-agent-public-approved.lock.yml index 6c6d5f22ab7..fa5803aa3ab 100644 --- a/.github/workflows/smoke-agent-public-approved.lock.yml +++ b/.github/workflows/smoke-agent-public-approved.lock.yml @@ -539,18 +539,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-agent-public-none.lock.yml b/.github/workflows/smoke-agent-public-none.lock.yml index 1eae7388df4..cfacec8aaf6 100644 --- a/.github/workflows/smoke-agent-public-none.lock.yml +++ b/.github/workflows/smoke-agent-public-none.lock.yml @@ -534,18 +534,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-agent-scoped-approved.lock.yml b/.github/workflows/smoke-agent-scoped-approved.lock.yml index 66ef904d6d5..f52d3b52771 100644 --- a/.github/workflows/smoke-agent-scoped-approved.lock.yml +++ b/.github/workflows/smoke-agent-scoped-approved.lock.yml @@ -541,18 +541,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-aider.lock.yml b/.github/workflows/smoke-aider.lock.yml index 51e1e263cb9..5c33e09af8d 100644 --- a/.github/workflows/smoke-aider.lock.yml +++ b/.github/workflows/smoke-aider.lock.yml @@ -524,12 +524,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -538,6 +532,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/smoke-call-workflow.lock.yml b/.github/workflows/smoke-call-workflow.lock.yml index 084b73e20ec..2421e03fa36 100644 --- a/.github/workflows/smoke-call-workflow.lock.yml +++ b/.github/workflows/smoke-call-workflow.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml index b89fe988496..422a2832d3b 100644 --- a/.github/workflows/smoke-checkout-pr-dispatch.lock.yml +++ b/.github/workflows/smoke-checkout-pr-dispatch.lock.yml @@ -541,18 +541,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-ci.lock.yml b/.github/workflows/smoke-ci.lock.yml index 2473d705f28..aea940c9bab 100644 --- a/.github/workflows/smoke-ci.lock.yml +++ b/.github/workflows/smoke-ci.lock.yml @@ -529,18 +529,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-claude-on-copilot.lock.yml b/.github/workflows/smoke-claude-on-copilot.lock.yml index 58f14dd15e0..51527051a05 100644 --- a/.github/workflows/smoke-claude-on-copilot.lock.yml +++ b/.github/workflows/smoke-claude-on-copilot.lock.yml @@ -526,12 +526,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -540,6 +534,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-claude.lock.yml b/.github/workflows/smoke-claude.lock.yml index 134efcd7e7a..a895626d30e 100644 --- a/.github/workflows/smoke-claude.lock.yml +++ b/.github/workflows/smoke-claude.lock.yml @@ -577,12 +577,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -629,6 +623,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-codex.lock.yml b/.github/workflows/smoke-codex.lock.yml index 278ce5086df..6b9aadc8985 100644 --- a/.github/workflows/smoke-codex.lock.yml +++ b/.github/workflows/smoke-codex.lock.yml @@ -571,12 +571,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -584,6 +578,12 @@ jobs: with: persist-credentials: false fetch-depth: 2 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml index 682a6d10e3f..cd2c842ade0 100644 --- a/.github/workflows/smoke-copilot-aoai-apikey.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-apikey.lock.yml @@ -639,12 +639,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -681,6 +675,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-copilot-aoai-entra.lock.yml b/.github/workflows/smoke-copilot-aoai-entra.lock.yml index b59c31bf718..4d9453b32f4 100644 --- a/.github/workflows/smoke-copilot-aoai-entra.lock.yml +++ b/.github/workflows/smoke-copilot-aoai-entra.lock.yml @@ -646,12 +646,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - id: azure-oidc @@ -692,6 +686,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-copilot-arm.lock.yml b/.github/workflows/smoke-copilot-arm.lock.yml index 8f90b362665..6c787e3e7a6 100644 --- a/.github/workflows/smoke-copilot-arm.lock.yml +++ b/.github/workflows/smoke-copilot-arm.lock.yml @@ -573,12 +573,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -615,6 +609,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-copilot-auto.lock.yml b/.github/workflows/smoke-copilot-auto.lock.yml index a6c4de2f296..7e60f9c5d16 100644 --- a/.github/workflows/smoke-copilot-auto.lock.yml +++ b/.github/workflows/smoke-copilot-auto.lock.yml @@ -516,12 +516,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -530,6 +524,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-copilot-mai.lock.yml b/.github/workflows/smoke-copilot-mai.lock.yml index 903bae4b082..c61a5f9f17e 100644 --- a/.github/workflows/smoke-copilot-mai.lock.yml +++ b/.github/workflows/smoke-copilot-mai.lock.yml @@ -552,12 +552,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -566,6 +560,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-copilot-sdk.lock.yml b/.github/workflows/smoke-copilot-sdk.lock.yml index 428ab20a6c3..920aa0ca5fe 100644 --- a/.github/workflows/smoke-copilot-sdk.lock.yml +++ b/.github/workflows/smoke-copilot-sdk.lock.yml @@ -549,12 +549,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -563,6 +557,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-copilot-small.lock.yml b/.github/workflows/smoke-copilot-small.lock.yml index 46521a68d45..9ecbb4456e9 100644 --- a/.github/workflows/smoke-copilot-small.lock.yml +++ b/.github/workflows/smoke-copilot-small.lock.yml @@ -552,12 +552,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -566,6 +560,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-copilot-sub-agents.lock.yml b/.github/workflows/smoke-copilot-sub-agents.lock.yml index 5a87bf1a25f..23263462446 100644 --- a/.github/workflows/smoke-copilot-sub-agents.lock.yml +++ b/.github/workflows/smoke-copilot-sub-agents.lock.yml @@ -503,12 +503,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -517,6 +511,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-copilot.lock.yml b/.github/workflows/smoke-copilot.lock.yml index 8e4aa18f868..554e3142f94 100644 --- a/.github/workflows/smoke-copilot.lock.yml +++ b/.github/workflows/smoke-copilot.lock.yml @@ -647,12 +647,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -689,6 +683,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/.github/workflows/smoke-create-cross-repo-pr.lock.yml b/.github/workflows/smoke-create-cross-repo-pr.lock.yml index aeb1b9b083c..7f65bbfe8b2 100644 --- a/.github/workflows/smoke-create-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-create-cross-repo-pr.lock.yml @@ -537,12 +537,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -570,6 +564,12 @@ jobs: const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); const { main } = require(path.join(actionsDir, 'build_checkout_manifest.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-crush.lock.yml b/.github/workflows/smoke-crush.lock.yml index 0ab0d1cbe4e..c5000bd3b7a 100644 --- a/.github/workflows/smoke-crush.lock.yml +++ b/.github/workflows/smoke-crush.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-cursor.lock.yml b/.github/workflows/smoke-cursor.lock.yml index 0e19a8cdf1f..b36fbb66b06 100644 --- a/.github/workflows/smoke-cursor.lock.yml +++ b/.github/workflows/smoke-cursor.lock.yml @@ -538,18 +538,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-deepseek-harness.lock.yml b/.github/workflows/smoke-deepseek-harness.lock.yml index c07916b6e31..104cf4a0e10 100644 --- a/.github/workflows/smoke-deepseek-harness.lock.yml +++ b/.github/workflows/smoke-deepseek-harness.lock.yml @@ -534,18 +534,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-drive.lock.yml b/.github/workflows/smoke-drive.lock.yml index f2ae5651c2e..f44ef622680 100644 --- a/.github/workflows/smoke-drive.lock.yml +++ b/.github/workflows/smoke-drive.lock.yml @@ -541,12 +541,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -555,6 +549,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index 2cab9f779fc..e3108053e98 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -596,18 +596,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-github-claude.lock.yml b/.github/workflows/smoke-github-claude.lock.yml index aa53e1ed097..ed5511a8003 100644 --- a/.github/workflows/smoke-github-claude.lock.yml +++ b/.github/workflows/smoke-github-claude.lock.yml @@ -526,12 +526,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -540,6 +534,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-goose.lock.yml b/.github/workflows/smoke-goose.lock.yml index 59d3b6a22a5..38f3c1064dc 100644 --- a/.github/workflows/smoke-goose.lock.yml +++ b/.github/workflows/smoke-goose.lock.yml @@ -533,18 +533,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-issues.lock.yml b/.github/workflows/smoke-issues.lock.yml index 68fa78479bd..15b57e1ba43 100644 --- a/.github/workflows/smoke-issues.lock.yml +++ b/.github/workflows/smoke-issues.lock.yml @@ -478,12 +478,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -492,6 +486,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-kiro.lock.yml b/.github/workflows/smoke-kiro.lock.yml index 42b5436deeb..fa272a36db4 100644 --- a/.github/workflows/smoke-kiro.lock.yml +++ b/.github/workflows/smoke-kiro.lock.yml @@ -538,18 +538,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-multi-pr.lock.yml b/.github/workflows/smoke-multi-pr.lock.yml index ee0c8a4a446..3c61974c6c8 100644 --- a/.github/workflows/smoke-multi-pr.lock.yml +++ b/.github/workflows/smoke-multi-pr.lock.yml @@ -535,18 +535,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-opencode.lock.yml b/.github/workflows/smoke-opencode.lock.yml index 4db3748d873..7cefeb8bf0d 100644 --- a/.github/workflows/smoke-opencode.lock.yml +++ b/.github/workflows/smoke-opencode.lock.yml @@ -540,18 +540,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-otel-backends.lock.yml b/.github/workflows/smoke-otel-backends.lock.yml index c9ecbf7914f..7be4459d51d 100644 --- a/.github/workflows/smoke-otel-backends.lock.yml +++ b/.github/workflows/smoke-otel-backends.lock.yml @@ -575,18 +575,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-pi.lock.yml b/.github/workflows/smoke-pi.lock.yml index 7e6c80bae9c..b07536ff7fc 100644 --- a/.github/workflows/smoke-pi.lock.yml +++ b/.github/workflows/smoke-pi.lock.yml @@ -551,18 +551,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/smoke-project.lock.yml b/.github/workflows/smoke-project.lock.yml index 3afcee04fc0..0ecb49f47f4 100644 --- a/.github/workflows/smoke-project.lock.yml +++ b/.github/workflows/smoke-project.lock.yml @@ -604,18 +604,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-pydantic.lock.yml b/.github/workflows/smoke-pydantic.lock.yml index ca8a9c5984c..e89c5b30292 100644 --- a/.github/workflows/smoke-pydantic.lock.yml +++ b/.github/workflows/smoke-pydantic.lock.yml @@ -524,12 +524,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -538,6 +532,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/smoke-service-ports.lock.yml b/.github/workflows/smoke-service-ports.lock.yml index d1e986bb4a8..9fb22f88db0 100644 --- a/.github/workflows/smoke-service-ports.lock.yml +++ b/.github/workflows/smoke-service-ports.lock.yml @@ -520,18 +520,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-temporary-id.lock.yml b/.github/workflows/smoke-temporary-id.lock.yml index cc6bb675b04..a0cf8dd43f5 100644 --- a/.github/workflows/smoke-temporary-id.lock.yml +++ b/.github/workflows/smoke-temporary-id.lock.yml @@ -565,18 +565,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-test-tools.lock.yml b/.github/workflows/smoke-test-tools.lock.yml index 1c655d571a1..e9c5a15b33f 100644 --- a/.github/workflows/smoke-test-tools.lock.yml +++ b/.github/workflows/smoke-test-tools.lock.yml @@ -527,18 +527,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup .NET uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0 with: diff --git a/.github/workflows/smoke-update-cross-repo-pr.lock.yml b/.github/workflows/smoke-update-cross-repo-pr.lock.yml index cd028fd4fb2..5a9007076f3 100644 --- a/.github/workflows/smoke-update-cross-repo-pr.lock.yml +++ b/.github/workflows/smoke-update-cross-repo-pr.lock.yml @@ -548,12 +548,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -588,6 +582,12 @@ jobs: const actionsDir = path.join(process.env.RUNNER_TEMP, 'gh-aw', 'actions'); const { main } = require(path.join(actionsDir, 'build_checkout_manifest.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml index bb8090ed8dd..ae04c0f306a 100644 --- a/.github/workflows/smoke-workflow-call-with-inputs.lock.yml +++ b/.github/workflows/smoke-workflow-call-with-inputs.lock.yml @@ -566,18 +566,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/smoke-workflow-call.lock.yml b/.github/workflows/smoke-workflow-call.lock.yml index 263e5e91151..a38f8085e6d 100644 --- a/.github/workflows/smoke-workflow-call.lock.yml +++ b/.github/workflows/smoke-workflow-call.lock.yml @@ -556,18 +556,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/spec-enforcer.lock.yml b/.github/workflows/spec-enforcer.lock.yml index e0ca3962128..6366f7ae48c 100644 --- a/.github/workflows/spec-enforcer.lock.yml +++ b/.github/workflows/spec-enforcer.lock.yml @@ -517,18 +517,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index e077b2821ce..e1b177761e9 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -503,18 +503,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 45c4d3b73fb..6e53f1b439b 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -481,18 +481,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/squad-game-planner.lock.yml b/.github/workflows/squad-game-planner.lock.yml index 935706ef0ba..7dfac88ae7c 100644 --- a/.github/workflows/squad-game-planner.lock.yml +++ b/.github/workflows/squad-game-planner.lock.yml @@ -498,12 +498,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -512,6 +506,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/squad-implement-worker.lock.yml b/.github/workflows/squad-implement-worker.lock.yml index 85bbddb2048..75cd35de2fe 100644 --- a/.github/workflows/squad-implement-worker.lock.yml +++ b/.github/workflows/squad-implement-worker.lock.yml @@ -536,12 +536,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -550,6 +544,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/squad-plan.lock.yml b/.github/workflows/squad-plan.lock.yml index 449a76bc12e..533b1b9206e 100644 --- a/.github/workflows/squad-plan.lock.yml +++ b/.github/workflows/squad-plan.lock.yml @@ -558,12 +558,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -572,6 +566,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/squad.lock.yml b/.github/workflows/squad.lock.yml index 19ef1a84c0e..ba2a3d3d43f 100644 --- a/.github/workflows/squad.lock.yml +++ b/.github/workflows/squad.lock.yml @@ -586,12 +586,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -600,6 +594,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/stale-pr-cleanup.lock.yml b/.github/workflows/stale-pr-cleanup.lock.yml index e30e0f4975c..d91b39e918e 100644 --- a/.github/workflows/stale-pr-cleanup.lock.yml +++ b/.github/workflows/stale-pr-cleanup.lock.yml @@ -460,18 +460,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index 31b77a4cd08..26e7c5f6411 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -491,18 +491,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/static-analysis-report.lock.yml b/.github/workflows/static-analysis-report.lock.yml index cd982c1b90d..c85c9cc782e 100644 --- a/.github/workflows/static-analysis-report.lock.yml +++ b/.github/workflows/static-analysis-report.lock.yml @@ -490,12 +490,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -532,6 +526,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Build and install gh-aw CLI from source run: | gh extension remove aw || true diff --git a/.github/workflows/step-name-alignment.lock.yml b/.github/workflows/step-name-alignment.lock.yml index c3ae80a4554..d3ecc4fceb5 100644 --- a/.github/workflows/step-name-alignment.lock.yml +++ b/.github/workflows/step-name-alignment.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/sub-issue-closer.lock.yml b/.github/workflows/sub-issue-closer.lock.yml index 2d5a2c6eead..0e430e5def9 100644 --- a/.github/workflows/sub-issue-closer.lock.yml +++ b/.github/workflows/sub-issue-closer.lock.yml @@ -449,18 +449,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/super-linter.lock.yml b/.github/workflows/super-linter.lock.yml index d25db02a881..4cdf8be604c 100644 --- a/.github/workflows/super-linter.lock.yml +++ b/.github/workflows/super-linter.lock.yml @@ -471,18 +471,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/technical-doc-writer.lock.yml b/.github/workflows/technical-doc-writer.lock.yml index 4c59fa4b21b..e351deda2ba 100644 --- a/.github/workflows/technical-doc-writer.lock.yml +++ b/.github/workflows/technical-doc-writer.lock.yml @@ -521,12 +521,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -546,6 +540,12 @@ jobs: setupGlobals(core, github, context, exec, io, getOctokit); const { main } = require(path.join(actionsDir, 'merge_remote_agent_github_folder.cjs')); await main(); + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index fb17d05ca1d..5d3a1799078 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -457,18 +457,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index f11ad7e4355..bc9197fa18f 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -580,18 +580,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/tidy.lock.yml b/.github/workflows/tidy.lock.yml index 09266a3f391..9e1cd01e815 100644 --- a/.github/workflows/tidy.lock.yml +++ b/.github/workflows/tidy.lock.yml @@ -548,18 +548,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index 59a8c2ab4ed..41219261f35 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -522,18 +522,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index f9201b9d07e..07bb641a941 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -500,18 +500,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index 0c006204ee4..03be60b37f7 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -480,18 +480,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index b26ae83229b..6f2ae2c4ec8 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -560,14 +560,14 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Mask OTLP telemetry headers + run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Mask OTLP telemetry headers - run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/update-astro.lock.yml b/.github/workflows/update-astro.lock.yml index 31aaa59f520..2150e10499d 100644 --- a/.github/workflows/update-astro.lock.yml +++ b/.github/workflows/update-astro.lock.yml @@ -511,18 +511,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Node.js uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 with: diff --git a/.github/workflows/video-analyzer.lock.yml b/.github/workflows/video-analyzer.lock.yml index 7ad7858765d..20b639f8d1b 100644 --- a/.github/workflows/video-analyzer.lock.yml +++ b/.github/workflows/video-analyzer.lock.yml @@ -454,18 +454,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/visual-regression-checker.lock.yml b/.github/workflows/visual-regression-checker.lock.yml index 2b93dd6a196..a3a7d31479d 100644 --- a/.github/workflows/visual-regression-checker.lock.yml +++ b/.github/workflows/visual-regression-checker.lock.yml @@ -489,14 +489,14 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" + - name: Mask OTLP telemetry headers + run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Mask OTLP telemetry headers - run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/weekly-blog-post-writer.lock.yml b/.github/workflows/weekly-blog-post-writer.lock.yml index a40b61e76f5..b2d150dd333 100644 --- a/.github/workflows/weekly-blog-post-writer.lock.yml +++ b/.github/workflows/weekly-blog-post-writer.lock.yml @@ -557,12 +557,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -599,6 +593,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/weekly-editors-health-check.lock.yml b/.github/workflows/weekly-editors-health-check.lock.yml index 0f6bbe8e0a1..f2dcb0170f3 100644 --- a/.github/workflows/weekly-editors-health-check.lock.yml +++ b/.github/workflows/weekly-editors-health-check.lock.yml @@ -491,18 +491,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index 103412d4988..b343b7dc234 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -470,18 +470,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Python uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 with: diff --git a/.github/workflows/weekly-network-domains-audit.lock.yml b/.github/workflows/weekly-network-domains-audit.lock.yml index 478dddaf14f..2ea43390ed6 100644 --- a/.github/workflows/weekly-network-domains-audit.lock.yml +++ b/.github/workflows/weekly-network-domains-audit.lock.yml @@ -450,12 +450,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -464,6 +458,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml index 1beff1f22f4..ed5d61fb95a 100644 --- a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml +++ b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml @@ -471,18 +471,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/windows-grower.lock.yml b/.github/workflows/windows-grower.lock.yml index d5caa9897b8..91fbc6ea29f 100644 --- a/.github/workflows/windows-grower.lock.yml +++ b/.github/workflows/windows-grower.lock.yml @@ -470,12 +470,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Check OTLP telemetry configuration @@ -484,6 +478,12 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/windows.lock.yml b/.github/workflows/windows.lock.yml index eae06a8c419..9b8c981aca1 100644 --- a/.github/workflows/windows.lock.yml +++ b/.github/workflows/windows.lock.yml @@ -576,13 +576,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - shell: bash - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers shell: bash run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" @@ -593,6 +586,13 @@ jobs: uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + shell: bash + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory shell: bash run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" diff --git a/.github/workflows/workflow-generator.lock.yml b/.github/workflows/workflow-generator.lock.yml index 97727939c77..097a92ce818 100644 --- a/.github/workflows/workflow-generator.lock.yml +++ b/.github/workflows/workflow-generator.lock.yml @@ -512,18 +512,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/workflow-health-manager.lock.yml b/.github/workflows/workflow-health-manager.lock.yml index fa9d322900d..45c3e6e0e11 100644 --- a/.github/workflows/workflow-health-manager.lock.yml +++ b/.github/workflows/workflow-health-manager.lock.yml @@ -482,18 +482,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/workflow-normalizer.lock.yml b/.github/workflows/workflow-normalizer.lock.yml index 9f5cf40fa9a..21e11696b67 100644 --- a/.github/workflows/workflow-normalizer.lock.yml +++ b/.github/workflows/workflow-normalizer.lock.yml @@ -476,12 +476,6 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository @@ -518,6 +512,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/.github/workflows/workflow-skill-extractor.lock.yml b/.github/workflows/workflow-skill-extractor.lock.yml index f8f2f964bcb..1dedb79dc7c 100644 --- a/.github/workflows/workflow-skill-extractor.lock.yml +++ b/.github/workflows/workflow-skill-extractor.lock.yml @@ -466,18 +466,18 @@ jobs: echo "GH_AW_SAFE_OUTPUTS_CONFIG_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" echo "GH_AW_SAFE_OUTPUTS_TOOLS_PATH=${RUNNER_TEMP}/gh-aw/safeoutputs/tools.json" } >> "$GITHUB_OUTPUT" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Mask OTLP telemetry headers run: bash "${RUNNER_TEMP}/gh-aw/actions/mask_otlp_headers.sh" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: persist-credentials: false + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/compiler_yaml_main_job.go b/pkg/workflow/compiler_yaml_main_job.go index 25ca7f968a0..a10eee2c399 100644 --- a/pkg/workflow/compiler_yaml_main_job.go +++ b/pkg/workflow/compiler_yaml_main_job.go @@ -9,10 +9,6 @@ import ( func (c *Compiler) generateMainJobSteps(yaml *strings.Builder, data *WorkflowData) error { compilerYamlLog.Printf("Generating main job steps for workflow: %s", data.Name) - for _, line := range generateComponentExecutionEvidenceStep("agent", "not_started", agentExecutionEvidencePath, "") { - yaml.WriteString(line) - } - // Phase 1: Initial setup, checkout, and repository imports checkoutMgr, needsCheckout, err := c.generateInitialAndCheckoutSteps(yaml, data) if err != nil { @@ -20,6 +16,10 @@ func (c *Compiler) generateMainJobSteps(yaml *strings.Builder, data *WorkflowDat } compilerYamlLog.Printf("Initial and checkout steps generated (needsCheckout=%v)", needsCheckout) + for _, line := range generateComponentExecutionEvidenceStep("agent", "not_started", agentExecutionEvidencePath, "") { + yaml.WriteString(line) + } + // Phase 2: Runtime detection, custom steps, and workspace setup customStepsContainCheckout := c.generateRuntimeAndWorkspaceSetupSteps(yaml, data, needsCheckout) needsGitConfig := needsCheckout || customStepsContainCheckout diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden index a2020b8d7e7..8d7f7f20133 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/claude.golden @@ -360,16 +360,16 @@ jobs: GH_AW_INFO_VERSION: "CLAUDE_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "claude" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden index 97568ea5875..f88a420cb1b 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/codex.golden @@ -361,16 +361,16 @@ jobs: GH_AW_INFO_VERSION: "CODEX_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "codex" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden index 20fd7f1b5e5..3c9996b3a83 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/copilot.golden @@ -360,16 +360,16 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden index 1ab7a7d1380..8e1a19e2d80 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/gemini.golden @@ -351,16 +351,16 @@ jobs: GH_AW_INFO_VERSION: "0.59.0" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "gemini" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden index 05e5e380b1e..6bb9ebc3bf4 100644 --- a/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden +++ b/pkg/workflow/testdata/TestWasmGolden_AllEngines/pi.golden @@ -350,16 +350,16 @@ jobs: GH_AW_INFO_VERSION: "PI_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "pi" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden index fd81b27dc9f..815d2d531c3 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/basic-copilot.golden @@ -360,16 +360,16 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden index fae0477dfbb..d3a5e35e980 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/playwright-cli-mode.golden @@ -360,16 +360,16 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden index 6a73b1b696c..8c6b4828775 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/smoke-copilot.golden @@ -402,12 +402,6 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" - - name: Initialize agent execution evidence - run: | - mkdir -p "/tmp/gh-aw" - evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" - printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" - mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: @@ -442,6 +436,12 @@ jobs: tags: localhost/gh-aw:dev build-args: | BINARY=dist/gh-aw-linux-amd64 + - name: Initialize agent execution evidence + run: | + mkdir -p "/tmp/gh-aw" + evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" + printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" + mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - name: Setup Go uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 with: diff --git a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden index 9ba52f1f7a5..b8771f929a6 100644 --- a/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden +++ b/pkg/workflow/testdata/TestWasmGolden_CompileFixtures/with-imports.golden @@ -361,16 +361,16 @@ jobs: GH_AW_INFO_VERSION: "COPILOT_VERSION" GH_AW_INFO_AWF_VERSION: "vAWF_VERSION" GH_AW_INFO_ENGINE_ID: "copilot" + - name: Checkout repository + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false - name: Initialize agent execution evidence run: | mkdir -p "/tmp/gh-aw" evidence_tmp="/tmp/gh-aw/agent_execution.json.tmp" printf '{"version":1,"component":"agent","run_id":%s,"run_attempt":%s,"state":"not_started"}\n' "$GITHUB_RUN_ID" "$GITHUB_RUN_ATTEMPT" > "$evidence_tmp" mv "$evidence_tmp" "/tmp/gh-aw/agent_execution.json" - - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - name: Create gh-aw temp directory run: bash "${RUNNER_TEMP}/gh-aw/actions/create_gh_aw_tmp_dir.sh" - name: Configure gh CLI for GitHub Enterprise