diff --git a/.github/workflows/bug-fix.lock.yml b/.github/workflows/bug-fix.lock.yml index 88b3dacfed..145939c481 100644 --- a/.github/workflows/bug-fix.lock.yml +++ b/.github/workflows/bug-fix.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"498fba21855a7dbfc826f2aaab47c5f25d8c38a996be6fd4047ccc2799f66bf8","body_hash":"f3f7f2fb75598f4970808325890cc7cc47e2283491c99a6df9ce5517cce8ecca","compiler_version":"v0.88.7","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.80"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"498fba21855a7dbfc826f2aaab47c5f25d8c38a996be6fd4047ccc2799f66bf8","body_hash":"83984289f2e7b0bcc14d7748fe1bda24e740add452706d25fb09d7cfafd2c35e","compiler_version":"v0.88.7","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.80"}} # gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_CI_TRIGGER_TOKEN","GH_AW_DEFAULT_OTLP_HEADERS","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"5e508589e03a7757a7e05b26e834292f5445bfb6","version":"v0.88.7"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.28.14","digest":"sha256:f7df036c86575527b61f3f7df91c4412349a12b2a74988d929eafa2999230c98","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.28.14@sha256:f7df036c86575527b61f3f7df91c4412349a12b2a74988d929eafa2999230c98"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.14","digest":"sha256:6f95e2234dd9bd6333a8ff28ccea7ecf0204acd4a09108723844dbd2bf6268c5","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.14@sha256:6f95e2234dd9bd6333a8ff28ccea7ecf0204acd4a09108723844dbd2bf6268c5"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.28.14","digest":"sha256:2ce8df3abf3e9b76e9c0cf5863da41f1ab3f89b20ad14b988806ab89e7bf2cd5","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.28.14@sha256:2ce8df3abf3e9b76e9c0cf5863da41f1ab3f89b20ad14b988806ab89e7bf2cd5"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.18","digest":"sha256:85b940556a8faa4e1fdbef124bfd75f2c4ebd855a10b88a1c3b6f3e97f6f1a53","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.18@sha256:85b940556a8faa4e1fdbef124bfd75f2c4ebd855a10b88a1c3b6f3e97f6f1a53"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:0daa8971fa4732b647150cb6524a6b0804b68d5d24f6f58b5dd1af23bd63fb23","pinned_image":"ghcr.io/github/gh-aw-node@sha256:0daa8971fa4732b647150cb6524a6b0804b68d5d24f6f58b5dd1af23bd63fb23"},{"image":"ghcr.io/github/github-mcp-server:v1.11.0","digest":"sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699","pinned_image":"ghcr.io/github/github-mcp-server:v1.11.0@sha256:fbec75de11c255213fa08d80fb166abe73d851fff631c51c0079872967720699"}],"mcp_servers":[{"name":"github","tools":["get_commit","get_file_contents","get_latest_release","get_release_by_tag","get_tag","issue_read","list_branches","list_commits","list_issue_types","list_issues","list_releases","list_starred_repositories","list_tags","search_code","search_issues","search_repositories"]},{"name":"safeoutputs","tools":["add_comment","add_labels","create_pull_request","missing_data","missing_tool","noop"]}]} # This file was automatically generated by gh-aw (v0.88.7). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/bug-fix.md b/.github/workflows/bug-fix.md index d73be52724..265d21ace5 100644 --- a/.github/workflows/bug-fix.md +++ b/.github/workflows/bug-fix.md @@ -206,6 +206,11 @@ are already present, `cargo test` when crates are already present), run the ## Step 6 — Open a Draft Pull Request +This repository-owned gh-aw maintenance workflow does not perform the contributor +open-PR count check or request confirmation. After completing the assessment-scoped +remediation and local checks above, emit the configured draft `create_pull_request` +safe output regardless of the submitter's or filing account's open PR count. + Use the `create-pull-request` safe output to open a **draft** PR with your changes. The harness handles branching, committing, and pushing from the working tree you edited — you do not run `git` yourself. diff --git a/tests/test_github_workflows.py b/tests/test_github_workflows.py index d97454b787..c84276c3b6 100644 --- a/tests/test_github_workflows.py +++ b/tests/test_github_workflows.py @@ -950,6 +950,20 @@ def test_bug_workflow_upgrade_preserves_runtime_and_negative_guards(name): } == expected_actions +def test_bug_fix_exempts_maintenance_from_pr_count_confirmation(): + source_text, compiled_text, _, _ = _agentic_workflow("bug-fix") + publication = source_text.split("## Step 6", 1)[1].split("## Step 7", 1)[0] + exemption = ( + "This repository-owned gh-aw maintenance workflow does not perform the " + "contributor open-PR count check or request confirmation. After completing " + "the assessment-scoped remediation and local checks above, emit the " + "configured draft `create_pull_request` safe output regardless of the " + "submitter's or filing account's open PR count." + ) + assert exemption in " ".join(publication.split()) + assert "{{#runtime-import .github/workflows/bug-fix.md}}" in compiled_text + + def test_bug_fix_upgrade_preserves_scoped_draft_pr_contract(): source_text, _, source, compiled = _agentic_workflow("bug-fix") create_pr = _safe_output_config(compiled)["create_pull_request"] @@ -996,6 +1010,10 @@ def test_bug_fix_upgrade_preserves_scoped_draft_pr_contract(): "**Stay within the files the assessment named**", "record it explicitly in the PR body under **Deviations from Assessment**", "Use the `create-pull-request` safe output to open a **draft** PR", + ( + "The harness handles branching, committing, and pushing from the " + "working tree you edited — you do not run `git` yourself." + ), "Use `Refs` (not `Closes`)", "Add **exactly one** status label per run when the label exists", ):