diff --git a/.github/workflows/issue-clarify.lock.yml b/.github/workflows/issue-go-clarify.lock.yml similarity index 97% rename from .github/workflows/issue-clarify.lock.yml rename to .github/workflows/issue-go-clarify.lock.yml index 88b8063c..d980227b 100644 --- a/.github/workflows/issue-clarify.lock.yml +++ b/.github/workflows/issue-go-clarify.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"9d0b2133c80e50579d02c3c6de29c15526822f5bd5eb0894bed614bd2d14700a","body_hash":"e0bda517a121787eedd565136e0527cfdb092404f4a9ad76fbf2c38ef2a5378a","compiler_version":"v0.81.6","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.65"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"2d4bfb2a89483076e06f94eb9df8ed8c34e1ff45b3da94c7caeb6440d4ce4bdc","body_hash":"e0bda517a121787eedd565136e0527cfdb092404f4a9ad76fbf2c38ef2a5378a","compiler_version":"v0.81.6","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.65"}} # gh-aw-manifest: {"version":1,"secrets":["GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/cache/save","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/github-script","sha":"ed597411d8f924073f98dfc5c65a23a2325f34cd","version":"v8"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"ba6380cc6e5be5d21677bebe04d52fb48e3abec7","version":"v0.81.6"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11","digest":"sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11@sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11","digest":"sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11@sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11","digest":"sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11@sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.30","digest":"sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.30@sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.4.0","digest":"sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036","pinned_image":"ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"}]} # This file was automatically generated by gh-aw (v0.81.6). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # @@ -50,7 +50,7 @@ # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036 -name: "Issue Clarification Agent" +name: "Issue Go: Clarify" on: issues: # names: # Label filtering applied via job conditions @@ -66,7 +66,7 @@ permissions: {} concurrency: group: "gh-aw-${{ github.workflow }}-${{ github.event.issue.number || github.run_id }}" -run-name: "Issue Clarification Agent" +run-name: "Issue Go: Clarify" jobs: activation: @@ -108,8 +108,8 @@ jobs: parent-span-id: ${{ needs.pre_activation.outputs.setup-parent-span-id || needs.pre_activation.outputs.setup-span-id }} safe-output-artifact-client: ${{ env.GH_AW_MAX_DAILY_AI_CREDITS != '' }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -122,7 +122,7 @@ jobs: GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AGENT_VERSION: "1.0.65" GH_AW_INFO_CLI_VERSION: "v0.81.6" - GH_AW_INFO_WORKFLOW_NAME: "Issue Clarification Agent" + GH_AW_INFO_WORKFLOW_NAME: "Issue Go: Clarify" GH_AW_INFO_EXPERIMENTAL: "false" GH_AW_INFO_SUPPORTS_TOOLS_ALLOWLIST: "true" GH_AW_INFO_STAGED: "false" @@ -145,8 +145,8 @@ jobs: continue-on-error: true uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueclarify-${{ github.run_id }} - restore-keys: agentic-workflow-usage-issueclarify- + key: agentic-workflow-usage-issuegoclarify-${{ github.run_id }} + restore-keys: agentic-workflow-usage-issuegoclarify- path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Restore daily AIC usage cache (artifact fallback) id: restore-daily-aic-cache-fallback @@ -168,8 +168,8 @@ jobs: if: ${{ env.GH_AW_MAX_DAILY_AI_CREDITS != '' }} uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_ID: "issue-clarify" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_ID: "issue-go-clarify" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_WORKFLOW_DISPATCH_AW_CONTEXT: ${{ github.event.inputs.aw_context || '' }} GH_AW_HAS_SLASH_COMMAND: "false" @@ -209,7 +209,7 @@ jobs: id: check-lock-file uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - GH_AW_WORKFLOW_FILE: "issue-clarify.lock.yml" + GH_AW_WORKFLOW_FILE: "issue-go-clarify.lock.yml" GH_AW_CONTEXT_WORKFLOW_REF: "${{ github.workflow_ref }}" with: script: | @@ -257,20 +257,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_83120a125fdba03a_EOF' + cat << 'GH_AW_PROMPT_01bd8eba433163e9_EOF' - GH_AW_PROMPT_83120a125fdba03a_EOF + GH_AW_PROMPT_01bd8eba433163e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_83120a125fdba03a_EOF' + cat << 'GH_AW_PROMPT_01bd8eba433163e9_EOF' Tools: add_comment, missing_tool, missing_data, noop - GH_AW_PROMPT_83120a125fdba03a_EOF + GH_AW_PROMPT_01bd8eba433163e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_83120a125fdba03a_EOF' + cat << 'GH_AW_PROMPT_01bd8eba433163e9_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -299,12 +299,12 @@ jobs: {{/if}} - GH_AW_PROMPT_83120a125fdba03a_EOF + GH_AW_PROMPT_01bd8eba433163e9_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_83120a125fdba03a_EOF' + cat << 'GH_AW_PROMPT_01bd8eba433163e9_EOF' - {{#runtime-import .github/workflows/issue-clarify.md}} - GH_AW_PROMPT_83120a125fdba03a_EOF + {{#runtime-import .github/workflows/issue-go-clarify.md}} + GH_AW_PROMPT_01bd8eba433163e9_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -398,7 +398,7 @@ jobs: GH_AW_ASSETS_MAX_SIZE_KB: 0 GH_AW_MCP_LOG_DIR: /tmp/gh-aw/mcp-logs/safeoutputs GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} - GH_AW_WORKFLOW_ID_SANITIZED: issueclarify + GH_AW_WORKFLOW_ID_SANITIZED: issuegoclarify outputs: agentic_engine_timeout: ${{ steps.detect-agent-errors.outputs.agentic_engine_timeout || 'false' }} ai_credits_rate_limit_error: ${{ steps.parse-mcp-gateway.outputs.ai_credits_rate_limit_error || 'false' }} @@ -427,8 +427,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -999,7 +999,7 @@ jobs: issues: write pull-requests: write concurrency: - group: "gh-aw-conclusion-issue-clarify" + group: "gh-aw-conclusion-issue-go-clarify" cancel-in-progress: false queue: max env: @@ -1019,8 +1019,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1087,8 +1087,8 @@ jobs: continue-on-error: true uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueclarify-${{ github.run_id }} - restore-keys: agentic-workflow-usage-issueclarify- + key: agentic-workflow-usage-issuegoclarify-${{ github.run_id }} + restore-keys: agentic-workflow-usage-issuegoclarify- path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Write daily AIC usage cache entry id: write-daily-aic-cache @@ -1108,7 +1108,7 @@ jobs: continue-on-error: true uses: actions/cache/save@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueclarify-${{ github.run_id }} + key: agentic-workflow-usage-issuegoclarify-${{ github.run_id }} path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Upload daily AIC usage cache artifact id: upload-daily-aic-cache @@ -1126,15 +1126,15 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" GH_AW_AIC: ${{ needs.agent.outputs.aic }} GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} - GH_AW_WORKFLOW_ID: "issue-clarify" + GH_AW_WORKFLOW_ID: "issue-go-clarify" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1147,8 +1147,8 @@ jobs: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1165,8 +1165,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1180,8 +1180,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1195,11 +1195,11 @@ jobs: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} - GH_AW_WORKFLOW_ID: "issue-clarify" + GH_AW_WORKFLOW_ID: "issue-go-clarify" GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "168" GH_AW_ENGINE_ID: "copilot" GH_AW_CHECKOUT_PR_SUCCESS: ${{ needs.agent.outputs.checkout_pr_success }} @@ -1258,8 +1258,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1331,7 +1331,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - WORKFLOW_NAME: "Issue Clarification Agent" + WORKFLOW_NAME: "Issue Go: Clarify" WORKFLOW_DESCRIPTION: "When a maintainer marks an issue go:needs-research, help scope it by asking focused clarifying questions — but only if the maintainer has not already asked them. If the maintainer has posted clarifying questions, sharpen or de-ambiguate those instead. Posts at most one comment." HAS_PATCH: ${{ needs.agent.outputs.has_patch }} with: @@ -1499,8 +1499,8 @@ jobs: destination: ${{ runner.temp }}/gh-aw/actions job-name: ${{ github.job }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1533,7 +1533,7 @@ jobs: GH_AW_AGENT_AIC: ${{ needs.agent.outputs.aic }} GH_AW_AIC: ${{ needs.agent.outputs.aic }} GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} - GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/issue-clarify" + GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/issue-go-clarify" GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} GH_AW_EFFECTIVE_TOKENS: ${{ needs.agent.outputs.effective_tokens }} @@ -1542,9 +1542,9 @@ jobs: GH_AW_ENGINE_VERSION: "1.0.65" GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} - GH_AW_WORKFLOW_ID: "issue-clarify" - GH_AW_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-clarify.md" + GH_AW_WORKFLOW_ID: "issue-go-clarify" + GH_AW_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-clarify.md" outputs: code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }} @@ -1564,8 +1564,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Clarification Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-clarify.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Clarify" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-clarify.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" diff --git a/.github/workflows/issue-clarify.md b/.github/workflows/issue-go-clarify.md similarity index 99% rename from .github/workflows/issue-clarify.md rename to .github/workflows/issue-go-clarify.md index ca1ef4ea..1a3693bf 100644 --- a/.github/workflows/issue-clarify.md +++ b/.github/workflows/issue-go-clarify.md @@ -1,4 +1,5 @@ --- +name: "Issue Go: Clarify" description: > When a maintainer marks an issue go:needs-research, help scope it by asking focused clarifying questions — but only if the maintainer has not already asked them. If the diff --git a/.github/workflows/issue-nogo.yml b/.github/workflows/issue-go-no.yml similarity index 99% rename from .github/workflows/issue-nogo.yml rename to .github/workflows/issue-go-no.yml index 724a2213..233c1f13 100644 --- a/.github/workflows/issue-nogo.yml +++ b/.github/workflows/issue-go-no.yml @@ -1,4 +1,4 @@ -name: Issue No-Go +name: "Issue Go: No" # Deterministic Workflow: No-Go decision # Trigger: a maintainer applies the "go:no" label to reject an issue. diff --git a/.github/workflows/issue-assign.lock.yml b/.github/workflows/issue-go-yes.lock.yml similarity index 91% rename from .github/workflows/issue-assign.lock.yml rename to .github/workflows/issue-go-yes.lock.yml index 3cdc5c0c..dbf2dc9a 100644 --- a/.github/workflows/issue-assign.lock.yml +++ b/.github/workflows/issue-go-yes.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"60ddfea64f983982e7da70bac227d0bb086de48fd814a6cd6556a22bb6322c84","body_hash":"dab8fe99999fed7d1ef283d6f6a0046aa81ebdda3b72e54fe2b83705f3922bd9","compiler_version":"v0.81.6","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.65"}} -# gh-aw-manifest: {"version":1,"secrets":["GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/cache/save","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/checkout","sha":"df4cb1c069e1874edd31b4311f1884172cec0e10","version":"v6.0.3 (source v6)"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/github-script","sha":"ed597411d8f924073f98dfc5c65a23a2325f34cd","version":"v8"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"ba6380cc6e5be5d21677bebe04d52fb48e3abec7","version":"v0.81.6"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11","digest":"sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11@sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11","digest":"sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11@sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11","digest":"sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11@sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.30","digest":"sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.30@sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.4.0","digest":"sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036","pinned_image":"ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"}]} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"46dc7cb473f668f59ea39afb12a3f7705d4c316dc2cf17559c4a99b8b05b3c29","body_hash":"5319da7c859b78cf1c300425552ac0636ff93a6cbe82bcfa2e3814c797f18177","compiler_version":"v0.81.6","strict":true,"agent_id":"copilot","engine_versions":{"copilot":"1.0.65"}} +# gh-aw-manifest: {"version":1,"secrets":["COPILOT_ASSIGN_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/cache/restore","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/cache/save","sha":"27d5ce7f107fe9357f9df03efb73ab90386fccae","version":"v5.0.5"},{"repo":"actions/checkout","sha":"9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0","version":"v7.0.0"},{"repo":"actions/checkout","sha":"df4cb1c069e1874edd31b4311f1884172cec0e10","version":"v6.0.3 (source v6)"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/github-script","sha":"ed597411d8f924073f98dfc5c65a23a2325f34cd","version":"v8"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"ba6380cc6e5be5d21677bebe04d52fb48e3abec7","version":"v0.81.6"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11","digest":"sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.11@sha256:979723c628182da7729333f2208bb249fd25ddee579645cf9a3892d681a929c7"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11","digest":"sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.11@sha256:807e4831999b44513b0a66e5859d478dc4da7ae74ab1918cec967d513f95bf9d"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11","digest":"sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.11@sha256:ff27ea0525ad953a6adee28a5fbe9d2e22be47dbec755c15767af4ea3f91df7d"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.30","digest":"sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.3.30@sha256:35625d1a2269b1238606078c879f59a91cffc4ac33eb54bf39c6418822c1a8be"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b","pinned_image":"ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b"},{"image":"ghcr.io/github/github-mcp-server:v1.4.0","digest":"sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036","pinned_image":"ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036"}]} # This file was automatically generated by gh-aw (v0.81.6). DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ @@ -23,9 +23,10 @@ # # For more information: https://github.github.com/gh-aw/introduction/overview/ # -# Assign an approved issue (go:yes) to the maintainer who approved it and route it to squad areas. Reads the prior triage analysis and the squad routing table, applies the squad label plus matched squad:{member} labels (and squad:copilot to hand the issue off to the Copilot coding agent), and posts an assignment rationale comment. +# Assign an approved issue (go:yes) to the maintainer who approved it and route it to squad areas. Reads the prior triage analysis and the squad routing table, applies the squad label plus matched squad:{member} labels (and squad:copilot to hand the issue off to the Copilot coding agent), and posts an assignment rationale comment that, when auto-assign is not configured (no COPILOT_ASSIGN_TOKEN), also nudges the assignee to assign the Copilot coding agent so work can begin. # # Secrets used: +# - COPILOT_ASSIGN_TOKEN # - GH_AW_GITHUB_MCP_SERVER_TOKEN # - GH_AW_GITHUB_TOKEN # - GITHUB_TOKEN @@ -51,7 +52,7 @@ # - ghcr.io/github/gh-aw-node@sha256:529d02eb970b1161aa25c593a9c3df57fdfad5a8add328cb3b6eccef66f3183b # - ghcr.io/github/github-mcp-server:v1.4.0@sha256:2afb26356481d1a350e14544a6e160f7f7ec1561a1ea309b823665abf0309036 -name: "Issue Assignment Agent" +name: "Issue Go: Yes" on: issues: # names: # Label filtering applied via job conditions @@ -67,7 +68,7 @@ permissions: {} concurrency: group: "gh-aw-${{ github.workflow }}-${{ github.event.issue.number || github.run_id }}" -run-name: "Issue Assignment Agent" +run-name: "Issue Go: Yes" jobs: activation: @@ -109,8 +110,8 @@ jobs: parent-span-id: ${{ needs.pre_activation.outputs.setup-parent-span-id || needs.pre_activation.outputs.setup-span-id }} safe-output-artifact-client: ${{ env.GH_AW_MAX_DAILY_AI_CREDITS != '' }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -123,7 +124,7 @@ jobs: GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AGENT_VERSION: "1.0.65" GH_AW_INFO_CLI_VERSION: "v0.81.6" - GH_AW_INFO_WORKFLOW_NAME: "Issue Assignment Agent" + GH_AW_INFO_WORKFLOW_NAME: "Issue Go: Yes" GH_AW_INFO_EXPERIMENTAL: "false" GH_AW_INFO_SUPPORTS_TOOLS_ALLOWLIST: "true" GH_AW_INFO_STAGED: "false" @@ -146,8 +147,8 @@ jobs: continue-on-error: true uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueassign-${{ github.run_id }} - restore-keys: agentic-workflow-usage-issueassign- + key: agentic-workflow-usage-issuegoyes-${{ github.run_id }} + restore-keys: agentic-workflow-usage-issuegoyes- path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Restore daily AIC usage cache (artifact fallback) id: restore-daily-aic-cache-fallback @@ -169,8 +170,8 @@ jobs: if: ${{ env.GH_AW_MAX_DAILY_AI_CREDITS != '' }} uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_ID: "issue-assign" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_ID: "issue-go-yes" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_WORKFLOW_DISPATCH_AW_CONTEXT: ${{ github.event.inputs.aw_context || '' }} GH_AW_HAS_SLASH_COMMAND: "false" @@ -210,7 +211,7 @@ jobs: id: check-lock-file uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - GH_AW_WORKFLOW_FILE: "issue-assign.lock.yml" + GH_AW_WORKFLOW_FILE: "issue-go-yes.lock.yml" GH_AW_CONTEXT_WORKFLOW_REF: "${{ github.workflow_ref }}" with: script: | @@ -258,20 +259,20 @@ jobs: run: | bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh" { - cat << 'GH_AW_PROMPT_c55537d93244191d_EOF' + cat << 'GH_AW_PROMPT_793180f3809d79e2_EOF' - GH_AW_PROMPT_c55537d93244191d_EOF + GH_AW_PROMPT_793180f3809d79e2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md" cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md" cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md" cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md" - cat << 'GH_AW_PROMPT_c55537d93244191d_EOF' + cat << 'GH_AW_PROMPT_793180f3809d79e2_EOF' Tools: add_comment, add_labels(max:5), assign_to_user, missing_tool, missing_data, noop - GH_AW_PROMPT_c55537d93244191d_EOF + GH_AW_PROMPT_793180f3809d79e2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md" - cat << 'GH_AW_PROMPT_c55537d93244191d_EOF' + cat << 'GH_AW_PROMPT_793180f3809d79e2_EOF' The following GitHub context information is available for this workflow: {{#if github.actor}} @@ -300,12 +301,12 @@ jobs: {{/if}} - GH_AW_PROMPT_c55537d93244191d_EOF + GH_AW_PROMPT_793180f3809d79e2_EOF cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md" - cat << 'GH_AW_PROMPT_c55537d93244191d_EOF' + cat << 'GH_AW_PROMPT_793180f3809d79e2_EOF' - {{#runtime-import .github/workflows/issue-assign.md}} - GH_AW_PROMPT_c55537d93244191d_EOF + {{#runtime-import .github/workflows/issue-go-yes.md}} + GH_AW_PROMPT_793180f3809d79e2_EOF } > "$GH_AW_PROMPT" - name: Interpolate variables and render templates uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 @@ -399,7 +400,7 @@ jobs: GH_AW_ASSETS_MAX_SIZE_KB: 0 GH_AW_MCP_LOG_DIR: /tmp/gh-aw/mcp-logs/safeoutputs GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} - GH_AW_WORKFLOW_ID_SANITIZED: issueassign + GH_AW_WORKFLOW_ID_SANITIZED: issuegoyes outputs: agentic_engine_timeout: ${{ steps.detect-agent-errors.outputs.agentic_engine_timeout || 'false' }} ai_credits_rate_limit_error: ${{ steps.parse-mcp-gateway.outputs.ai_credits_rate_limit_error || 'false' }} @@ -428,8 +429,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -454,13 +455,14 @@ jobs: - env: GH_TOKEN: ${{ github.token }} GO_YES_SENDER: ${{ github.event.sender.login }} + HAS_ASSIGN_TOKEN: ${{ secrets.COPILOT_ASSIGN_TOKEN != '' }} ISSUE_AUTHOR: ${{ github.event.issue.user.login }} ISSUE_BODY: ${{ github.event.issue.body || '' }} ISSUE_NUMBER: ${{ github.event.issue.number }} ISSUE_TITLE: ${{ github.event.issue.title }} id: context name: Prepare assignment context - run: "mkdir -p /tmp/gh-aw/agent\n\n# ---------------------------------------------------------------------\n# USER context (untrusted): the issue itself + the prior triage comment.\n# ---------------------------------------------------------------------\nUSER_FILE=\"/tmp/gh-aw/agent/issue-content.md\"\n{\n printf '%s\\n' '---' 'context-role: user' '---' '# Issue Approved for Work (go:yes)' ''\n printf '**Title:** %s\\n' \"$ISSUE_TITLE\"\n printf '**Number:** #%s\\n' \"$ISSUE_NUMBER\"\n printf '**Author:** @%s\\n' \"$ISSUE_AUTHOR\"\n printf '\\n## Body\\n\\n'\n printf '%s\\n' \"$ISSUE_BODY\"\n printf '\\n## Prior Triage Analysis\\n\\n'\n} > \"$USER_FILE\"\n\n# Append the most recent triage recommendation comment, if one exists.\nTRIAGE=$(gh issue view \"$ISSUE_NUMBER\" --repo \"$GITHUB_REPOSITORY\" --json comments \\\n --jq '[.comments[] | select(.body | test(\"Triage Recommendation|Squad Triage\"))] | last | .body' 2>/dev/null || printf '')\nif [ -n \"$TRIAGE\" ] && [ \"$TRIAGE\" != \"null\" ]; then\n printf '%s\\n' \"$TRIAGE\" >> \"$USER_FILE\"\nelse\n printf '%s\\n' '_No prior triage analysis comment found — route from the issue content alone._' >> \"$USER_FILE\"\nfi\n\n# ---------------------------------------------------------------------\n# SYSTEM context (trusted): assignment policy + routing/team tables.\n# Single-quoted printf args keep backticks/`$` literal (no expansion).\n# ---------------------------------------------------------------------\nSYS_FILE=\"/tmp/gh-aw/agent/system-policy.md\"\n{\n printf '%s\\n' '---' 'context-role: system' '---'\n printf '%s\\n\\n' '# Issue Assignment Policy'\n printf '%s\\n\\n' '## Assignment (deterministic — do not deviate)'\n printf -- '- The maintainer who applied the `go:yes` label is **@%s**.\\n' \"$GO_YES_SENDER\"\n printf -- '- Assign this issue to **@%s** with the `assign_to_user` tool. Assign no one else.\\n' \"$GO_YES_SENDER\"\n printf '%s\\n' '- Always apply the `squad` label to mark the issue as squad-routed.'\n printf '%s\\n' '- Apply one `squad:{member}` label for every squad area the issue touches, per the routing table below.'\n printf '%s\\n' '- Apply the `squad:copilot` label to hand the issue off to the Copilot coding agent to begin implementation.'\n printf '%s\\n' '- Never apply `go:*`, `priority:*`, `override:*`, or `type:*` labels.'\n printf '\\n'\n} > \"$SYS_FILE\"\n\nappend_md() {\n if [ -f \"$2\" ]; then\n printf '\\n## %s\\n\\n' \"$1\" >> \"$SYS_FILE\"\n cat \"$2\" >> \"$SYS_FILE\"\n printf '\\n' >> \"$SYS_FILE\"\n fi\n}\nappend_json() {\n if [ -f \"$2\" ]; then\n printf '\\n## %s\\n\\n```json\\n' \"$1\" >> \"$SYS_FILE\"\n cat \"$2\" >> \"$SYS_FILE\"\n printf '\\n```\\n' >> \"$SYS_FILE\"\n fi\n}\nappend_md \"Routing Policy (routing.md)\" \".squad/routing.md\"\nappend_md \"Team Roster (team.md)\" \".squad/team.md\"\nappend_json \"Routing Table (routing-table.json)\" \".squad/routing-table.json\"\nappend_json \"Issue Routing (issue-routing.json)\" \".squad/issue-routing.json\"\n\necho \"context_user_file=issue-content.md\" >> \"$GITHUB_OUTPUT\"\necho \"context_system_file=system-policy.md\" >> \"$GITHUB_OUTPUT\"\n" + run: "mkdir -p /tmp/gh-aw/agent\n\n# ---------------------------------------------------------------------\n# USER context (untrusted): the issue itself + the prior triage comment.\n# ---------------------------------------------------------------------\nUSER_FILE=\"/tmp/gh-aw/agent/issue-content.md\"\n{\n printf '%s\\n' '---' 'context-role: user' '---' '# Issue Approved for Work (go:yes)' ''\n printf '**Title:** %s\\n' \"$ISSUE_TITLE\"\n printf '**Number:** #%s\\n' \"$ISSUE_NUMBER\"\n printf '**Author:** @%s\\n' \"$ISSUE_AUTHOR\"\n printf '\\n## Body\\n\\n'\n printf '%s\\n' \"$ISSUE_BODY\"\n printf '\\n## Prior Triage Analysis\\n\\n'\n} > \"$USER_FILE\"\n\n# Append the most recent triage recommendation comment, if one exists.\nTRIAGE=$(gh issue view \"$ISSUE_NUMBER\" --repo \"$GITHUB_REPOSITORY\" --json comments \\\n --jq '[.comments[] | select(.body | test(\"Triage Recommendation|Squad Triage\"))] | last | .body' 2>/dev/null || printf '')\nif [ -n \"$TRIAGE\" ] && [ \"$TRIAGE\" != \"null\" ]; then\n printf '%s\\n' \"$TRIAGE\" >> \"$USER_FILE\"\nelse\n printf '%s\\n' '_No prior triage analysis comment found — route from the issue content alone._' >> \"$USER_FILE\"\nfi\n\n# ---------------------------------------------------------------------\n# Copilot coding-agent hand-off status (deterministic, trusted context).\n# NUDGE_NEEDED is true only when auto-assign is unavailable AND the coding\n# agent is not already an assignee — so the agent should nudge the human.\n# ---------------------------------------------------------------------\nCURRENT_ASSIGNEES=$(gh issue view \"$ISSUE_NUMBER\" --repo \"$GITHUB_REPOSITORY\" --json assignees \\\n --jq '[.assignees[].login] | join(\",\")' 2>/dev/null | tr 'A-Z' 'a-z' || printf '')\nAGENT_ALREADY_ASSIGNED=false\nif printf ',%s,' \"$CURRENT_ASSIGNEES\" | grep -qE ',(copilot-swe-agent\\[bot\\]|copilot-swe-agent|copilot),'; then\n AGENT_ALREADY_ASSIGNED=true\nfi\nNUDGE_NEEDED=false\nif [ \"${HAS_ASSIGN_TOKEN:-false}\" != \"true\" ] && [ \"$AGENT_ALREADY_ASSIGNED\" != \"true\" ]; then\n NUDGE_NEEDED=true\nfi\n\n# ---------------------------------------------------------------------\n# SYSTEM context (trusted): assignment policy + routing/team tables.\n# Single-quoted printf args keep backticks/`$` literal (no expansion).\n# ---------------------------------------------------------------------\nSYS_FILE=\"/tmp/gh-aw/agent/system-policy.md\"\n{\n printf '%s\\n' '---' 'context-role: system' '---'\n printf '%s\\n\\n' '# Issue Assignment Policy'\n printf '%s\\n\\n' '## Assignment (deterministic — do not deviate)'\n printf -- '- The maintainer who applied the `go:yes` label is **@%s**.\\n' \"$GO_YES_SENDER\"\n printf -- '- Assign this issue to **@%s** with the `assign_to_user` tool. Assign no one else.\\n' \"$GO_YES_SENDER\"\n printf '%s\\n' '- Always apply the `squad` label to mark the issue as squad-routed.'\n printf '%s\\n' '- Apply one `squad:{member}` label for every squad area the issue touches, per the routing table below.'\n printf '%s\\n' '- Apply the `squad:copilot` label to hand the issue off to the Copilot coding agent to begin implementation.'\n printf '%s\\n' '- Never apply `go:*`, `priority:*`, `override:*`, or `type:*` labels.'\n if [ \"$NUDGE_NEEDED\" = \"true\" ]; then\n printf -- '- **Copilot hand-off nudge REQUIRED:** no coding agent is assigned to this issue yet. In your single assignment comment, add an `### 🤖 Action needed` section that @-mentions **@%s** and tells them to assign this issue to Copilot from the Assignees menu so implementation can begin. Do NOT mention COPILOT_ASSIGN_TOKEN, repository secrets, `.squad/team.md`, or any workflow internals in the comment.\\n' \"$GO_YES_SENDER\"\n else\n printf '%s\\n' '- **Copilot hand-off nudge:** NOT required — do not add any Copilot-assignment nudge to the comment (auto-assign is configured or the coding agent is already assigned).'\n fi\n printf '\\n'\n} > \"$SYS_FILE\"\n\nappend_md() {\n if [ -f \"$2\" ]; then\n printf '\\n## %s\\n\\n' \"$1\" >> \"$SYS_FILE\"\n cat \"$2\" >> \"$SYS_FILE\"\n printf '\\n' >> \"$SYS_FILE\"\n fi\n}\nappend_json() {\n if [ -f \"$2\" ]; then\n printf '\\n## %s\\n\\n```json\\n' \"$1\" >> \"$SYS_FILE\"\n cat \"$2\" >> \"$SYS_FILE\"\n printf '\\n```\\n' >> \"$SYS_FILE\"\n fi\n}\nappend_md \"Routing Policy (routing.md)\" \".squad/routing.md\"\nappend_md \"Team Roster (team.md)\" \".squad/team.md\"\nappend_json \"Routing Table (routing-table.json)\" \".squad/routing-table.json\"\nappend_json \"Issue Routing (issue-routing.json)\" \".squad/issue-routing.json\"\n\necho \"context_user_file=issue-content.md\" >> \"$GITHUB_OUTPUT\"\necho \"context_system_file=system-policy.md\" >> \"$GITHUB_OUTPUT\"\n" - name: Contract test — verify context separation run: "USER_FILE=\"/tmp/gh-aw/agent/issue-content.md\"\nSYSTEM_FILE=\"/tmp/gh-aw/agent/system-policy.md\"\n\nif ! head -n 5 \"$USER_FILE\" | grep -qx \"context-role: user\"; then\n echo \"::error::Contract violation: user context file has an unexpected role marker\"\n exit 1\nfi\nif ! head -n 5 \"$SYSTEM_FILE\" | grep -qx \"context-role: system\"; then\n echo \"::error::Contract violation: system context file has an unexpected role marker\"\n exit 1\nfi\n# Untrusted issue markers must NOT bleed into the trusted system context.\nif grep -q \"context-role: user\" \"$SYSTEM_FILE\" || grep -q \"^# Issue Approved for Work\" \"$SYSTEM_FILE\"; then\n echo \"::error::Contract violation: user context leaked into system context\"\n exit 1\nfi\necho \"✅ Context separation contract verified\"\n" @@ -908,7 +910,8 @@ jobs: const { main } = require('${{ runner.temp }}/gh-aw/actions/redact_secrets.cjs'); await main(); env: - GH_AW_SECRET_NAMES: 'GH_AW_GITHUB_MCP_SERVER_TOKEN,GH_AW_GITHUB_TOKEN,GITHUB_TOKEN' + GH_AW_SECRET_NAMES: 'COPILOT_ASSIGN_TOKEN,GH_AW_GITHUB_MCP_SERVER_TOKEN,GH_AW_GITHUB_TOKEN,GITHUB_TOKEN' + SECRET_COPILOT_ASSIGN_TOKEN: ${{ secrets.COPILOT_ASSIGN_TOKEN }} SECRET_GH_AW_GITHUB_MCP_SERVER_TOKEN: ${{ secrets.GH_AW_GITHUB_MCP_SERVER_TOKEN }} SECRET_GH_AW_GITHUB_TOKEN: ${{ secrets.GH_AW_GITHUB_TOKEN }} SECRET_GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -1041,7 +1044,7 @@ jobs: issues: write pull-requests: write concurrency: - group: "gh-aw-conclusion-issue-assign" + group: "gh-aw-conclusion-issue-go-yes" cancel-in-progress: false queue: max env: @@ -1061,8 +1064,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1129,8 +1132,8 @@ jobs: continue-on-error: true uses: actions/cache/restore@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueassign-${{ github.run_id }} - restore-keys: agentic-workflow-usage-issueassign- + key: agentic-workflow-usage-issuegoyes-${{ github.run_id }} + restore-keys: agentic-workflow-usage-issuegoyes- path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Write daily AIC usage cache entry id: write-daily-aic-cache @@ -1150,7 +1153,7 @@ jobs: continue-on-error: true uses: actions/cache/save@27d5ce7f107fe9357f9df03efb73ab90386fccae # v5.0.5 with: - key: agentic-workflow-usage-issueassign-${{ github.run_id }} + key: agentic-workflow-usage-issuegoyes-${{ github.run_id }} path: /tmp/gh-aw/agentic-workflow-usage-cache.jsonl - name: Upload daily AIC usage cache artifact id: upload-daily-aic-cache @@ -1168,15 +1171,15 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_NOOP_MAX: "1" - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} GH_AW_NOOP_REPORT_AS_ISSUE: "true" GH_AW_AIC: ${{ needs.agent.outputs.aic }} GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} - GH_AW_WORKFLOW_ID: "issue-assign" + GH_AW_WORKFLOW_ID: "issue-go-yes" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1189,8 +1192,8 @@ jobs: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} @@ -1207,8 +1210,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_MISSING_TOOL_CREATE_ISSUE: "true" - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1222,8 +1225,8 @@ jobs: env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true" - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" with: github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }} script: | @@ -1237,11 +1240,11 @@ jobs: uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }} - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }} GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }} - GH_AW_WORKFLOW_ID: "issue-assign" + GH_AW_WORKFLOW_ID: "issue-go-yes" GH_AW_ACTION_FAILURE_ISSUE_EXPIRES_HOURS: "168" GH_AW_ENGINE_ID: "copilot" GH_AW_CHECKOUT_PR_SUCCESS: ${{ needs.agent.outputs.checkout_pr_success }} @@ -1300,8 +1303,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1373,8 +1376,8 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0 env: - WORKFLOW_NAME: "Issue Assignment Agent" - WORKFLOW_DESCRIPTION: "Assign an approved issue (go:yes) to the maintainer who approved it and route it to squad areas. Reads the prior triage analysis and the squad routing table, applies the squad label plus matched squad:{member} labels (and squad:copilot to hand the issue off to the Copilot coding agent), and posts an assignment rationale comment." + WORKFLOW_NAME: "Issue Go: Yes" + WORKFLOW_DESCRIPTION: "Assign an approved issue (go:yes) to the maintainer who approved it and route it to squad areas. Reads the prior triage analysis and the squad routing table, applies the squad label plus matched squad:{member} labels (and squad:copilot to hand the issue off to the Copilot coding agent), and posts an assignment rationale comment that, when auto-assign is not configured (no COPILOT_ASSIGN_TOKEN), also nudges the assignee to assign the Copilot coding agent so work can begin." HAS_PATCH: ${{ needs.agent.outputs.has_patch }} with: script: | @@ -1617,8 +1620,8 @@ jobs: destination: ${{ runner.temp }}/gh-aw/actions job-name: ${{ github.job }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" @@ -1651,7 +1654,7 @@ jobs: GH_AW_AGENT_AIC: ${{ needs.agent.outputs.aic }} GH_AW_AIC: ${{ needs.agent.outputs.aic }} GH_AW_AMBIENT_CONTEXT: ${{ needs.agent.outputs.ambient_context }} - GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/issue-assign" + GH_AW_CALLER_WORKFLOW_ID: "${{ github.repository }}/issue-go-yes" GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }} GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }} GH_AW_EFFECTIVE_TOKENS: ${{ needs.agent.outputs.effective_tokens }} @@ -1660,9 +1663,9 @@ jobs: GH_AW_ENGINE_VERSION: "1.0.65" GH_AW_RUNTIME_FEATURES: ${{ vars.GH_AW_RUNTIME_FEATURES }} GH_AW_THREAT_DETECTION_AIC: ${{ needs.detection.outputs.aic }} - GH_AW_WORKFLOW_ID: "issue-assign" - GH_AW_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-assign.md" + GH_AW_WORKFLOW_ID: "issue-go-yes" + GH_AW_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/${{ github.repository }}/blob/${{ github.ref_name }}/.github/workflows/issue-go-yes.md" outputs: assign_to_user_assigned: ${{ steps.process_safe_outputs.outputs.assigned }} code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }} @@ -1683,8 +1686,8 @@ jobs: trace-id: ${{ needs.activation.outputs.setup-trace-id }} parent-span-id: ${{ needs.activation.outputs.setup-parent-span-id || needs.activation.outputs.setup-span-id }} env: - GH_AW_SETUP_WORKFLOW_NAME: "Issue Assignment Agent" - GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-assign.lock.yml@${{ github.ref }} + GH_AW_SETUP_WORKFLOW_NAME: "Issue Go: Yes" + GH_AW_CURRENT_WORKFLOW_REF: ${{ github.repository }}/.github/workflows/issue-go-yes.lock.yml@${{ github.ref }} GH_AW_INFO_VERSION: "1.0.65" GH_AW_INFO_AWF_VERSION: "v0.27.11" GH_AW_INFO_ENGINE_ID: "copilot" diff --git a/.github/workflows/issue-assign.md b/.github/workflows/issue-go-yes.md similarity index 79% rename from .github/workflows/issue-assign.md rename to .github/workflows/issue-go-yes.md index 813975cb..0fba62d6 100644 --- a/.github/workflows/issue-assign.md +++ b/.github/workflows/issue-go-yes.md @@ -1,9 +1,12 @@ --- +name: "Issue Go: Yes" description: > Assign an approved issue (go:yes) to the maintainer who approved it and route it to squad areas. Reads the prior triage analysis and the squad routing table, applies the squad label plus matched squad:{member} labels (and squad:copilot to hand the issue - off to the Copilot coding agent), and posts an assignment rationale comment. + off to the Copilot coding agent), and posts an assignment rationale comment that, + when auto-assign is not configured (no COPILOT_ASSIGN_TOKEN), also nudges the + assignee to assign the Copilot coding agent so work can begin. on: issues: @@ -44,6 +47,10 @@ steps: ISSUE_TITLE: ${{ github.event.issue.title }} GO_YES_SENDER: ${{ github.event.sender.login }} GH_TOKEN: ${{ github.token }} + # 'true' only when the repo secret is set — i.e. squad-heartbeat can + # auto-assign the coding agent. The secret VALUE is never exposed; only + # this boolean is placed in the environment. + HAS_ASSIGN_TOKEN: ${{ secrets.COPILOT_ASSIGN_TOKEN != '' }} run: | mkdir -p /tmp/gh-aw/agent @@ -70,6 +77,22 @@ steps: printf '%s\n' '_No prior triage analysis comment found — route from the issue content alone._' >> "$USER_FILE" fi + # --------------------------------------------------------------------- + # Copilot coding-agent hand-off status (deterministic, trusted context). + # NUDGE_NEEDED is true only when auto-assign is unavailable AND the coding + # agent is not already an assignee — so the agent should nudge the human. + # --------------------------------------------------------------------- + CURRENT_ASSIGNEES=$(gh issue view "$ISSUE_NUMBER" --repo "$GITHUB_REPOSITORY" --json assignees \ + --jq '[.assignees[].login] | join(",")' 2>/dev/null | tr 'A-Z' 'a-z' || printf '') + AGENT_ALREADY_ASSIGNED=false + if printf ',%s,' "$CURRENT_ASSIGNEES" | grep -qE ',(copilot-swe-agent\[bot\]|copilot-swe-agent|copilot),'; then + AGENT_ALREADY_ASSIGNED=true + fi + NUDGE_NEEDED=false + if [ "${HAS_ASSIGN_TOKEN:-false}" != "true" ] && [ "$AGENT_ALREADY_ASSIGNED" != "true" ]; then + NUDGE_NEEDED=true + fi + # --------------------------------------------------------------------- # SYSTEM context (trusted): assignment policy + routing/team tables. # Single-quoted printf args keep backticks/`$` literal (no expansion). @@ -85,6 +108,11 @@ steps: printf '%s\n' '- Apply one `squad:{member}` label for every squad area the issue touches, per the routing table below.' printf '%s\n' '- Apply the `squad:copilot` label to hand the issue off to the Copilot coding agent to begin implementation.' printf '%s\n' '- Never apply `go:*`, `priority:*`, `override:*`, or `type:*` labels.' + if [ "$NUDGE_NEEDED" = "true" ]; then + printf -- '- **Copilot hand-off nudge REQUIRED:** no coding agent is assigned to this issue yet. In your single assignment comment, add an `### 🤖 Action needed` section that @-mentions **@%s** and tells them to assign this issue to Copilot from the Assignees menu so implementation can begin. Do NOT mention COPILOT_ASSIGN_TOKEN, repository secrets, `.squad/team.md`, or any workflow internals in the comment.\n' "$GO_YES_SENDER" + else + printf '%s\n' '- **Copilot hand-off nudge:** NOT required — do not add any Copilot-assignment nudge to the comment (auto-assign is configured or the coding agent is already assigned).' + fi printf '\n' } > "$SYS_FILE" @@ -226,6 +254,9 @@ context — you do not decide the assignee yourself. `squad` label, `squad:copilot`, and the most relevant matched member labels. 6. **Comment** exactly once with `add_comment`, explaining the assignee, the matched squad areas, and the routing evidence (which routing-table entries matched and why). + If the system policy says a **Copilot hand-off nudge** is REQUIRED, append the + `### 🤖 Action needed` section (described in that policy) to this same comment. If it + says the nudge is NOT required, omit that section entirely. ## Assignment comment format @@ -241,6 +272,11 @@ context — you do not decide the assignee yourself. #### Notes + + +### 🤖 Action needed +@ — this issue is not assigned to the Copilot coding agent yet, so no agent +session has started. Please assign it to Copilot from the Assignees menu to begin work. ``` ## Security Rules diff --git a/.github/workflows/squad-heartbeat.yml b/.github/workflows/squad-heartbeat.yml index 5a70db11..609cb51e 100644 --- a/.github/workflows/squad-heartbeat.yml +++ b/.github/workflows/squad-heartbeat.yml @@ -129,12 +129,19 @@ jobs: per_page: 5 }); - const unassigned = copilotIssues.filter(i => - !i.assignees || i.assignees.length === 0 + // Include issues that don't yet have the coding agent assigned. + // issue-go-yes always assigns the go:yes maintainer as owner, so an + // issue almost always has a (human) assignee — filtering on "zero + // assignees" would skip every routed issue. Filter on the agent's + // presence instead; the POST below ADDS the bot as an extra assignee + // without removing the human owner. + const COPILOT_LOGINS = new Set(['copilot-swe-agent[bot]', 'copilot-swe-agent', 'copilot']); + const needsAgent = copilotIssues.filter(i => + !(i.assignees || []).some(a => COPILOT_LOGINS.has((a.login || '').toLowerCase())) ); - if (unassigned.length === 0) { - core.info('No unassigned squad:copilot issues'); + if (needsAgent.length === 0) { + core.info('No squad:copilot issues awaiting the coding agent'); return; } @@ -144,7 +151,7 @@ jobs: repo: context.repo.repo }); - for (const issue of unassigned) { + for (const issue of needsAgent) { try { await github.request('POST /repos/{owner}/{repo}/issues/{issue_number}/assignees', { owner: context.repo.owner, diff --git a/.squad/team.md b/.squad/team.md index f4088c90..6911e6a8 100644 --- a/.squad/team.md +++ b/.squad/team.md @@ -26,6 +26,30 @@ | SecurityExpert | 🔒 Security Expert | [charter](.squad/agents/securityexpert/charter.md) | ✅ Active | | Ralph | 🔄 Work Monitor | — | ✅ Active | +## Coding Agent + + + +GitHub's Copilot coding agent (`@copilot`) autonomously implements issues labeled +`squad:copilot`. Ralph (`squad-heartbeat.yml`) assigns `copilot-swe-agent[bot]` to +every open `squad:copilot` issue that does not already have the agent assigned — +in addition to the human maintainer who owns it — which is what actually starts an +agent session (the label alone does not). + +| Name | Role | Auto-assign | Notes | +|------|------|-------------|-------| +| Copilot | 🤖 Coding Agent | ✅ Enabled | Requires the `COPILOT_ASSIGN_TOKEN` repo secret (a PAT that can assign the coding agent). Without it the assign step is a no-op. | + +**Setting up `COPILOT_ASSIGN_TOKEN`:** the default `GITHUB_TOKEN` cannot assign the +coding agent, so the assign step needs a user token stored as a repo secret. Create a +[fine-grained personal access token](https://docs.github.com/en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens) +(ideally on a machine/bot account) with **Repository permissions** — *Metadata*: read, +and *Actions*, *Contents*, *Issues*, and *Pull requests*: read & write — then add it as a +[repository secret](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets#creating-secrets-for-a-repository) +named `COPILOT_ASSIGN_TOKEN`. A classic PAT with the `repo` scope also works. The exact +token requirements are documented under +[Assigning issues to Copilot via the API](https://docs.github.com/en/copilot/how-tos/use-copilot-agents/cloud-agent/use-cloud-agent-via-the-api#using-the-issues-api). + ## Issue Source - **Repository:** Azure/apiops-cli diff --git a/.squad/templates/workflows/squad-heartbeat.yml b/.squad/templates/workflows/squad-heartbeat.yml index 957915a4..77d03c23 100644 --- a/.squad/templates/workflows/squad-heartbeat.yml +++ b/.squad/templates/workflows/squad-heartbeat.yml @@ -133,12 +133,19 @@ jobs: per_page: 5 }); - const unassigned = copilotIssues.filter(i => - !i.assignees || i.assignees.length === 0 + // Include issues that don't yet have the coding agent assigned. + // issue-go-yes always assigns the go:yes maintainer as owner, so an + // issue almost always has a (human) assignee — filtering on "zero + // assignees" would skip every routed issue. Filter on the agent's + // presence instead; the POST below ADDS the bot as an extra assignee + // without removing the human owner. + const COPILOT_LOGINS = new Set(['copilot-swe-agent[bot]', 'copilot-swe-agent', 'copilot']); + const needsAgent = copilotIssues.filter(i => + !(i.assignees || []).some(a => COPILOT_LOGINS.has((a.login || '').toLowerCase())) ); - if (unassigned.length === 0) { - core.info('No unassigned squad:copilot issues'); + if (needsAgent.length === 0) { + core.info('No squad:copilot issues awaiting the coding agent'); return; } @@ -148,7 +155,7 @@ jobs: repo: context.repo.repo }); - for (const issue of unassigned) { + for (const issue of needsAgent) { try { await github.request('POST /repos/{owner}/{repo}/issues/{issue_number}/assignees', { owner: context.repo.owner,