chore(deps): update github/gh-aw action to v0.83.4 - #369
Conversation
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Python | May 6, 2026 11:42a.m. | Review ↗ | |
| Secrets | May 6, 2026 11:42a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
Merge Queue Status
This pull request spent 1 day 33 seconds in the queue, with no time running CI. ReasonThe pull request #369 has been manually updated HintIf you want to requeue this pull request, you can post a |
Code Review SummaryStatus: No Issues Found | Recommendation: Merge OverviewChanges are routine version bumps in auto-generated workflow lock files (v0.67.1 → v0.81.5). No functional changes detected. This is a Renovate bot update for GitHub Actions. Files Reviewed (2 files)
Previous Review Summaries (6 snapshots, latest commit 3030fd6)Current summary above is authoritative. Previous snapshots are kept for context only. Previous review (commit 3030fd6)Status: No Issues Found | Recommendation: Merge OverviewChanges are routine version bumps in auto-generated workflow lock files (v0.67.1 → v0.80.9). No functional changes detected. This is a Renovate bot update for GitHub Actions. Files Reviewed (2 files)
Previous review (commit f1d3998)Status: No Issues Found | Recommendation: Merge OverviewFull diff review (incremental base unavailable due to history rewrite) — changes are routine version bumps in auto-generated workflow lock files (v0.67.1 → v0.80.9). No functional changes detected. Files Reviewed (2 files)
Previous review (commit e352849)Status: No Issues Found | Recommendation: Merge OverviewIncremental changes since commit Files Reviewed (2 files)
Previous review (commit 3c9b0f5)Status: No Issues Found | Recommendation: Merge OverviewFull diff review (incremental history unavailable) - changes are routine version bumps in auto-generated workflow lock files. No functional changes detected. Files Reviewed (2 files)
Previous review (commit f04c221)Status: No Issues Found | Recommendation: Merge OverviewIncremental changes since previous review (commit Files Reviewed (2 files)
Previous review (commit 566df55)Status: No Issues Found | Recommendation: Merge Files Reviewed (2 files)
Reviewed by laguna-m.1-20260312:free · Input: 244.4K · Output: 2.3K · Cached: 313.1K |
962ccd6 to
12bb3e3
Compare
Merge Queue Status
This pull request spent 2 days 16 hours 57 minutes 39 seconds in the queue, with no time running CI. ReasonThe pull request #369 has been manually updated HintIf you want to requeue this pull request, you can post a |
12bb3e3 to
989e44b
Compare
Merge Queue Status
This pull request spent 2 hours 39 minutes 5 seconds in the queue, with no time running CI. ReasonThe pull request #369 has been manually updated HintIf you want to requeue this pull request, you can post a |
989e44b to
aa3aa42
Compare
Merge Queue Status
This pull request spent 1 day 4 hours 53 minutes 29 seconds in the queue, with no time running CI. ReasonThe pull request #369 has been manually updated HintIf you want to requeue this pull request, you can post a |
aa3aa42 to
a1b536b
Compare
Merge Queue Status
This pull request spent 4 hours 52 minutes 3 seconds in the queue, including 50 seconds running CI. ReasonThe pull request #369 has been manually updated Requeued — the merge queue status continues in this comment ↓. |
Merge Queue Status
This pull request spent 2 days 11 hours 45 minutes 53 seconds in the queue, including 36 seconds running CI. Required conditions to merge
ReasonThe pull request #369 has been manually updated Requeued — the merge queue status continues in this comment ↓. |
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
This pull request spent 26 days 1 hour 27 minutes 47 seconds in the queue, including 9 minutes 56 seconds running CI. Required conditions to merge
ReasonThe pull request #369 has been manually updated Requeued — the merge queue status continues in this comment ↓. |
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
This pull request spent 2 days 1 hour 19 minutes 41 seconds in the queue, including 2 minutes 38 seconds running CI. Required conditions to merge
ReasonThe pull request #369 has been manually updated Requeued — the merge queue status continues in this comment ↓. |
|
Merge Queue Status
|
Merge Queue Status
|
Merge Queue Status
|




This PR contains the following updates:
v0.67.1→v0.83.4Release Notes
github/gh-aw (github/gh-aw)
v0.83.4Compare Source
🌟 Release Highlights
This release brings significant security hardening, new authentication options, expanded model support, and important workflow reliability fixes across the gh-aw platform.
✨ What's New
extraHeaders,extraBodyFields, andsessionIdin workflow frontmatter for bring-your-own-key Copilot SDK integrations. (#48096)stringsindexhasprefixGo linter — New analyzer detectsstrings.Index(...) == 0patterns that should usestrings.HasPrefix. (#48049)claude-opus-5to pricing catalogs and kept all model mirrors in sync. (#48294, #48279, #48303)v0.27.42/ MCP Gatewayv0.4.6with refreshed pinned artifacts. (#48236)🐛 Bug Fixes & Improvements
dispatch_workflowbackward compatibility restored — Single-target dispatch safe outputs work again after the multi-target refactor. (#48317)add-wizardbootstrap ordering fixed — Pre-install bootstrap steps now run before engine selection, and call-workflow worker loading is properly initialized. (#48282, #48301)GH_AW_INPUT_*forwarded to MCP container — Dynamic safe-outputs configuration now reaches the MCP container environment as intended. (#48099)label_commandactivation guard preserved — Customif:conditions in frontmatter no longer clobber the built-in activation guard. (#48105)(redacted)autolinks. (#48169)playwright-climode in CI containers, fixing test failures in rootless environments. (#48102)StartDockerImageDownloadto prevent goroutine leaks. (#47974)📚 Documentation
What's Changed
StartDockerImageDownloadto bound goroutine lifecycle by @pelikhan with @Copilot in #47974linters.All()inpkg/lintersspec by @pelikhan with @Copilot in #48015engine.driversources for Copilot SDK workflows by @pelikhan with @Copilot in #47991stringsindexhasprefixanalyzer forstrings.Index(... ) == 0/!= 0by @pelikhan with @Copilot in #48049max-patch-sizepre-check with push diff semantics by @pelikhan with @Copilot in #48106steps.*.outputs.*ingithub-tokenexpressions for same-job safe-output auth by @pelikhan with @Copilot in #48101if:by @pelikhan with @Copilot in #48105models.providerspricing into AWFapiProxy(including threat-detection runs) by @pelikhan with @Copilot in #48107gh aw add-wizardby @pelikhan with @Copilot in #48282gh-aw-wasmpackage (main is undeclared) by @github-actions[bot] in #48320dispatch_workflowsafe outputs by @pelikhan with @Copilot in #48317Full Changelog: github/gh-aw@v0.83.3...v0.83.4
v0.83.3Compare Source
🌟 Release Highlights
This release delivers significant security hardening, expanded linter coverage, improved tooling reliability, and key fixes across the compilation and evaluation pipeline.
✨ What's New
daily-github-docs-seo-optimizer) now continuously scans and improves documentation SEO, keeping content discoverable without manual intervention. (#47975)cli-version-checkerworkflow now monitors Docker image updates, ensuring container dependencies stay current. (#47980)stringsconcatloopLinter — New Go linter detects inefficientstring +=concatenation inside loops, guiding developers towardstrings.Builderfor better performance. (#47894)🔒 Security Fixes
getOwnerNodeId(code scanning alerts #651 and #652). (#47952)gh-aw-firewallv0.27.41 container digest pins following a Go stdlib CVE rebuild. (#47838)actions-lockentries after updates, preventing supply-chain tampering. (#47959)🐛 Bug Fixes & Improvements
ModelMappingsare now propagated into evalsWorkflowData, unblocking model alias resolution in evaluation runs. (#47956)require-fetch-try-catchFalse Positives — Fixed false positives forawait fetchinside directly-awaited async callbacks and member-chained calls. (#47969, #47963)goleak-based leak detection forpkg/cliandpkg/consoletests, catching resource leaks early. (#47865, #47891)Process Safe Outputsstdout/stderr are now pre-bundled in failure artifacts, making debugging failed safe-output steps significantly easier. (#47855)config.tomlincorrectly emittingmodel_providerunder[history]. (#47832)📚 Documentation
🔧 Internal
mcp_setup_generator.gointo 5 focused modules. (#47839)internal/astutil. (#47912)appendoneelement,timenowsub, andstringsjoinonelinters in CI. (#47970)pkg/cliandpkg/consoleunit tests are executed. (#47905)What's Changed
CompileWorkflow_WithMCPbenchmark to remove warning-path overhead by @pelikhan with @Copilot in #47698actions: readto smoke-trigger and smoke-multi-caller caller permissions by @pelikhan with @Copilot in #47721no-child-process-interpolated-commandby @pelikhan with @Copilot in #47866pkg/cliandpkg/consoletests by @pelikhan with @Copilot in #47865Process Safe Outputsstdout/stderr in safe-output failure artifacts by @pelikhan with @Copilot in #47855.github/workflows/*.mdedits by @pelikhan with @Copilot in #47962require-fetch-try-catchby @pelikhan with @Copilot in #47963Full Changelog: github/gh-aw@v0.83.2...v0.83.3
v0.83.2Compare Source
🌟 Release Highlights
This release focuses on security hardening, reliability fixes, and developer tooling improvements — with enhanced shell-injection detection, WIF auth regression fixes, and a smarter
gh aw addcommand.✨ What's New
gh aw add: Local skill references are now automatically rewritten to fully-qualified specs ongh aw add, reducing configuration drift and making workflows more portable. (#47690)sandbox.agent.default-ai-credits-pricingto fix HTTP 400 errors when using Bring-Your-Own-Key Ollama engines. (#47687)no-child-process-interpolated-commandrule to catch shell-injection command strings at authoring time. (#47555)🐛 Bug Fixes & Improvements
close-older-issuesfrom accidentally closing issues created in the same workflow run. (#47585)no-exec-interpolated-command. (#47544)🔧 Internal
ghCLI calls with native go-gh REST clients for release and ref lookups📚 Documentation
What's Changed
no-child-process-interpolated-commandto catch shell-injection command strings by @pelikhan with @Copilot in #47555sub_agent_strategyexperiment to smoke-copilot-sub-agents by @pelikhan with @Copilot in #47557largefuncfindings in CLI/workflow paths by @pelikhan with @Copilot in #47601gh aw addby @pelikhan with @Copilot in #47690Full Changelog: github/gh-aw@v0.83.1...v0.83.2
v0.83.1Compare Source
🌟 Release Highlights
This release expands the
gh aw compilesecurity pipeline with container vulnerability scanning, license auditing, and YAML linting — while delivering a wave of reliability fixes across the compiler, harness, and PR review workflows.✨ What's New
gh aw compilenow runs [Grype](https://redirect.github.com/anchore/grypeConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.