Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
557 commits
Select commit Hold shift + click to select a range
6dcb0b0
docs(discussion view): improve long help text for clarity
babakks Jun 5, 2026
b8361f8
chore(deps): bump charm.land/bubbletea/v2 from 2.0.6 to 2.0.7
dependabot[bot] Jun 5, 2026
def924b
chore(deps): bump github/codeql-action from 4.36.0 to 4.36.1
dependabot[bot] Jun 5, 2026
8c582eb
chore(deps): bump actions/checkout from 6.0.2 to 6.0.3
dependabot[bot] Jun 5, 2026
db66865
Merge pull request #13597 from cli/dependabot/github_actions/actions/…
BagToad Jun 5, 2026
19ac156
Merge pull request #13596 from cli/dependabot/github_actions/github/c…
BagToad Jun 5, 2026
898d972
Merge pull request #13595 from cli/dependabot/go_modules/charm.land/b…
BagToad Jun 5, 2026
ea72240
Merge pull request #13572 from cli/dependabot/go_modules/github.com/m…
BagToad Jun 5, 2026
6b86763
feat(extension): alias `uninstall` to `remove`
BagToad Jun 5, 2026
5c9ec1c
Merge pull request #13599 from cli/bagtoad/kw-issue-13598-extension-u…
babakks Jun 5, 2026
fbd733e
refactor(discussion): add Cursor field and ExportData to DiscussionLi…
babakks Jun 5, 2026
e104885
refactor(discussion/client): precheck discussions enabled via getRepo…
babakks Jun 5, 2026
ca8e126
fix(discussion list): print "answered" instead of checkmark in non-tt…
babakks Jun 5, 2026
ada8583
test(discussion): add acceptance tests for discussion commands
babakks Jun 5, 2026
8ec0830
docs(acceptance): add new jq2env and jq-assert functions
babakks Jun 5, 2026
f147d02
test(discussion list): consolidate tests into table-driven format
babakks Jun 5, 2026
e61df07
Merge branch 'trunk' into feature/discussion
babakks Jun 5, 2026
c1f3c1a
fix(discussion): add missing repo flag override
babakks Jun 8, 2026
1a279ac
chore(deps): bump github/codeql-action from 4.36.1 to 4.36.2
dependabot[bot] Jun 8, 2026
da68cb8
Add terminal-mockup canvas extension for marketing screenshots (#13612)
BagToad Jun 8, 2026
9d413e7
test(discussion list): rename TestNewCmdList2 to TestNewCmdList
babakks Jun 9, 2026
e2d150d
fix(discussion): remove redundant error wrapping on ListCategories
babakks Jun 9, 2026
95fc89c
chore(discussion): remove unused HttpClient field from create and edit
babakks Jun 9, 2026
4166ecf
chore: apply formatting
babakks Jun 9, 2026
4a02c38
Merge remote-tracking branch 'upstream/trunk' into trunk
malancas Jun 9, 2026
3fed6ef
return error if GitHub verifier is not available
malancas Jun 9, 2026
2618999
feat(discussion/client): add comment manipulation methods
babakks Jun 6, 2026
6f5e114
feat(discussion): add discussion comment command
babakks Jun 8, 2026
82ac0d7
refactor(acceptance): use discussion comment command instead of raw A…
babakks Jun 8, 2026
2629753
test(acceptance): add discussion comment acceptance test
babakks Jun 8, 2026
61a4476
test(discussion comment): add non-tty delete flag validation test case
babakks Jun 8, 2026
d026f8f
feat(discussion): support comment URLs in --replies and comment command
babakks Jun 8, 2026
6394ca8
test(acceptance): cover discussion comment URLs in comment and view t…
babakks Jun 8, 2026
bc7ed48
chore: fix formatting
babakks Jun 8, 2026
55928c9
refactor(discussion view): replace --replies flag with positional com…
babakks Jun 10, 2026
8747c69
refactor(discussion/client): take host instead of repo in GetComment
babakks Jun 10, 2026
869c044
test(acceptance): use positional comment argument in discussion view …
babakks Jun 10, 2026
8d2b059
fix(discussion view): error when --comments is used with a comment ar…
babakks Jun 10, 2026
42db02d
Merge pull request #13620 from cli/babakks/add-discussion-comment
babakks Jun 10, 2026
27aabfa
fix(discussion view): use color scheme method for success icon
babakks Jun 10, 2026
951d76e
refactor(discussion list): simplify no-results message and use succes…
babakks Jun 10, 2026
9f2da11
fix(discussion view): show comments and replies in chronological order
babakks Jun 10, 2026
06d2e34
docs(discussion list): clarify answered examples refer to Q&A discuss…
babakks Jun 10, 2026
5d77247
fix(discussion view): print only requested items in non-tty output
babakks Jun 10, 2026
d63ab8d
fix(discussion/shared): error on out-of-range discussion number in URL
babakks Jun 10, 2026
5e6a58b
test(acceptance): fix discussion comment acceptance tests
babakks Jun 10, 2026
616d929
chore(discussion/client): rename client files
babakks Jun 10, 2026
69855b7
fix(discussion comment): fix bug in requiring body/body-file in add/e…
babakks Jun 10, 2026
52e8e74
Merge pull request #13541 from cli/feature/discussion
babakks Jun 10, 2026
cac0ba1
Add gh discussion and Issues 2.0 reference to the `gh` skill, plus a …
BagToad Jun 10, 2026
9075b62
docs(discussion): polish help docs
babakks Jun 10, 2026
2ededc5
Potential fix for pull request finding
babakks Jun 10, 2026
57b9b20
Merge pull request #13632 from cli/babakks/fix-discussion-docs
babakks Jun 10, 2026
4343e40
test(skill): merge isolated test into table
babakks Jun 11, 2026
b5fec79
test(skill): fix test case name
babakks Jun 11, 2026
6e755df
chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0
dependabot[bot] Jun 12, 2026
412c5fa
Merge pull request #13523 from cli/tommy/skill-claude-config-dir-fix
tommaso-moro Jun 15, 2026
a834c67
Merge pull request #13640 from cli/dependabot/go_modules/golang.org/x…
babakks Jun 15, 2026
6f665ed
chore(deps): bump github.com/sigstore/sigstore-go from 1.1.4 to 1.2.1
dependabot[bot] Jun 15, 2026
49b18f5
chore(deps): bump charm.land/lipgloss/v2 from 2.0.3 to 2.0.4
dependabot[bot] Jun 15, 2026
f4cab89
Merge pull request #13663 from cli/dependabot/go_modules/charm.land/l…
babakks Jun 15, 2026
981f43b
chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0
dependabot[bot] Jun 15, 2026
1e449a2
Merge pull request #13661 from cli/dependabot/go_modules/golang.org/x…
babakks Jun 15, 2026
e66c2c4
Merge pull request #13619 from cli/dependabot/github_actions/github/c…
babakks Jun 15, 2026
54fa0c6
Merge pull request #13662 from cli/dependabot/go_modules/github.com/s…
babakks Jun 15, 2026
ec0fe28
chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0
dependabot[bot] Jun 15, 2026
f15dce8
Merge pull request #13641 from cli/dependabot/go_modules/golang.org/x…
babakks Jun 15, 2026
da101bf
Merge remote-tracking branch 'origin/wm-site-deploy-app' into niik/de…
niik Jun 16, 2026
7d92f7d
Initial conversion to reusable workflow
niik Jun 16, 2026
8f2ecd2
Update deployment.yml
niik Jun 16, 2026
d05c71a
Make filtering by bot authors more discoverable (#13642)
BagToad Jun 16, 2026
b401862
Bump Go in devcontainer
spenserblack Jun 16, 2026
a6012ac
Merge pull request #13674 from spenserblack/devcontainer
BagToad Jun 16, 2026
9522f6e
Mint a token from GitHub app
niik Jun 17, 2026
9ac613a
Use client-id input for create-github-app-token
niik Jun 17, 2026
f8dec08
Rename DEPLOY_APP_ID secret to DEPLOY_APP_CLIENT_ID
niik Jun 17, 2026
4f43068
Update deployment.yml
niik Jun 17, 2026
733e35c
feat: add `repo read-file` and `repo read-dir` (#13580)
babakks Jun 17, 2026
01bcd47
fix(skills): stage updates in a temp dir and swap in-place (#13449)
SamMorrowDrums Jun 17, 2026
70bb306
feat(skills): list available skills when install runs non-interactive…
SamMorrowDrums Jun 17, 2026
cce391b
fix: show checks summary when all checks were cancelled
s3onghyun Jun 18, 2026
517dae6
fix(skills): install universal agent to ~/.agents/skills
toller892 Jun 18, 2026
32db186
Cover all printSummary branches in a table test
s3onghyun Jun 19, 2026
f4a29a3
docs: fix broken anchor link in release-process-deep-dive (#13688)
patrickwehbe Jun 19, 2026
0274077
Use int64 for GitHub database IDs (#13403)
williammartin Jun 19, 2026
23f83e6
Merge pull request #13679 from s3onghyun/fix-checks-cancelled-only
babakks Jun 22, 2026
2d57360
chore(deps): bump github.com/google/go-containerregistry
dependabot[bot] Jun 22, 2026
5d1d164
ci: pin GitHub Actions to commit SHAs
BagToad Jun 12, 2026
9ad0bcc
Merge pull request #13705 from BagToad/bagtoad/kw-pin-reusable-workfl…
babakks Jun 23, 2026
31625d8
chore(deps): bump github.com/microsoft/dev-tunnels from 0.1.19 to 0.1.27
dependabot[bot] Jun 23, 2026
cd68c69
Merge pull request #13681 from toller892/fix/universal-install-location
tommaso-moro Jun 24, 2026
cc7120e
chore(deps): bump actions/checkout from 6.0.3 to 7.0.0
dependabot[bot] Jun 24, 2026
dd26eb3
Add security disclosure guidance to AGENTS.md (#13720)
BagToad Jun 24, 2026
015e6cf
Merge pull request #13708 from cli/dependabot/go_modules/github.com/m…
babakks Jun 25, 2026
561d9f9
Detect additional third-party coding agents (#13722)
BagToad Jun 25, 2026
954ffc3
Fix flaky TestHuhPrompterMultiSelectWithSearchPersistence on slow arc…
pdostal Jun 25, 2026
751dc5e
fix(release): don't let a failed draft lookup mask a found release
BagToad Jun 24, 2026
f0a128a
feat(release): allow download without authentication
BagToad Jun 24, 2026
7b681a4
fix(cmdutil): honor DisableAuthCheck under repo-override parents
BagToad Jun 25, 2026
71fb4f5
Merge pull request #13723 from cli/bagtoad/disable-auth-check-release…
BagToad Jun 26, 2026
047f43e
Merge pull request #13703 from cli/dependabot/github_actions/actions/…
niik Jun 29, 2026
f2abd40
chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0
dependabot[bot] Jun 29, 2026
a0c0773
Merge pull request #13702 from cli/dependabot/go_modules/github.com/g…
niik Jun 29, 2026
f843011
Merge pull request #13740 from cli/dependabot/github_actions/actions/…
niik Jun 29, 2026
ccaad40
chore(deps): bump actions/attest from 4.1.0 to 4.1.1
dependabot[bot] Jun 29, 2026
19201f3
Merge pull request #13754 from cli/dependabot/github_actions/actions/…
sergiou87 Jun 29, 2026
8a6b76d
docs(search): add examples for multiple qualifiers
happysnaker Jun 30, 2026
f69cf0f
Add 20-minute timeouts to deploy jobs
niik Jun 30, 2026
83f9562
Skip Windows code signing outside production deploys
niik Jun 30, 2026
6ee1a91
docs(search): simplify raw qualifier examples
happysnaker Jun 30, 2026
2c76101
chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3
dependabot[bot] Jun 30, 2026
b7195a5
Merge pull request #13759 from cli/dependabot/github_actions/goreleas…
babakks Jun 30, 2026
0afaf6f
docs(search): reword raw qualifier examples
happysnaker Jul 1, 2026
ff4e4a2
Merge pull request #13756 from happysnaker/docs-search-qualifier-exam…
babakks Jul 1, 2026
e64de0c
Add dry_run flag to gate release publishing
niik Jul 1, 2026
0e3afb4
Fix macOS signing/notarization keychain and gating
niik Jul 1, 2026
57e8cce
Update deployment.yml
niik Jul 1, 2026
9e37641
Use workflow_dispatch for deployment flow
niik Jul 1, 2026
d6be637
Update deployment.yml
niik Jul 1, 2026
3b24ab7
Update deployment.yml
niik Jul 1, 2026
7dbc4b5
Add draft issue-triage gh-aw workflow (issue-intents starting point)
lukewar Jul 2, 2026
ecd7027
Retune issue-triage stub to the team's documented triage process
lukewar Jul 2, 2026
637455c
Let's try a different approach
niik Jul 2, 2026
86ded77
Add diagnostic step to list macOS signing identities
niik Jul 2, 2026
0d8d855
Try this then
niik Jul 2, 2026
52669eb
Don't see how this could have worked in the past
niik Jul 2, 2026
ef90664
Don't need this any more
niik Jul 2, 2026
eeb9a3c
Update release deep-dive doc for macOS signing and dry_run changes
niik Jul 2, 2026
070ed9b
Forward dry_run to deployment workflow from script/release
niik Jul 2, 2026
7441b07
Remove ref input from deployment workflow
niik Jul 2, 2026
7a6ed73
Pass macOS signing secrets via env instead of inline interpolation
niik Jul 2, 2026
b63b811
Gate macOS signing on DO_SIGN_ARTIFACTS
niik Jul 2, 2026
64840c7
Mark dry runs in the workflow run name
niik Jul 2, 2026
a79c060
Revert to missing var
niik Jul 2, 2026
f4ce1d9
chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0
dependabot[bot] Jul 2, 2026
b5b459a
Merge branch 'trunk' into niik/deploy
niik Jul 2, 2026
397876d
Merge pull request #13779 from cli/dependabot/github_actions/golangci…
sergiou87 Jul 2, 2026
326faaa
Support antigravity-cli and antigravity2.0 in gh skill (#13784)
Copilot Jul 2, 2026
f1d1121
fix(skills): honor --dir without agent prompt (#13766)
happysnaker Jul 2, 2026
fd8bbbd
docs: fix duplicated word in primer README (#13677)
s3onghyun Jul 2, 2026
5cb1b08
Clarify `--clone` boolean flag behaviour in `gh repo fork` help (#13786)
Copilot Jul 2, 2026
6dae307
docs: fix broken install command and link/grammar errors (#13690)
patrickwehbe Jul 2, 2026
74e7791
Fix concurrent map writes in codespace port forwarding (#13313)
williammartin Jul 2, 2026
b300f2e
Merge commit from fork
victoriamaciver Jul 2, 2026
ed04ff2
Gate publishing the site on the production environment
niik Jul 3, 2026
1b7da92
Fix pkg installer var in deep-dive code snippet
niik Jul 3, 2026
ee7fd9d
Correct pkg signing NOTE in deep-dive
niik Jul 3, 2026
7822e91
Quote $KEYCHAIN in notarytool submit invocation
niik Jul 3, 2026
0ca080d
Bump keyring operation timeout from 3s to 60s
kofuk Jul 3, 2026
c62577b
Merge branch 'trunk' into niik/deploy
niik Jul 3, 2026
9cde87c
Apply suggestions from code review
niik Jul 3, 2026
57a479f
Update deep-dive doc for final release workflow state
niik Jul 3, 2026
9bd8c74
chore(deps): bump charm.land/lipgloss/v2 from 2.0.4 to 2.0.5
dependabot[bot] Jul 3, 2026
62f01e7
chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.19.0
dependabot[bot] Jul 3, 2026
cfa2cad
Merge pull request #13790 from cli/dependabot/go_modules/charm.land/l…
babakks Jul 3, 2026
4abc935
chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.0
dependabot[bot] Jul 3, 2026
4e40c24
Merge pull request #13789 from cli/dependabot/go_modules/google.golan…
babakks Jul 3, 2026
27762fc
Merge pull request #13791 from cli/dependabot/go_modules/github.com/k…
sergiou87 Jul 3, 2026
94817b7
chore(deps): bump charm.land/bubbletea/v2 from 2.0.7 to 2.0.8
dependabot[bot] Jul 6, 2026
df0bd23
chore(deps): bump github/codeql-action/analyze from 4.36.2 to 4.36.3
dependabot[bot] Jul 6, 2026
e9a621b
chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0
dependabot[bot] Jul 7, 2026
ca4604b
Bump Go to 1.26.5
web-flow Jul 8, 2026
12fb220
Merge pull request #13817 from cli/bump-go-1.26.5
babakks Jul 8, 2026
5b17281
chore(deps): bump golang.org/x/sys from 0.46.0 to 0.47.0
dependabot[bot] Jul 8, 2026
487aea5
Adopt skills-driven triage approach from desktop/desktop
tidy-dev Jul 9, 2026
03d2889
Remove medium-confidence instruction from Step 5
tidy-dev Jul 9, 2026
5d4c548
Merge pull request #13777 from lukewar/aw-issue-intents-triage-stub
tidy-dev Jul 9, 2026
6c61ee4
Use Actions token for Copilot inference instead of PAT
tidy-dev Jul 9, 2026
eb42db6
Merge pull request #13830 from cli/aw-copilot-requests-permission
tidy-dev Jul 9, 2026
5cce0a3
chore(deps): bump github/gh-aw-actions/setup from 0.81.6 to 0.82.2
dependabot[bot] Jul 9, 2026
0611eb6
Merge pull request #13800 from cli/dependabot/go_modules/charm.land/b…
tidy-dev Jul 9, 2026
73c6102
chore(deps): bump charm.land/bubbles/v2 from 2.1.0 to 2.1.1
dependabot[bot] Jul 9, 2026
53d9b44
chore(deps): bump codeql-action/init and upload-sarif to v4.36.3
tidy-dev Jul 9, 2026
9ea7e69
Merge pull request #13812 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
989c466
Merge pull request #13821 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
e9e13a8
chore(deps): bump golang.org/x/sync from 0.21.0 to 0.22.0
dependabot[bot] Jul 9, 2026
9c980dc
Merge pull request #13801 from cli/dependabot/github_actions/github/c…
tidy-dev Jul 9, 2026
a483977
Merge pull request #13832 from cli/dependabot/github_actions/github/g…
tidy-dev Jul 9, 2026
fba5ab9
Merge pull request #13813 from cli/dependabot/go_modules/charm.land/b…
tidy-dev Jul 9, 2026
bd81afd
Merge pull request #13822 from cli/dependabot/go_modules/golang.org/x…
tidy-dev Jul 9, 2026
27d437e
chore(deps): bump actions/cache/restore from 5.0.5 to 6.1.0
dependabot[bot] Jul 10, 2026
1146c49
chore(deps): bump github/gh-aw-actions/setup from 0.82.2 to 0.82.3
dependabot[bot] Jul 10, 2026
180930b
Merge branch 'trunk' into handle-missing-trusted-root
malancas Jul 10, 2026
d58ad9c
drop notPanics assertion
malancas Jul 10, 2026
2a371b2
Merge branch 'handle-missing-trusted-root' of github.com:malancas/cli…
malancas Jul 10, 2026
d51b722
Merge pull request #13624 from malancas/handle-missing-trusted-root
malancas Jul 10, 2026
2b97099
Merge pull request #13843 from cli/dependabot/github_actions/github/g…
babakks Jul 13, 2026
d5f4bed
Add Grok skill host support
tommaso-moro Jul 13, 2026
10c3f78
Merge pull request #13841 from cli/dependabot/github_actions/actions/…
babakks Jul 13, 2026
37f5259
Clarify agent host examples
tommaso-moro Jul 13, 2026
9d95dd7
Merge pull request #13864 from cli/tommaso-moro-add-grok-skill-host
tommaso-moro Jul 13, 2026
70f1c08
chore(deps): bump golang.org/x/crypto from 0.53.0 to 0.54.0
dependabot[bot] Jul 13, 2026
ebaa7af
chore(deps): bump github/codeql-action/upload-sarif
dependabot[bot] Jul 13, 2026
90e850c
chore(deps): bump github/codeql-action/analyze from 4.36.3 to 4.37.0
dependabot[bot] Jul 13, 2026
c14cbaa
Merge pull request #13780 from cli/niik/deploy
tidy-dev Jul 13, 2026
b1e3bf6
chore(deps): bump github/gh-aw-actions/setup from 0.82.3 to 0.82.8
dependabot[bot] Jul 14, 2026
b84c906
chore: remove dead CODEOWNERS rule for non-existent pkg/cmd/release/a…
kobihikri Jul 15, 2026
2af8c11
Merge pull request #13787 from kofuk/bump-keyring-timeout
BagToad Jul 16, 2026
63636a4
docs(search): note OWNER/REPO format on --repo flag
BagToad Jul 20, 2026
d1897f8
Add name-based resolution to gh project item-edit (#13807)
zwick Jul 20, 2026
4007349
Merge pull request #13922 from cli/bagtoad/search-repo-flag-hint
babakks Jul 20, 2026
54a0440
Merge pull request #13867 from cli/dependabot/go_modules/golang.org/x…
babakks Jul 21, 2026
794bbb8
chore(deps): bump github.com/yuin/goldmark from 1.8.2 to 1.8.4
dependabot[bot] Jul 21, 2026
9493134
Merge pull request #13869 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
dcd1adc
Merge pull request #13868 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
f15b788
chore(deps): bump github/codeql-action/init from 4.36.3 to 4.37.1
dependabot[bot] Jul 21, 2026
e1a095c
Upgrade CodeQL action to version 4.37.1
babakks Jul 21, 2026
713fc70
Merge pull request #13870 from cli/dependabot/github_actions/github/c…
babakks Jul 21, 2026
64bc042
Merge pull request #13888 from cli/dependabot/go_modules/github.com/y…
babakks Jul 21, 2026
731fc4c
chore(deps): bump github.com/sigstore/sigstore-go from 1.2.1 to 1.2.2
dependabot[bot] Jul 21, 2026
34a264f
Merge pull request #13842 from cli/dependabot/go_modules/github.com/s…
babakks Jul 21, 2026
340c0de
Merge pull request #13877 from cli/dependabot/github_actions/github/g…
babakks Jul 21, 2026
567a0cc
chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0
dependabot[bot] Jul 21, 2026
8355114
chore(deps): bump google.golang.org/grpc from 1.82.0 to 1.82.1
dependabot[bot] Jul 21, 2026
9d3aeaa
chore(deps): bump actions/attest from 4.1.1 to 4.2.0
dependabot[bot] Jul 21, 2026
ee721e8
chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0
dependabot[bot] Jul 21, 2026
a694799
Merge pull request #13886 from kobihikri/rm-dead-codeowners
williammartin Jul 21, 2026
ab07d0c
Merge pull request #13933 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
4b04d7d
Merge pull request #13934 from cli/dependabot/go_modules/google.golan…
babakks Jul 22, 2026
a5a326f
Merge pull request #13936 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
3f0b328
chore(deps): bump github/gh-aw-actions/setup from 0.82.8 to 0.82.13
dependabot[bot] Jul 22, 2026
457f377
Merge pull request #13935 from cli/dependabot/github_actions/actions/…
babakks Jul 22, 2026
6769f9c
chore(deps): bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23
dependabot[bot] Jul 22, 2026
ed60093
Merge pull request #13937 from cli/dependabot/go_modules/github.com/m…
babakks Jul 22, 2026
400e248
Merge pull request #13938 from cli/dependabot/github_actions/github/g…
babakks Jul 22, 2026
0492fd1
chore(typos): fix typos in code and documentation
pstoeckle Jul 22, 2026
bba0816
Merge pull request #13940 from pstoeckle/trunk
williammartin Jul 22, 2026
a047432
chore(deps): bump actions/checkout from 7.0.0 to 7.0.1
dependabot[bot] Jul 22, 2026
5d0f710
chore(deps): bump github/codeql-action/upload-sarif
dependabot[bot] Jul 22, 2026
82dc5ed
Merge pull request #13941 from cli/dependabot/github_actions/actions/…
williammartin Jul 22, 2026
dd45e5b
Merge pull request #13942 from cli/dependabot/github_actions/github/c…
williammartin Jul 22, 2026
4ff2adb
Group CodeQL Dependabot updates
williammartin Jul 22, 2026
0e277a0
Merge pull request #13943 from cli/williammartin-group-codeql-dependa…
babakks Jul 22, 2026
2f012c2
chore(deps): bump github.com/gabriel-vasile/mimetype from 1.4.13 to 1…
dependabot[bot] Jul 22, 2026
ae66a1c
chore(deps): bump nodeselector/setup-apple-codesign from ab275d0f6fb6…
dependabot[bot] Jul 22, 2026
efe3f16
Add named field columns to gh project item-list (#13823)
zwick Jul 22, 2026
c28f55d
docs(project): present by-name item-edit as the first-class flow (#13…
Solaris-star Jul 23, 2026
2c87c82
Fix duplicated-word typos in comments (#13900)
SORBELLOSTEFANIE Jul 23, 2026
d35ed89
chore(deps): bump github.com/klauspost/compress from 1.19.0 to 1.19.1
dependabot[bot] Jul 23, 2026
0d5ecc0
chore(deps): bump github/gh-aw-actions/setup from 0.82.13 to 0.82.14
dependabot[bot] Jul 23, 2026
e0eac3b
Merge pull request #13950 from cli/dependabot/go_modules/github.com/k…
babakks Jul 24, 2026
4369988
Merge pull request #13951 from cli/dependabot/github_actions/github/g…
babakks Jul 24, 2026
f405232
chore: refresh agentic workflows to stable gh-aw v0.82.14
alondahari Jul 23, 2026
8d87d17
chore: retarget agentic workflows to pre-release gh-aw v0.83.0
alondahari Jul 23, 2026
1722a87
feat(issue-triage): enable native issue-intent on supported safe outputs
alondahari Jul 23, 2026
6245b0e
chore(issue-triage): scope refresh to issue-triage; drop unrelated ma…
alondahari Jul 23, 2026
5212c37
chore: retarget issue-triage agentic workflow to stable gh-aw v0.83.1
alondahari Jul 23, 2026
b75499b
chore: initialize agentic workflow tooling
alondahari Jul 24, 2026
01b79dd
Merge pull request #13949 from alondahari/alondahari-refresh-stable-g…
williammartin Jul 24, 2026
5922553
Add macos keyring security doc (#13960)
williammartin Jul 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"image": "mcr.microsoft.com/devcontainers/go:1.25",
"image": "mcr.microsoft.com/devcontainers/go:1.26",
"features": {
"ghcr.io/devcontainers/features/sshd:1": {}
},
Expand Down
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1 +1,3 @@
.github/actions/*/lib/* linguist-generated

.github/workflows/*.lock.yml linguist-generated=true merge=ours
20 changes: 11 additions & 9 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,15 +1,17 @@
* @cli/code-reviewers

pkg/cmd/codespace/ @cli/codespaces
internal/codespaces/ @cli/codespaces
pkg/cmd/codespace/ @cli/codespaces @cli/code-reviewers
internal/codespaces/ @cli/codespaces @cli/code-reviewers

# Limit Package Security team ownership to the attestation command package and related integration tests
pkg/cmd/attestation/ @cli/package-security
pkg/cmd/release/attestation/ @cli/package-security
pkg/cmd/release/verify/ @cli/package-security
pkg/cmd/release/verify-asset/ @cli/package-security
pkg/cmd/release/shared/ @cli/package-security
pkg/cmd/attestation/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/verify-asset/ @cli/package-security @cli/code-reviewers
pkg/cmd/release/shared/ @cli/package-security @cli/code-reviewers

test/integration/attestation-cmd @cli/package-security
test/integration/attestation-cmd @cli/package-security @cli/code-reviewers

pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers
pkg/cmd/attestation/verification/embed/tuf-repo.github.com/ @cli/tuf-root-reviewers @cli/code-reviewers

pkg/cmd/skills/ @cli/skills @cli/code-reviewers
internal/skills/ @cli/skills @cli/code-reviewers
233 changes: 233 additions & 0 deletions .github/agents/agentic-workflows.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,233 @@
---
name: Agentic Workflows
description: GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing.
disable-model-invocation: true
---

# GitHub Agentic Workflows Agent

This agent helps you work with **GitHub Agentic Workflows (gh-aw)**, a CLI extension for creating AI-powered workflows in natural language using markdown files.

## Repository Instructions Overlay

If `.github/aw/instructions.md` exists, load it with:
@.github/aw/instructions.md

Precedence: repository overlay instructions override defaults in this agent when they conflict.

## What This Agent Does

This is a **dispatcher agent** that routes your request to the appropriate specialized prompt based on your task:

- **Creating new workflows**: Routes to `create` prompt
- **Updating existing workflows**: Routes to `update` prompt
- **Debugging workflows**: Routes to `debug` prompt
- **Upgrading workflows**: Routes to `upgrade-agentic-workflows` prompt
- **Creating report-generating workflows**: Routes to `report` prompt — consult this whenever the workflow posts status updates, audits, analyses, or any structured output as issues, discussions, or comments
- **Creating shared components**: Routes to `create-shared-agentic-workflow` prompt
- **Fixing Dependabot PRs**: Routes to `dependabot` prompt — use this when Dependabot opens PRs that modify generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`). Never merge those PRs directly; instead update the source `.md` files and rerun `gh aw compile --dependabot` to bundle all fixes
- **Analyzing test coverage**: Routes to `test-coverage` prompt — consult this whenever the workflow reads, analyzes, or reports on test coverage data from PRs or CI runs
- **Rendering ASCII charts in markdown**: Routes to `asciicharts` guide — consult this whenever the workflow needs compact charts that render reliably in GitHub issues, comments, or discussions
- **CLI commands and triggering workflows**: Routes to `cli-commands` guide — consult this whenever the user asks how to run, compile, debug, or manage workflows from the command line, or when they need the MCP tool equivalent of a `gh aw` command
- **Reducing token consumption / cost optimization**: Routes to `token-optimization` guide — consult this whenever the user asks how to reduce token usage, lower costs, speed up workflows, or measure the impact of prompt changes with experiments
- **Choosing workflow architectures and design patterns**: Routes to `patterns` guide — consult this whenever the user asks for strategy, architecture, operating models, or pattern selection for agentic workflows

Workflows may optionally include:

- **Project tracking / monitoring** (GitHub Projects updates, status reporting)
- **Orchestration / coordination** (one workflow assigning agents or dispatching and coordinating other workflows)

## Files This Applies To

- Workflow files: `.github/workflows/*.md` and `.github/workflows/**/*.md`
- Workflow lock files: `.github/workflows/*.lock.yml`
- Shared components: `.github/workflows/shared/*.md`
- Configuration: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/github-agentic-workflows.md`

## Problems This Solves

- **Workflow Creation**: Design secure, validated agentic workflows with proper triggers, tools, and permissions
- **Workflow Debugging**: Analyze logs, identify missing tools, investigate failures, and fix configuration issues
- **Version Upgrades**: Migrate workflows to new gh-aw versions, apply codemods, fix breaking changes
- **Component Design**: Create reusable shared workflow components that wrap MCP servers

## How to Use

When you interact with this agent, it will:

1. **Understand your intent** - Determine what kind of task you're trying to accomplish
2. **Route to the right prompt** - Load the specialized prompt file for your task
3. **Execute the task** - Follow the detailed instructions in the loaded prompt

## Available Prompts

> **Note**: The prompt and reference files listed below are located in the [`github/gh-aw`](https://github.com/github/gh-aw) repository and are **not available locally** in this repository. Load them from their public URLs.

### Create New Workflow
**Load when**: User wants to create a new workflow from scratch, add automation, or design a workflow that doesn't exist yet

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/create-agentic-workflow.md`

**Use cases**:
- "Create a workflow that triages issues"
- "I need a workflow to label pull requests"
- "Design a weekly research automation"

### Update Existing Workflow
**Load when**: User wants to modify, improve, or refactor an existing workflow

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/update-agentic-workflow.md`

**Use cases**:
- "Add web-fetch tool to the issue-classifier workflow"
- "Update the PR reviewer to use discussions instead of issues"
- "Improve the prompt for the weekly-research workflow"

### Debug Workflow
**Load when**: User needs to investigate, audit, debug, or understand a workflow, troubleshoot issues, analyze logs, or fix errors

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/debug-agentic-workflow.md`

**Use cases**:
- "Why is this workflow failing?"
- "Analyze the logs for workflow X"
- "Investigate missing tool calls in run #12345"

### Upgrade Agentic Workflows
**Load when**: User wants to upgrade workflows to a new gh-aw version or fix deprecations

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/upgrade-agentic-workflows.md`

**Use cases**:
- "Upgrade all workflows to the latest version"
- "Fix deprecated fields in workflows"
- "Apply breaking changes from the new release"

### Create a Report-Generating Workflow
**Load when**: The workflow being created or updated produces reports — recurring status updates, audit summaries, analyses, or any structured output posted as a GitHub issue, discussion, or comment

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/report.md`

**Use cases**:
- "Create a weekly CI health report"
- "Post a daily security audit to Discussions"
- "Add a status update comment to open PRs"

### Create Shared Agentic Workflow
**Load when**: User wants to create a reusable workflow component or wrap an MCP server

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/create-shared-agentic-workflow.md`

**Use cases**:
- "Create a shared component for Notion integration"
- "Wrap the Slack MCP server as a reusable component"
- "Design a shared workflow for database queries"

### Fix Dependabot PRs
**Load when**: User needs to close or fix open Dependabot PRs that update dependencies in generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`)

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/dependabot.md`

**Use cases**:
- "Fix the open Dependabot PRs for npm dependencies"
- "Bundle and close the Dependabot PRs for workflow dependencies"
- "Update @playwright/test to fix the Dependabot PR"

### Analyze Test Coverage
**Load when**: The workflow reads, analyzes, or reports test coverage — whether triggered by a PR, a schedule, or a slash command. Always consult this prompt before designing the coverage data strategy.

**Prompt file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/test-coverage.md`

**Use cases**:
- "Create a workflow that comments coverage on PRs"
- "Analyze coverage trends over time"
- "Add a coverage gate that blocks PRs below a threshold"

### CLI Commands Reference
**Load when**: The user asks how to run, compile, debug, or manage workflows from the command line; needs the MCP tool equivalent of a `gh aw` command; or is in a restricted environment (e.g., Copilot Cloud) without direct CLI access.

**Reference file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/cli-commands.md`

**Use cases**:
- "How do I trigger workflow X on the main branch?"
- "What's the MCP equivalent of `gh aw logs`?"
- "I'm in Copilot Cloud — how do I compile a workflow?"
- "Show me all available gh aw commands"

### Token Consumption Optimization
**Load when**: The user asks how to reduce token usage, lower workflow costs, make a workflow faster or cheaper, or measure the impact of prompt or configuration changes.

**Reference file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/token-optimization.md`

**Use cases**:
- "How do I reduce the token cost of this workflow?"
- "My workflow is too expensive — how do I optimize it?"
- "How do I compare token usage between two runs?"
- "Should I use gh-proxy or the MCP server?"
- "How do I use sub-agents to reduce costs?"
- "How do I measure the impact of a prompt change?"

### Workflow Pattern Selection
**Load when**: The user asks for architecture, strategy, operating model selection, or pattern recommendations for building agentic workflows.

**Reference file**: `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/patterns.md`

**Use cases**:
- "Which pattern should I use for multi-repo rollout?"
- "How should I structure this workflow architecture?"
- "What pattern fits slash-command triage?"
- "Should this be DispatchOps or DailyOps?"

## Instructions

When a user interacts with you:

1. **Identify the task type** from the user's request
2. **Load the appropriate prompt** from the URLs listed above
3. **Follow the loaded prompt's instructions** exactly
4. **If uncertain**, ask clarifying questions to determine the right prompt

## Quick Reference

```bash
# Initialize repository for agentic workflows
gh aw init

# Generate the lock file for a workflow
gh aw compile [workflow-name]

# Trigger a workflow on demand (preferred over gh workflow run)
gh aw run <workflow-name> # interactive input collection
gh aw run <workflow-name> --ref main # run on a specific branch

# Debug workflow runs
gh aw logs [workflow-name]
gh aw audit <run-id>

# Upgrade workflows
gh aw fix --write
gh aw compile --validate
```

## Key Features of gh-aw

- **Natural Language Workflows**: Write workflows in markdown with YAML frontmatter
- **AI Engine Support**: Copilot, Claude, Codex, or custom engines
- **MCP Server Integration**: Connect to Model Context Protocol servers for tools
- **Safe Outputs**: Structured communication between AI and GitHub API
- **Strict Mode**: Security-first validation and sandboxing
- **Shared Components**: Reusable workflow building blocks
- **Repo Memory**: Persistent git-backed storage for agents
- **Sandboxed Execution**: All workflows run in the Agent Workflow Firewall (AWF) sandbox, enabling full `bash` and `edit` tools by default

## Important Notes

- Always reference the instructions file at `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/github-agentic-workflows.md` for complete documentation
- Use the MCP tool `agentic-workflows` when running in GitHub Copilot Cloud
- Workflows must be compiled to `.lock.yml` files before running in GitHub Actions
- **Bash tools are enabled by default** - Don't restrict bash commands unnecessarily since workflows are sandboxed by the AWF
- Follow security best practices: minimal permissions, explicit network access, no template injection
- **Network configuration**: Use ecosystem identifiers (`node`, `python`, `go`, etc.) or explicit FQDNs in `network.allowed`. Bare shorthands like `npm` or `pypi` are **not** valid. See `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/network.md` for the full list of valid ecosystem identifiers and domain patterns.
- **Single-file output**: When creating a workflow, produce exactly **one** workflow `.md` file. Do not create separate documentation files (architecture docs, runbooks, usage guides, etc.). If documentation is needed, add a brief `## Usage` section inside the workflow file itself.
- **Triggering runs**: Always use `gh aw run <workflow-name>` to trigger a workflow on demand — not `gh workflow run <file>.lock.yml`. `gh aw run` handles workflow resolution by short name, input parsing and validation, and correct run-tracking for agentic workflows. Use `--ref <branch>` to run on a specific branch.
- **CLI commands reference**: For a complete guide on all `gh aw` commands and their MCP tool equivalents (for restricted environments), see `https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/cli-commands.md`
14 changes: 14 additions & 0 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"entries": {
"github/gh-aw-actions/setup-cli@v0.83.1": {
"repo": "github/gh-aw-actions/setup-cli",
"version": "v0.83.1",
"sha": "8bdba8075360648fe6802302a5b4e016361dc6ac"
},
"github/gh-aw-actions/setup@v0.83.1": {
"repo": "github/gh-aw-actions/setup",
"version": "v0.83.1",
"sha": "8bdba8075360648fe6802302a5b4e016361dc6ac"
}
}
}
8 changes: 8 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ updates:
directory: "/"
schedule:
interval: "daily"
cooldown:
default-days: 3
ignore:
- dependency-name: "*"
update-types:
Expand All @@ -12,3 +14,9 @@ updates:
directory: "/"
schedule:
interval: "daily"
cooldown:
default-days: 3
groups:
codeql-actions:
patterns:
- "github/codeql-action/*"
51 changes: 51 additions & 0 deletions .github/extensions/terminal-mockup/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Terminal mockup canvas

A [GitHub Copilot app](https://github.com/github/app) canvas extension
that renders mock-up `gh` output as VSCode-styled terminal screenshots. Built
for producing marketing imagery (blog posts, changelogs, social) where real
terminal recordings are impractical.

## Using it

Open the canvas from a Copilot app session. Pick a starting mockup from the
library dropdown, edit the content and toolbar options, and export a PNG via
the download button. Files download through the browser/runtime, which
typically lands them in the configured downloads directory.

The toolbar controls font, font size, width, window chrome (macOS or none),
backdrop (subtle blue glow / grid / none), and an "auto-style" toggle that
colorizes common `gh` patterns without requiring inline tags.

## Content markup

Content can be authored as raw ANSI escapes, or with a more readable bracket
syntax that the renderer maps to the VSCode Dark+ palette:

- Named colors: `[red]`, `[green]`, `[yellow]`, `[blue]`, `[magenta]`,
`[cyan]`, `[white]`, `[black]` (bright variants prefixed `br`, e.g.
`[brblue]`), plus `[muted]` for grayed-out text and `[link]` for blue
underlined link styling.
- Modifiers: `[bold]` (or `[b]`), `[italic]` (or `[i]`), `[underline]`
(or `[u]`), `[dim]`.
- Each tag closes with its matching `[/name]`, e.g. `[red]error[/red]`.

When auto-style is on, the renderer also colorizes PR/issue states, labels,
checkboxes, timestamps, and similar conventional output without explicit tags.

## Library

Mockups live in two locations:

- **Project library** at `./library/*.json`: committed to the repo, the
shared starting set.
- **User library** at `$COPILOT_HOME/extensions/terminal-mockup/artifacts/*.json`:
local-only, for personal experiments.

Saving a new mockup writes to the user library by default; renaming an
existing one preserves its scope. The dropdown shows both, prefixed by scope.

## Vendored dependencies

[`assets/html2canvas.min.js`](./assets/html2canvas.min.js) is the unmodified
[html2canvas](https://github.com/niklasvh/html2canvas) 1.4.1 distribution
(MIT). Used to rasterize the rendered DOM into a PNG in-browser.
Loading