Skip to content

Upgrade agentic workflows to gh-aw v0.89.21 - #69568

Merged
DeagleGross merged 3 commits into
dotnet:mainfrom
DeagleGross:deaglegross-upgrade-gh-aw-v0-89-21
Sep 28, 2026
Merged

DeagleGross merged 3 commits into
dotnet:mainfrom
DeagleGross:deaglegross-upgrade-gh-aw-v0-89-21

Conversation

@DeagleGross

@DeagleGross DeagleGross commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Summary

Upgrade all ASP.NET Core agentic workflows to stable gh-aw v0.89.21 (not prerelease v0.89.22) using the supported gh aw upgrade flow and recompile with the established dotnet/aspnetcore schedule seed.

This includes the same-organization fork fix from github/gh-aw#62720 for github/gh-aw#62680. The failed production run https://github.com/dotnet/aspnetcore/actions/runs/35735631578/job/106776284741 pushed signed commit 629e6a5c1f1220a3754840d640269b83021b4e52 to dotnet/AspNetCore.Docs.Automation:docs/aspnetcore-pr-68648, but the v0.88.7 compiled handler omitted the REST head_repo field and GitHub rejected the PR head.

Version update

  • Previous repository state: action setup v0.89.17, with generated workflows mixed between v0.89.17 and v0.88.7 (pr-docs-check)
  • New state: action setup and all generated workflows at stable v0.89.21
  • Setup action SHA: 924af5fdc64061cfbf66fb584c8b07e2ac230c60

The v0.89.21 create_or_update_pull_request.cjs request includes head_repo when the configured head repository differs from the target repository. pr-docs-check retains target dotnet/AspNetCore.Docs, head dotnet/AspNetCore.Docs.Automation, and the separate head GitHub App token.

safe-outputs.create-pull-request also enables both preserve-branch-name: true and recreate-ref: true. When no trusted matching PR exists but the deterministic branch is left behind by a failed run, the v0.89.21 handler deletes the existing unprotected remote ref and recreates it from the new signed output before opening the cross-repository PR. Existing matching PRs continue through the trusted update/push path instead of create_pull_request.

Regenerated workflows

  • browsertesting-deps-update
  • community-pr-issue-check
  • cswin32-update
  • issue-triage-agent
  • pr-attention-pulse
  • pr-docs-check
  • pull-request-review
  • test-quarantine

The v0.89.21 compiler also generated agentics-maintenance-dotnet-AspNetCore.Docs.yml.

Source workflow changes

  • pr-attention-pulse.md: the steps-run-secrets-to-env codemod moves direct ${{ runner.temp }} interpolation from PowerShell commands into step-level environment bindings for strict-mode compatibility. Pulse source comments and focused contract tests now describe and verify the v0.89.21 output rather than hard-coding v0.88.7. The suite derives the compiler version from lock metadata and the setup SHA/version from .github/aw/actions-lock.json, while continuing to lock down reviewed behavior such as the AWF v0.28.23 runtime, effective shell allowlist, credential exclusions, model policy, inaccessible conclusion job, and private validator cleanup.
  • pull-request-review.md and test-quarantine.md: gh aw upgrade normalized partial action tags (@v9, @v7, @v8) to full release tags (@v9.0.0, @v7.0.1, @v8.0.1). These normalizations are not required for v0.89.21 compilation—the previous source forms compile successfully—but they are legitimate canonical output from the supported upgrade flow and avoid the same normalization recurring on the next upgrade. They do not change the resolved action SHAs in the generated locks.

Recommendation: retain these small normalization changes in this repository-wide upgrade rather than partially undoing supported gh aw upgrade output.

Validation

  • pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PRAttentionPulse.ps1: passed the complete focused Pulse regression suite, including 82 snapshot cases and 91 local snapshot-retrieval cases
  • python -m unittest discover -s .github/workflows/pr-docs-check -p "test_*.py" -v: 32 passed, including source and compiled assertions for preserve-branch-name and recreate-ref
  • gh aw compile --schedule-seed dotnet/aspnetcore --strict --show-all --verbose: 8/8 compiled
  • gh aw compile --schedule-seed dotnet/aspnetcore --actionlint --show-all: 8/8 compiled; actionlint found 0 issues
  • git diff --check: passed

Warnings remain and are not treated as clean validation: the compiler reports the existing experimental rate-limiting feature, recommends the dotnet ecosystem identifier instead of *.vsblob.vsassets.io, and emits informational schema-validation-skipped notices. A separate --validate run reaches 7/8 workflows, then the generic GitHub Actions schema rejects the established gh-aw pull_request.names/pull_request.forks source filters in community-pr-issue-check; the generated lock workflow is accepted by actionlint.

Post-merge rerun

Start a new workflow_dispatch after merge. Rerunning run 35735631578 would reuse its old compiled v0.88.7 workflow and would not test this fix.

No manual deletion of dotnet/AspNetCore.Docs.Automation:docs/aspnetcore-pr-68648 is required. The new dispatch will safely recreate that unprotected orphan branch through the dedicated head-repository token when no matching docs PR exists. This PR does not directly mutate either documentation repository.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 28, 2026 09:41
@DeagleGross
DeagleGross requested review from a team and wtgodbe as code owners September 28, 2026 09:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Update the pulse regression suite and add the newly required lock cache entries.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Upgrades ASP.NET Core agentic workflows to stable gh-aw v0.89.21 and regenerates their pinned artifacts.

Changes:

  • Updates gh-aw actions, containers, and workflow locks.
  • Adds the Docs maintenance workflow.
  • Normalizes action versions and runner environment handling.
File Description
.github/​workflows/​test-quarantine.md Normalizes action versions.
.github/​workflows/​test-quarantine.lock.yml Regenerates the pinned workflow.
.github/​workflows/​pull-request-review.md Normalizes the GitHub Script action version.
.github/​workflows/​pull-request-review.lock.yml Regenerates the pinned workflow.
.github/​workflows/​pr-attention-pulse.md Updates runner environment bindings.
.github/​workflows/​pr-attention-pulse.lock.yml Regenerates the pinned workflow.
.github/​workflows/​agentics-maintenance-dotnet-AspNetCore.Docs.yml Adds Docs maintenance automation.
.github/​aw/​actions-lock.json Updates action and container lock metadata.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/pr-attention-pulse.lock.yml
DeagleGross and others added 2 commits September 28, 2026 11:57
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@DeagleGross
DeagleGross merged commit 368afe8 into dotnet:main Sep 28, 2026
13 checks passed
@DeagleGross
DeagleGross deleted the deaglegross-upgrade-gh-aw-v0-89-21 branch September 28, 2026 10:30
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants