Repository navigation
Upgrade agentic workflows to gh-aw v0.89.21 - #69568
Merged
DeagleGross merged 3 commits intoSep 28, 2026
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Update the pulse regression suite and add the newly required lock cache entries.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Upgrades ASP.NET Core agentic workflows to stable gh-aw v0.89.21 and regenerates their pinned artifacts.
Changes:
- Updates gh-aw actions, containers, and workflow locks.
- Adds the Docs maintenance workflow.
- Normalizes action versions and runner environment handling.
| File | Description |
|---|---|
.github/workflows/test-quarantine.md |
Normalizes action versions. |
.github/workflows/test-quarantine.lock.yml |
Regenerates the pinned workflow. |
.github/workflows/pull-request-review.md |
Normalizes the GitHub Script action version. |
.github/workflows/pull-request-review.lock.yml |
Regenerates the pinned workflow. |
.github/workflows/pr-attention-pulse.md |
Updates runner environment bindings. |
.github/workflows/pr-attention-pulse.lock.yml |
Regenerates the pinned workflow. |
.github/workflows/agentics-maintenance-dotnet-AspNetCore.Docs.yml |
Adds Docs maintenance automation. |
.github/aw/actions-lock.json |
Updates action and container lock metadata. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
javiercn
approved these changes
Sep 28, 2026
4 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Upgrade all ASP.NET Core agentic workflows to stable gh-aw v0.89.21 (not prerelease v0.89.22) using the supported
gh aw upgradeflow and recompile with the establisheddotnet/aspnetcoreschedule seed.This includes the same-organization fork fix from github/gh-aw#62720 for github/gh-aw#62680. The failed production run https://github.com/dotnet/aspnetcore/actions/runs/35735631578/job/106776284741 pushed signed commit
629e6a5c1f1220a3754840d640269b83021b4e52todotnet/AspNetCore.Docs.Automation:docs/aspnetcore-pr-68648, but the v0.88.7 compiled handler omitted the RESThead_repofield and GitHub rejected the PR head.Version update
pr-docs-check)924af5fdc64061cfbf66fb584c8b07e2ac230c60The v0.89.21
create_or_update_pull_request.cjsrequest includeshead_repowhen the configured head repository differs from the target repository.pr-docs-checkretains targetdotnet/AspNetCore.Docs, headdotnet/AspNetCore.Docs.Automation, and the separate head GitHub App token.safe-outputs.create-pull-requestalso enables bothpreserve-branch-name: trueandrecreate-ref: true. When no trusted matching PR exists but the deterministic branch is left behind by a failed run, the v0.89.21 handler deletes the existing unprotected remote ref and recreates it from the new signed output before opening the cross-repository PR. Existing matching PRs continue through the trusted update/push path instead ofcreate_pull_request.Regenerated workflows
browsertesting-deps-updatecommunity-pr-issue-checkcswin32-updateissue-triage-agentpr-attention-pulsepr-docs-checkpull-request-reviewtest-quarantineThe v0.89.21 compiler also generated
agentics-maintenance-dotnet-AspNetCore.Docs.yml.Source workflow changes
pr-attention-pulse.md: thesteps-run-secrets-to-envcodemod moves direct${{ runner.temp }}interpolation from PowerShell commands into step-level environment bindings for strict-mode compatibility. Pulse source comments and focused contract tests now describe and verify the v0.89.21 output rather than hard-coding v0.88.7. The suite derives the compiler version from lock metadata and the setup SHA/version from.github/aw/actions-lock.json, while continuing to lock down reviewed behavior such as the AWF v0.28.23 runtime, effective shell allowlist, credential exclusions, model policy, inaccessible conclusion job, and private validator cleanup.pull-request-review.mdandtest-quarantine.md:gh aw upgradenormalized partial action tags (@v9,@v7,@v8) to full release tags (@v9.0.0,@v7.0.1,@v8.0.1). These normalizations are not required for v0.89.21 compilation—the previous source forms compile successfully—but they are legitimate canonical output from the supported upgrade flow and avoid the same normalization recurring on the next upgrade. They do not change the resolved action SHAs in the generated locks.Recommendation: retain these small normalization changes in this repository-wide upgrade rather than partially undoing supported
gh aw upgradeoutput.Validation
pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PRAttentionPulse.ps1: passed the complete focused Pulse regression suite, including 82 snapshot cases and 91 local snapshot-retrieval casespython -m unittest discover -s .github/workflows/pr-docs-check -p "test_*.py" -v: 32 passed, including source and compiled assertions forpreserve-branch-nameandrecreate-refgh aw compile --schedule-seed dotnet/aspnetcore --strict --show-all --verbose: 8/8 compiledgh aw compile --schedule-seed dotnet/aspnetcore --actionlint --show-all: 8/8 compiled; actionlint found 0 issuesgit diff --check: passedWarnings remain and are not treated as clean validation: the compiler reports the existing experimental rate-limiting feature, recommends the
dotnetecosystem identifier instead of*.vsblob.vsassets.io, and emits informational schema-validation-skipped notices. A separate--validaterun reaches 7/8 workflows, then the generic GitHub Actions schema rejects the established gh-awpull_request.names/pull_request.forkssource filters incommunity-pr-issue-check; the generated lock workflow is accepted by actionlint.Post-merge rerun
Start a new
workflow_dispatchafter merge. Rerunning run35735631578would reuse its old compiled v0.88.7 workflow and would not test this fix.No manual deletion of
dotnet/AspNetCore.Docs.Automation:docs/aspnetcore-pr-68648is required. The new dispatch will safely recreate that unprotected orphan branch through the dedicated head-repository token when no matching docs PR exists. This PR does not directly mutate either documentation repository.