From 6b5d0f02f250b4371de469e3ae8a67eebdedf87a Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 6 Aug 2026 14:03:55 +0000 Subject: [PATCH 1/4] Initial plan From 068a66cff3f1df9b8e7d44b08711d08b50afde42 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 6 Aug 2026 14:13:31 +0000 Subject: [PATCH 2/4] Publish shareable AI moderator workflow Co-authored-by: salmanmkc <32169182+salmanmkc@users.noreply.github.com> --- .github/workflows/ai-moderator.lock.yml | 2 +- .github/workflows/ai-moderator.md | 1 - pkg/cli/add_private_test.go | 15 +++++++++++++++ 3 files changed, 16 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index e3626606fa9..2c4a4541374 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -1,4 +1,4 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"5357ba23b10bc1dd4acc8cbb59fdc9176dc8fddc798b574768c81a37369806aa","body_hash":"0f33a663fa498bde06e781b4c528eb50b425c942da80eb99082f174f0c7b6644","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.146.0"}} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ee03837be0ae8a30b4ae8b9cc4bbd2d97c071d538e3d10b0ea7f8a9d481b006d","body_hash":"0f33a663fa498bde06e781b4c528eb50b425c942da80eb99082f174f0c7b6644","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.146.0"}} # gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions/cache","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44","digest":"sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44@sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44","digest":"sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44","digest":"sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44","digest":"sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.8","digest":"sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.8@sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196","pinned_image":"ghcr.io/github/gh-aw-node@sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196"},{"image":"ghcr.io/github/github-mcp-server:v1.8.0","digest":"sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520","pinned_image":"ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520"}],"has_pull_request":true} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # diff --git a/.github/workflows/ai-moderator.md b/.github/workflows/ai-moderator.md index 8005a41d207..d988cc00bde 100644 --- a/.github/workflows/ai-moderator.md +++ b/.github/workflows/ai-moderator.md @@ -1,5 +1,4 @@ --- -private: true emoji: "🤖" timeout-minutes: 5 on: diff --git a/pkg/cli/add_private_test.go b/pkg/cli/add_private_test.go index 794e2d43518..fffef7686c7 100644 --- a/pkg/cli/add_private_test.go +++ b/pkg/cli/add_private_test.go @@ -3,6 +3,8 @@ package cli import ( + "os" + "path/filepath" "testing" ) @@ -63,3 +65,16 @@ on: push }) } } + +func TestAIModeratorWorkflowIsShareable(t *testing.T) { + t.Parallel() + + content, err := os.ReadFile(filepath.Join("..", "..", ".github", "workflows", "ai-moderator.md")) + if err != nil { + t.Fatalf("failed to read AI Moderator workflow: %v", err) + } + + if ExtractWorkflowPrivate(string(content)) { + t.Fatal("AI Moderator workflow must remain shareable for gh aw add") + } +} From d60abd493475cd2db6439c58a749fa7409cd056c Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 6 Aug 2026 15:01:46 +0000 Subject: [PATCH 3/4] Keep AI moderator private with redirect Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ai-moderator.lock.yml | 4 ++-- .github/workflows/ai-moderator.md | 2 ++ pkg/cli/add_private_test.go | 15 ++++++++++++--- 3 files changed, 16 insertions(+), 5 deletions(-) diff --git a/.github/workflows/ai-moderator.lock.yml b/.github/workflows/ai-moderator.lock.yml index 2c4a4541374..7b00a3b3e12 100644 --- a/.github/workflows/ai-moderator.lock.yml +++ b/.github/workflows/ai-moderator.lock.yml @@ -1,5 +1,5 @@ -# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"ee03837be0ae8a30b4ae8b9cc4bbd2d97c071d538e3d10b0ea7f8a9d481b006d","body_hash":"0f33a663fa498bde06e781b4c528eb50b425c942da80eb99082f174f0c7b6644","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.146.0"}} -# gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions/cache","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44","digest":"sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44@sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44","digest":"sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44","digest":"sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44","digest":"sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.8","digest":"sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.8@sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196","pinned_image":"ghcr.io/github/gh-aw-node@sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196"},{"image":"ghcr.io/github/github-mcp-server:v1.8.0","digest":"sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520","pinned_image":"ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520"}],"has_pull_request":true} +# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"9815b716cd9af874384b92129266197fd226cd7368a9686df0cb2b9b9b8bc470","body_hash":"0f33a663fa498bde06e781b4c528eb50b425c942da80eb99082f174f0c7b6644","strict":true,"agent_id":"codex","engine_versions":{"codex":"0.146.0"}} +# gh-aw-manifest: {"version":1,"secrets":["CODEX_API_KEY","COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GH_AW_OTEL_GRAFANA_AUTHORIZATION","GH_AW_OTEL_GRAFANA_ENDPOINT","GH_AW_OTEL_SENTRY_AUTHORIZATION","GH_AW_OTEL_SENTRY_ENDPOINT","GITHUB_TOKEN","OPENAI_API_KEY"],"actions":[{"repo":"actions/cache","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/restore","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/cache/save","sha":"55cc8345863c7cc4c66a329aec7e433d2d1c52a9","version":"v6.1.0"},{"repo":"actions/checkout","sha":"3d3c42e5aac5ba805825da76410c181273ba90b1","version":"v7.0.1"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"820762786026740c76f36085b0efc47a31fe5020","version":"v7.0.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44","digest":"sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4","pinned_image":"ghcr.io/github/gh-aw-firewall/agent:0.27.44@sha256:0d727725c737b58c7bdf51f640cffb928385ec46517e0917c7f1a02f1bada8b4"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44","digest":"sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7","pinned_image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.27.44@sha256:b50fbadba138f6e9aba94aca09711335c489bb3b15861220cb66f6092e042dc7"},{"image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44","digest":"sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff","pinned_image":"ghcr.io/github/gh-aw-firewall/cli-proxy:0.27.44@sha256:c064d15974f7c933ec7d3f7b4038f4fd203547b3154bdc821afd379144887eff"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44","digest":"sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627","pinned_image":"ghcr.io/github/gh-aw-firewall/squid:0.27.44@sha256:83e48bbe12c634be8c228a576832fe45f66c529ac3659db92bddbcf2eeb6d627"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.4.8","digest":"sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8","pinned_image":"ghcr.io/github/gh-aw-mcpg:v0.4.8@sha256:38bbea36cdb46a3c9d04d1db05e672966f5239b431a2022eb35881688e5721d8"},{"image":"ghcr.io/github/gh-aw-node","digest":"sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196","pinned_image":"ghcr.io/github/gh-aw-node@sha256:0d9f1fb5fd6610c0ac1f5194a38e45a8a1e81f8a390d5142d8e4e6f26a4b3196"},{"image":"ghcr.io/github/github-mcp-server:v1.8.0","digest":"sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520","pinned_image":"ghcr.io/github/github-mcp-server:v1.8.0@sha256:d5a18c04b92714c309eb46a2305087e91a4dbd80420f6e462656699f95093520"}],"redirect":"githubnext/agentics/workflows/ai-moderator.md@main","has_pull_request":true} # This file was automatically generated by gh-aw. DO NOT EDIT. To debug this workflow, load the skill at https://github.com/github/gh-aw/blob/main/debug.md # # ___ _ _ diff --git a/.github/workflows/ai-moderator.md b/.github/workflows/ai-moderator.md index d988cc00bde..57b7e41994d 100644 --- a/.github/workflows/ai-moderator.md +++ b/.github/workflows/ai-moderator.md @@ -1,4 +1,6 @@ --- +private: true +redirect: "githubnext/agentics/workflows/ai-moderator.md@main" emoji: "🤖" timeout-minutes: 5 on: diff --git a/pkg/cli/add_private_test.go b/pkg/cli/add_private_test.go index fffef7686c7..e1d46fc07ae 100644 --- a/pkg/cli/add_private_test.go +++ b/pkg/cli/add_private_test.go @@ -66,7 +66,7 @@ on: push } } -func TestAIModeratorWorkflowIsShareable(t *testing.T) { +func TestAIModeratorWorkflowIsPrivateRedirect(t *testing.T) { t.Parallel() content, err := os.ReadFile(filepath.Join("..", "..", ".github", "workflows", "ai-moderator.md")) @@ -74,7 +74,16 @@ func TestAIModeratorWorkflowIsShareable(t *testing.T) { t.Fatalf("failed to read AI Moderator workflow: %v", err) } - if ExtractWorkflowPrivate(string(content)) { - t.Fatal("AI Moderator workflow must remain shareable for gh aw add") + contentStr := string(content) + if !ExtractWorkflowPrivate(contentStr) { + t.Fatal("AI Moderator workflow must remain private") + } + + redirect, err := extractRedirectFromContent(contentStr) + if err != nil { + t.Fatalf("failed to extract AI Moderator redirect: %v", err) + } + if redirect != "githubnext/agentics/workflows/ai-moderator.md@main" { + t.Fatalf("AI Moderator redirect = %q, want %q", redirect, "githubnext/agentics/workflows/ai-moderator.md@main") } } From 0bbcb8c005d7a8f6213e416d8e98f77064595bf8 Mon Sep 17 00:00:00 2001 From: Peli de Halleux Date: Thu, 6 Aug 2026 08:09:36 -0700 Subject: [PATCH 4/4] Delete pkg/cli/add_private_test.go --- pkg/cli/add_private_test.go | 89 ------------------------------------- 1 file changed, 89 deletions(-) delete mode 100644 pkg/cli/add_private_test.go diff --git a/pkg/cli/add_private_test.go b/pkg/cli/add_private_test.go deleted file mode 100644 index e1d46fc07ae..00000000000 --- a/pkg/cli/add_private_test.go +++ /dev/null @@ -1,89 +0,0 @@ -//go:build !integration - -package cli - -import ( - "os" - "path/filepath" - "testing" -) - -// TestExtractWorkflowPrivate tests the ExtractWorkflowPrivate function -func TestExtractWorkflowPrivate(t *testing.T) { - t.Parallel() - tests := []struct { - name string - content string - expected bool - }{ - { - name: "workflow with private: true", - content: `--- -name: Test Workflow -private: true -on: push ---- - -# Test Workflow`, - expected: true, - }, - { - name: "workflow with private: false", - content: `--- -name: Test Workflow -private: false -on: push ---- - -# Test Workflow`, - expected: false, - }, - { - name: "workflow without private field", - content: `--- -name: Test Workflow -on: push ---- - -# Test Workflow`, - expected: false, - }, - { - name: "workflow without frontmatter", - content: "# Test Workflow\n\nThis is the workflow content.", - expected: false, - }, - } - - for _, tt := range tests { - t.Run(tt.name, func(t *testing.T) { - t.Parallel() - result := ExtractWorkflowPrivate(tt.content) - if result != tt.expected { - t.Errorf("ExtractWorkflowPrivate() = %v, want %v", result, tt.expected) - } - }) - } -} - -func TestAIModeratorWorkflowIsPrivateRedirect(t *testing.T) { - t.Parallel() - - content, err := os.ReadFile(filepath.Join("..", "..", ".github", "workflows", "ai-moderator.md")) - if err != nil { - t.Fatalf("failed to read AI Moderator workflow: %v", err) - } - - contentStr := string(content) - if !ExtractWorkflowPrivate(contentStr) { - t.Fatal("AI Moderator workflow must remain private") - } - - redirect, err := extractRedirectFromContent(contentStr) - if err != nil { - t.Fatalf("failed to extract AI Moderator redirect: %v", err) - } - if redirect != "githubnext/agentics/workflows/ai-moderator.md@main" { - t.Fatalf("AI Moderator redirect = %q, want %q", redirect, "githubnext/agentics/workflows/ai-moderator.md@main") - } -}