githubnext / githubnext/ado-aw

[deps-release-notes] awf — upstream release action items

Open
#2,028 10 comments 0 reactions 0 assignees View on GitHub
automation dependencies
Dominant language
Rust
Stars
23
Forks
8
Avg merge
4d 9h
Merged PRs (30d)
22

Description

# Rolling upstream release action items — `awf`

This is the **single canonical tracking issue** for action items arising from
new releases of the `awf` dependency. The `update-awf-version` workflow appends
a new comment to this issue for each version bump going forward, so **the most
recent activity lives in the comments below**. This body is a consolidated
history of everything filed so far.

**Latest pinned version covered:** `0.28.9`

## Consolidated history (earliest → latest)

### `0.25.48` → `0.25.60` (was #851)
- **OTel distributed tracing in api-proxy** ([v0.25.51](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.51)): api-proxy now emits OTel traces; ado-aw could expose config to help consumers use this.
- **ARC/DinD split-filesystem auto-detection** ([v0.25.52](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.52)): AWF auto-detects DinD split filesystem via sentinel probe; ado-aw docs may need updating.
- **Middle-power model fallback** ([v0.25.53](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.53)): api-proxy supports model fallback when primary is unavailable; ado-aw could expose this.
- **Anthropic WIF support** ([v0.25.58](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.58)): api-proxy supports Anthropic WIF schema fields + OIDC validation.
- **Pre-startup model validation via `requestedModel` config** ([v0.25.58](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.58)): api-proxy validates requested model before startup; ado-aw may wish to populate this field.

### `0.25.48` → `0.25.63` (was #859)
- **Security: proxy auth normalization hardened** ([v0.25.49](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.49)): Prevents malformed `Authorization` headers from reaching the upstream API.
- **Responses API cache reads in token usage rollups** ([v0.25.63](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.63)): Fixes under-reporting of cached token reads; improves `ado-aw audit` accuracy.

### `0.25.65` → `0.25.66` (was #902)
- **Azure/AWS/GCP OIDC support in Copilot adapter** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): api-proxy supports cloud OIDC credential injection; ado-aw could expose via `engine:`/`network:` front-matter.
- **Budget fields in `token-usage.jsonl`** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): `maxTurns` and budget fields now persisted; ado-aw audit module could surface these in `AuditData`.

### `0.25.65` → `0.25.68` (was #930)
- **`GITHUB_COPILOT_INTEGRATION_ID` forwarding fix** ([v0.25.67](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.67)): AWF now correctly forwards it as `COPILOT_INTEGRATION_ID` to the api-proxy.
- **PAT-safe integration ID + model name normalization** ([v0.25.68](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.68)): Regression fix from v0.25.67; normalizes legacy CAPI model names.

### `0.25.65` → `0.27.0` (was #950)
- **cli-proxy fail fast on DIFC unreachability** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): CLI proxy now errors immediately rather than hanging; verify DIFC proxy config before upgrade.

### `0.25.65` → `0.27.1` (was #970)
- **AI credits as OTEL span attributes** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): AWF emits AI credit consumption as OTel spans; `agent_stats.rs` + `audit` could surface these.
- **Redacted resolved config as audit artifact** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): `ado-aw audit` could expose for configuration diagnostics.
- **Opt-in diagnostics artifact for blocked LLM request bodies** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): ado-aw could surface via `ado-aw-debug:` flag.

### `0.25.65` → `0.27.2` (was #983)
- **Security: WIF/OIDC Anthropic auth regression** ([v0.27.2](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.2)): `ANTHROPIC_API_KEY` leaked to agent container when Squid blocked OIDC exchange; fixed in `0.27.2`.

### `0.25.65` → `0.27.3` (was #990)
- **OTLP fan-out to multiple endpoints** ([v0.27.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.3)): api-proxy can fan out telemetry to multiple OTLP endpoints simultaneously.

### `0.27.3` → `0.27.5` (was #1093)
- **Security: HTTPS-only for bare API proxy targets** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): Prevents over-broad HTTP allowlisting; verify no existing config relies on HTTP.
- **`allowedModels`/`disallowedModels` in api-proxy** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): Model allow/deny-list policy; ado-aw could expose as `engine.allowed-models` front-matter.
- **`COPILOT_INTEGRATION_ID` forwarding from host env** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): api-proxy forwards from host into sandbox; ensure ado-aw passes it through AWF invocation.
- **GHES detection fix for Copilot auth prefix** ([v0.27.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.4)): Fixes auth failures for non-standard GHES hostnames.

### `0.27.3` → `0.27.7` (was #1118)
- **`max-cache-misses` guardrail** ([v0.27.6](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.6)): Limits token spend when cache misses exceed threshold; useful for cost-sensitive pipelines.

### `0.27.3` → `0.27.9` (was #1184)
- **Copilot Business endpoint auth prefix corrected** ([v0.27.9](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.9)): Fixed wrong `bearer` prefix (should be `token`); Business-account pipelines may have been silently failing.

### `0.27.9` → `0.27.11` (was #1219)
- **Portable self-hosted runner doctor agent** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): New AWF diagnostic tool; ado-aw could reference in troubleshooting docs.
- **Topology-attach ordering deadlock fix** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): Starved cli-proxy health gate; MCPG-based pipelines (`--topology-attach mcp-gateway`) were directly affected.
- **ARC/DinD chroot path fix** ([v0.27.10](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.10)): `/host/tmp/awf-runner-bin` instead of `/host/usr` collision; update ARC/DinD docs if referencing `/host/usr`.

### `0.27.9` → `0.27.12` (was #1241)
- **Security: June 2026 dependency refresh** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): Routine security dep upgrades; upgrading recommended.
- **OIDC config propagation fix** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): `apiProxy.auth` OIDC fields were not propagated to all proxy layers; previously configured OIDC may have been silently ignored.

### `0.27.9` → `0.27.13` (was #1252)
- **Security: ReDoS fix in postprocess script** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): ReDoS vulnerability patched; no consumer action beyond upgrading.
- **`maxRuns` counts only inference calls** ([v0.27.13](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.13)): Semantics changed — no longer counts tool calls; re-evaluate any `max-runs` tuning based on total tool-call counts.
- **HTTP 429 (not 403) when max turns exceeded** ([v0.27.13](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.13)): Update any ado-aw code/docs that treat 403 as the max-turns-exceeded indicator.

### `0.27.9` → `0.27.15` (was #1260)
- **Note**: v0.27.14 was retracted; its changes are included in v0.27.15.
- **Security: transitive `linkify-it` → v5.0.1** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): Part of June 2026 security refresh.

### `0.27.9` → `0.27.21` (was #1304)
- **`container.mounts` in AWF config schema** ([v0.27.21](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.21)): ado-aw could expose as front-matter field for custom sandbox mounts.
- **Model-to-API endpoint mapping** ([v0.27.16](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.16)): AWF maintains a model→endpoint map updated daily; relevant for ado-aw model validation allowlist.

### `0.27.32` → `0.28.5` (was #1990)
- **Firecracker microVM backend removed** (v0.28.1, "ci: disable Firecracker workflows and release artifacts") — AWF has dropped Firecracker in favor of Cloud Hypervisor as the sandbox backend. ado-aw does not reference Firecracker directly, but any docs/runner-doctor guidance mentioning it upstream should not be assumed to apply going forward.
- **Enforce filesystem `allowWrite` boundaries in AWF sandboxes** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7634) — tightens write-path enforcement so sandboxed agents can only write within explicitly allowed paths.
- **Route CLI artifact redirects through scoped Squid egress** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7635) — CLI artifact download redirects are now proxied through Squid's domain-allowlist instead of bypassing egress controls, closing a potential egress-control bypass.
- **fix: route CLI proxy through isolated egress relay** ([v0.28.2](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.2), #7338) — routes the CLI proxy through an isolated egress relay for DIFC credential isolation.
- **fix(security): suppress non-reachable GO-2026-4337 in gosu binary** ([v0.27.43](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.43), #6645) and **update brace-expansion to 5.0.8 (GHSA-mh99-v99m-4gvg)** ([v0.27.42](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.42), #6585) — routine dependency CVE remediations in the AWF toolchain.
- **Support compiler-authorized digest-pinned container image manifests** ([v0.28.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.4), #7601) — ado-aw could adopt this to pin AWF/MCPG/agent images by digest instead of tag for stronger supply-chain guarantees.
- **feat: support secret-backed OpenAI-compatible targets** ([v0.28.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.3), #7576) — new API-proxy target type; relevant if ado-aw ever wants to support OpenAI-compatible engine backends secured via secret-backed credentials.
- **API proxy: first-class AI-credit accounting for Copilot `auto` dynamic selector** ([v0.28.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.4), #7604) — improved cost/credit accounting when using Copilot's `auto` model selector, could inform ado-aw's engine cost-reporting/observability docs.
- **Recover transient Cloud Hypervisor readiness failures** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7611) and **Fix Cloud Hypervisor API proxy readiness race** ([v0.28.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.3), #7582) — reliability fixes for the (preview) Cloud Hypervisor backend that ado-aw's OneBranch integration may rely on.

### `0.27.32` → `0.28.9` (was #2028) — canonical
- **Firecracker support removed** (#7362) — anyone relying on the Firecracker VM isolation backend for AWF will need to migrate to the supported sandboxing path before upgrading past this range.
- `fix(security): update vulnerable deps in agent and api-proxy images` (#6505) — patches known CVEs in the agent/api-proxy container images.
- `chore(deps): safe patch updates incl. ajv 8.20.0 security fix` (#6962) — bundled `ajv` security patch.
- **Protect `ANTHROPIC_AUTH_TOKEN` in AWF credential isolation paths** (#6410) — extends AWF's credential-isolation guarantees to Anthropic auth tokens.
- **Exclude topology-attached MCP peers from agent proxy routing** (#6189) — relevant to how ado-aw wires MCPG via `--topology-attach`; may simplify or change proxy routing assumptions in `agentic_pipeline.rs`.
- **Auto-allow topology-attached container hostnames in Squid ACL** (#6473) — reduces manual allowlist entries for topology-attached containers (e.g. MCPG), potentially letting ado-aw drop custom allowlist workarounds.
- **Support `COPILOT_MODEL=auto`** (#6474) — new dynamic model-selection env var AWF passes through; ado-aw's `engine.rs` model handling could expose this as a supported option.
- **Route CLI proxy through isolated egress relay** (#7338) — changes to how the wrapped `az`/CLI network egress is routed; worth double-checking `az_wrapper.rs` assumptions still hold.
- **API proxy: first-class AI-credit accounting for Copilot auto dynamic selector** (#7604) — new usage/cost accounting surfaced by AWF that ado-aw's audit/otel tooling could ingest.
- **Remove "bounded-query" terminology** (#7735) — naming/terminology change in AWF docs/config; check for any ado-aw docs or config referencing the old term.

---
*Consolidated by the Deps Release-Notes Consolidator workflow. Superseded per-release issues were closed and point here.*> Generated by [Deps Release-Notes Consolidator](https://github.com/githubnext/ado-aw/actions/runs/33234357474) · auto · 76.3 AIC · ⌖ 11.6 AIC · ⊞ 10.6K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fado-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fado-aw%2Fdeps-notes-consolidator%22&type=issues)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the latest comments on this canonical tracking issue and the `update-awf-version` workflow, since the body is a consolidated history rather than one task. Read the mentioned `agentic_pipeline.rs` entry point if investigating topology-attached MCP routing. The issue does not define a single change or acceptance criterion, so completion must first be narrowed to one action item.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
tooling
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.