githubnext / githubnext/ado-aw
[deps-release-notes] awf — upstream release action items
- Dominant language
- Rust
- Stars
- 23
- Forks
- 8
- Avg merge
- 4d 9h
- Merged PRs (30d)
- 22
Description
# Rolling upstream release action items — `awf`
This is the **single canonical tracking issue** for action items arising from
new releases of the `awf` dependency. The `update-awf-version` workflow appends
a new comment to this issue for each version bump going forward, so **the most
recent activity lives in the comments below**. This body is a consolidated
history of everything filed so far.
**Latest pinned version covered:** `0.28.9`
## Consolidated history (earliest → latest)
### `0.25.48` → `0.25.60` (was #851)
- **OTel distributed tracing in api-proxy** ([v0.25.51](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.51)): api-proxy now emits OTel traces; ado-aw could expose config to help consumers use this.
- **ARC/DinD split-filesystem auto-detection** ([v0.25.52](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.52)): AWF auto-detects DinD split filesystem via sentinel probe; ado-aw docs may need updating.
- **Middle-power model fallback** ([v0.25.53](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.53)): api-proxy supports model fallback when primary is unavailable; ado-aw could expose this.
- **Anthropic WIF support** ([v0.25.58](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.58)): api-proxy supports Anthropic WIF schema fields + OIDC validation.
- **Pre-startup model validation via `requestedModel` config** ([v0.25.58](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.58)): api-proxy validates requested model before startup; ado-aw may wish to populate this field.
### `0.25.48` → `0.25.63` (was #859)
- **Security: proxy auth normalization hardened** ([v0.25.49](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.49)): Prevents malformed `Authorization` headers from reaching the upstream API.
- **Responses API cache reads in token usage rollups** ([v0.25.63](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.63)): Fixes under-reporting of cached token reads; improves `ado-aw audit` accuracy.
### `0.25.65` → `0.25.66` (was #902)
- **Azure/AWS/GCP OIDC support in Copilot adapter** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): api-proxy supports cloud OIDC credential injection; ado-aw could expose via `engine:`/`network:` front-matter.
- **Budget fields in `token-usage.jsonl`** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): `maxTurns` and budget fields now persisted; ado-aw audit module could surface these in `AuditData`.
### `0.25.65` → `0.25.68` (was #930)
- **`GITHUB_COPILOT_INTEGRATION_ID` forwarding fix** ([v0.25.67](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.67)): AWF now correctly forwards it as `COPILOT_INTEGRATION_ID` to the api-proxy.
- **PAT-safe integration ID + model name normalization** ([v0.25.68](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.68)): Regression fix from v0.25.67; normalizes legacy CAPI model names.
### `0.25.65` → `0.27.0` (was #950)
- **cli-proxy fail fast on DIFC unreachability** ([v0.25.66](https://github.com/github/gh-aw-firewall/releases/tag/v0.25.66)): CLI proxy now errors immediately rather than hanging; verify DIFC proxy config before upgrade.
### `0.25.65` → `0.27.1` (was #970)
- **AI credits as OTEL span attributes** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): AWF emits AI credit consumption as OTel spans; `agent_stats.rs` + `audit` could surface these.
- **Redacted resolved config as audit artifact** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): `ado-aw audit` could expose for configuration diagnostics.
- **Opt-in diagnostics artifact for blocked LLM request bodies** ([v0.27.1](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.1)): ado-aw could surface via `ado-aw-debug:` flag.
### `0.25.65` → `0.27.2` (was #983)
- **Security: WIF/OIDC Anthropic auth regression** ([v0.27.2](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.2)): `ANTHROPIC_API_KEY` leaked to agent container when Squid blocked OIDC exchange; fixed in `0.27.2`.
### `0.25.65` → `0.27.3` (was #990)
- **OTLP fan-out to multiple endpoints** ([v0.27.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.3)): api-proxy can fan out telemetry to multiple OTLP endpoints simultaneously.
### `0.27.3` → `0.27.5` (was #1093)
- **Security: HTTPS-only for bare API proxy targets** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): Prevents over-broad HTTP allowlisting; verify no existing config relies on HTTP.
- **`allowedModels`/`disallowedModels` in api-proxy** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): Model allow/deny-list policy; ado-aw could expose as `engine.allowed-models` front-matter.
- **`COPILOT_INTEGRATION_ID` forwarding from host env** ([v0.27.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.5)): api-proxy forwards from host into sandbox; ensure ado-aw passes it through AWF invocation.
- **GHES detection fix for Copilot auth prefix** ([v0.27.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.4)): Fixes auth failures for non-standard GHES hostnames.
### `0.27.3` → `0.27.7` (was #1118)
- **`max-cache-misses` guardrail** ([v0.27.6](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.6)): Limits token spend when cache misses exceed threshold; useful for cost-sensitive pipelines.
### `0.27.3` → `0.27.9` (was #1184)
- **Copilot Business endpoint auth prefix corrected** ([v0.27.9](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.9)): Fixed wrong `bearer` prefix (should be `token`); Business-account pipelines may have been silently failing.
### `0.27.9` → `0.27.11` (was #1219)
- **Portable self-hosted runner doctor agent** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): New AWF diagnostic tool; ado-aw could reference in troubleshooting docs.
- **Topology-attach ordering deadlock fix** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): Starved cli-proxy health gate; MCPG-based pipelines (`--topology-attach mcp-gateway`) were directly affected.
- **ARC/DinD chroot path fix** ([v0.27.10](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.10)): `/host/tmp/awf-runner-bin` instead of `/host/usr` collision; update ARC/DinD docs if referencing `/host/usr`.
### `0.27.9` → `0.27.12` (was #1241)
- **Security: June 2026 dependency refresh** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): Routine security dep upgrades; upgrading recommended.
- **OIDC config propagation fix** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): `apiProxy.auth` OIDC fields were not propagated to all proxy layers; previously configured OIDC may have been silently ignored.
### `0.27.9` → `0.27.13` (was #1252)
- **Security: ReDoS fix in postprocess script** ([v0.27.11](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.11)): ReDoS vulnerability patched; no consumer action beyond upgrading.
- **`maxRuns` counts only inference calls** ([v0.27.13](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.13)): Semantics changed — no longer counts tool calls; re-evaluate any `max-runs` tuning based on total tool-call counts.
- **HTTP 429 (not 403) when max turns exceeded** ([v0.27.13](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.13)): Update any ado-aw code/docs that treat 403 as the max-turns-exceeded indicator.
### `0.27.9` → `0.27.15` (was #1260)
- **Note**: v0.27.14 was retracted; its changes are included in v0.27.15.
- **Security: transitive `linkify-it` → v5.0.1** ([v0.27.12](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.12)): Part of June 2026 security refresh.
### `0.27.9` → `0.27.21` (was #1304)
- **`container.mounts` in AWF config schema** ([v0.27.21](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.21)): ado-aw could expose as front-matter field for custom sandbox mounts.
- **Model-to-API endpoint mapping** ([v0.27.16](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.16)): AWF maintains a model→endpoint map updated daily; relevant for ado-aw model validation allowlist.
### `0.27.32` → `0.28.5` (was #1990)
- **Firecracker microVM backend removed** (v0.28.1, "ci: disable Firecracker workflows and release artifacts") — AWF has dropped Firecracker in favor of Cloud Hypervisor as the sandbox backend. ado-aw does not reference Firecracker directly, but any docs/runner-doctor guidance mentioning it upstream should not be assumed to apply going forward.
- **Enforce filesystem `allowWrite` boundaries in AWF sandboxes** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7634) — tightens write-path enforcement so sandboxed agents can only write within explicitly allowed paths.
- **Route CLI artifact redirects through scoped Squid egress** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7635) — CLI artifact download redirects are now proxied through Squid's domain-allowlist instead of bypassing egress controls, closing a potential egress-control bypass.
- **fix: route CLI proxy through isolated egress relay** ([v0.28.2](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.2), #7338) — routes the CLI proxy through an isolated egress relay for DIFC credential isolation.
- **fix(security): suppress non-reachable GO-2026-4337 in gosu binary** ([v0.27.43](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.43), #6645) and **update brace-expansion to 5.0.8 (GHSA-mh99-v99m-4gvg)** ([v0.27.42](https://github.com/github/gh-aw-firewall/releases/tag/v0.27.42), #6585) — routine dependency CVE remediations in the AWF toolchain.
- **Support compiler-authorized digest-pinned container image manifests** ([v0.28.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.4), #7601) — ado-aw could adopt this to pin AWF/MCPG/agent images by digest instead of tag for stronger supply-chain guarantees.
- **feat: support secret-backed OpenAI-compatible targets** ([v0.28.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.3), #7576) — new API-proxy target type; relevant if ado-aw ever wants to support OpenAI-compatible engine backends secured via secret-backed credentials.
- **API proxy: first-class AI-credit accounting for Copilot `auto` dynamic selector** ([v0.28.4](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.4), #7604) — improved cost/credit accounting when using Copilot's `auto` model selector, could inform ado-aw's engine cost-reporting/observability docs.
- **Recover transient Cloud Hypervisor readiness failures** ([v0.28.5](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.5), #7611) and **Fix Cloud Hypervisor API proxy readiness race** ([v0.28.3](https://github.com/github/gh-aw-firewall/releases/tag/v0.28.3), #7582) — reliability fixes for the (preview) Cloud Hypervisor backend that ado-aw's OneBranch integration may rely on.
### `0.27.32` → `0.28.9` (was #2028) — canonical
- **Firecracker support removed** (#7362) — anyone relying on the Firecracker VM isolation backend for AWF will need to migrate to the supported sandboxing path before upgrading past this range.
- `fix(security): update vulnerable deps in agent and api-proxy images` (#6505) — patches known CVEs in the agent/api-proxy container images.
- `chore(deps): safe patch updates incl. ajv 8.20.0 security fix` (#6962) — bundled `ajv` security patch.
- **Protect `ANTHROPIC_AUTH_TOKEN` in AWF credential isolation paths** (#6410) — extends AWF's credential-isolation guarantees to Anthropic auth tokens.
- **Exclude topology-attached MCP peers from agent proxy routing** (#6189) — relevant to how ado-aw wires MCPG via `--topology-attach`; may simplify or change proxy routing assumptions in `agentic_pipeline.rs`.
- **Auto-allow topology-attached container hostnames in Squid ACL** (#6473) — reduces manual allowlist entries for topology-attached containers (e.g. MCPG), potentially letting ado-aw drop custom allowlist workarounds.
- **Support `COPILOT_MODEL=auto`** (#6474) — new dynamic model-selection env var AWF passes through; ado-aw's `engine.rs` model handling could expose this as a supported option.
- **Route CLI proxy through isolated egress relay** (#7338) — changes to how the wrapped `az`/CLI network egress is routed; worth double-checking `az_wrapper.rs` assumptions still hold.
- **API proxy: first-class AI-credit accounting for Copilot auto dynamic selector** (#7604) — new usage/cost accounting surfaced by AWF that ado-aw's audit/otel tooling could ingest.
- **Remove "bounded-query" terminology** (#7735) — naming/terminology change in AWF docs/config; check for any ado-aw docs or config referencing the old term.
---
*Consolidated by the Deps Release-Notes Consolidator workflow. Superseded per-release issues were closed and point here.*> Generated by [Deps Release-Notes Consolidator](https://github.com/githubnext/ado-aw/actions/runs/33234357474) · auto · 76.3 AIC · ⌖ 11.6 AIC · ⊞ 10.6K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fado-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fado-aw%2Fdeps-notes-consolidator%22&type=issues)
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with the latest comments on this canonical tracking issue and the `update-awf-version` workflow, since the body is a consolidated history rather than one task. Read the mentioned `agentic_pipeline.rs` entry point if investigating topology-attached MCP routing. The issue does not define a single change or acceptance criterion, so completion must first be narrowed to one action item.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- tooling
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100