Skip to content
Closed

merge #166

Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
40 commits
Select commit Hold shift + click to select a range
cdbcddd
feat: add comprehensive tests for Jules comment analysis logic
google-labs-jules[bot] Feb 20, 2026
3c58de9
feat: Optimize webhook handling with batched label creation and datab…
google-labs-jules[bot] Feb 20, 2026
cec11d3
Merge pull request #11 from sjoerd2025/webhook-performance-optimizati…
sjoerd2025 Feb 20, 2026
bd9faa4
Merge pull request #10 from sjoerd2025/jules-tests-1861617116859476336
sjoerd2025 Feb 20, 2026
d1b7173
perf: optimize installation service sync and cleanup
google-labs-jules[bot] Feb 24, 2026
f08b2fe
🔒 Security: Fix DoS vulnerability in checkIfUserStarredRepository
google-labs-jules[bot] Feb 25, 2026
911e108
test: add unit tests for getInstallationStatus
google-labs-jules[bot] Feb 25, 2026
6a69d1d
⚡ Optimize retryAllFlaggedTasks to avoid redundant DB fetch
google-labs-jules[bot] Feb 25, 2026
a1adc21
refactor: remove debug logging in installation status handler
google-labs-jules[bot] Feb 25, 2026
b8b57d3
Refactor: remove leftover debug logging in label setup handler
google-labs-jules[bot] Feb 25, 2026
a367175
test: add tests for crypto utility
google-labs-jules[bot] Feb 25, 2026
37cb7cb
Refactor: extract duplicate repository upsert logic
google-labs-jules[bot] Feb 25, 2026
e84005c
🧪 Add tests for src/lib/number.ts
google-labs-jules[bot] Feb 25, 2026
63a7a6a
test: add unit tests for crypto.ts
google-labs-jules[bot] Feb 25, 2026
446a2e4
Secure tasks router endpoints with adminProcedure
google-labs-jules[bot] Feb 25, 2026
531f425
Fix timing attack in cron retry route and logger type errors
google-labs-jules[bot] Feb 25, 2026
6cfb379
chore: initialize GitHub Agentic Workflows
sjoerd2025 Feb 26, 2026
cf252b6
feat: add Angular agentic workflows
sjoerd2025 Feb 26, 2026
4b87f53
chore: remove Angular workflows (not an Angular project)
sjoerd2025 Feb 26, 2026
009e45b
Merge pull request #35 from sjoerd2025/refactor/deduplicate-repositor…
sjoerd2025 Mar 1, 2026
ebfb2de
Merge pull request #30 from sjoerd2025/perf/jules-retry-task-17902049…
sjoerd2025 Mar 1, 2026
e7b1b6e
Merge pull request #29 from sjoerd2025/test-github-app-utils-13888117…
sjoerd2025 Mar 1, 2026
df7c0e5
Merge pull request #28 from sjoerd2025/fix/dos-vulnerability-github-s…
sjoerd2025 Mar 1, 2026
f5c82a7
Merge pull request #27 from sjoerd2025/bolt-performance-installation-…
sjoerd2025 Mar 1, 2026
0c16466
Merge pull request #33 from sjoerd2025/refactor-remove-debug-logging-…
sjoerd2025 Mar 1, 2026
220726a
Merge pull request #32 from sjoerd2025/refactor/remove-debug-logging-…
sjoerd2025 Mar 1, 2026
3129bc4
Merge pull request #36 from sjoerd2025/jules/test-number-utils-137757…
sjoerd2025 Mar 1, 2026
2b50427
Merge pull request #37 from sjoerd2025/testing-improvement-crypto-tes…
sjoerd2025 Mar 1, 2026
efc8742
Merge pull request #39 from sjoerd2025/secure-tasks-router-7002806243…
sjoerd2025 Mar 1, 2026
a08e2d0
Merge pull request #34 from sjoerd2025/testing-improvement-crypto-tes…
sjoerd2025 Mar 1, 2026
d511859
Merge pull request #42 from sjoerd2025/fix/cron-timing-attack-1767132…
sjoerd2025 Mar 1, 2026
e3308e6
perf: use atomic upsert for rate limiting to prevent TOCTOU and N+1 q…
google-labs-jules[bot] Mar 7, 2026
380e46f
Merge pull request #58 from sjoerd2025/bolt-rate-limiter-upsert-16750…
sjoerd2025 Mar 9, 2026
6b1a589
⚡ Bolt: Optimize syncAllInstallations performance
google-labs-jules[bot] Apr 12, 2026
1ebb508
⚡ Bolt: Refactor manual upsert to use Prisma native upsert for JulesTask
google-labs-jules[bot] Apr 30, 2026
8eb4357
perf: Optimize bulk repository removal in github app webhooks
google-labs-jules[bot] May 1, 2026
35b375a
Merge pull request #109 from sjoerd2025/bolt-optimize-upsert-jules-ta…
sjoerd2025 May 2, 2026
ee8ae82
Merge pull request #110 from sjoerd2025/bolt-optimize-bulk-repo-remov…
sjoerd2025 May 2, 2026
abeddb3
Merge branch 'main' into bolt-optimize-syncallinstallations-308843730…
sjoerd2025 May 2, 2026
c8ef5c0
Merge pull request #92 from sjoerd2025/bolt-optimize-syncallinstallat…
sjoerd2025 May 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
.github/workflows/*.lock.yml linguist-generated=true merge=ours
177 changes: 177 additions & 0 deletions .github/agents/agentic-workflows.agent.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,177 @@
---
description: GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing
disable-model-invocation: true
---

# GitHub Agentic Workflows Agent

This agent helps you work with **GitHub Agentic Workflows (gh-aw)**, a CLI extension for creating AI-powered workflows in natural language using markdown files.

## What This Agent Does

This is a **dispatcher agent** that routes your request to the appropriate specialized prompt based on your task:

- **Creating new workflows**: Routes to `create` prompt
- **Updating existing workflows**: Routes to `update` prompt
- **Debugging workflows**: Routes to `debug` prompt
- **Upgrading workflows**: Routes to `upgrade-agentic-workflows` prompt
- **Creating report-generating workflows**: Routes to `report` prompt — consult this whenever the workflow posts status updates, audits, analyses, or any structured output as issues, discussions, or comments
- **Creating shared components**: Routes to `create-shared-agentic-workflow` prompt
- **Fixing Dependabot PRs**: Routes to `dependabot` prompt — use this when Dependabot opens PRs that modify generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`). Never merge those PRs directly; instead update the source `.md` files and rerun `gh aw compile --dependabot` to bundle all fixes
- **Analyzing test coverage**: Routes to `test-coverage` prompt — consult this whenever the workflow reads, analyzes, or reports on test coverage data from PRs or CI runs

Workflows may optionally include:

- **Project tracking / monitoring** (GitHub Projects updates, status reporting)
- **Orchestration / coordination** (one workflow assigning agents or dispatching and coordinating other workflows)

## Files This Applies To

- Workflow files: `.github/workflows/*.md` and `.github/workflows/**/*.md`
- Workflow lock files: `.github/workflows/*.lock.yml`
- Shared components: `.github/workflows/shared/*.md`
- Configuration: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/github-agentic-workflows.md

## Problems This Solves

- **Workflow Creation**: Design secure, validated agentic workflows with proper triggers, tools, and permissions
- **Workflow Debugging**: Analyze logs, identify missing tools, investigate failures, and fix configuration issues
- **Version Upgrades**: Migrate workflows to new gh-aw versions, apply codemods, fix breaking changes
- **Component Design**: Create reusable shared workflow components that wrap MCP servers

## How to Use

When you interact with this agent, it will:

1. **Understand your intent** - Determine what kind of task you're trying to accomplish
2. **Route to the right prompt** - Load the specialized prompt file for your task
3. **Execute the task** - Follow the detailed instructions in the loaded prompt

## Available Prompts

### Create New Workflow
**Load when**: User wants to create a new workflow from scratch, add automation, or design a workflow that doesn't exist yet

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/create-agentic-workflow.md

**Use cases**:
- "Create a workflow that triages issues"
- "I need a workflow to label pull requests"
- "Design a weekly research automation"

### Update Existing Workflow
**Load when**: User wants to modify, improve, or refactor an existing workflow

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/update-agentic-workflow.md

**Use cases**:
- "Add web-fetch tool to the issue-classifier workflow"
- "Update the PR reviewer to use discussions instead of issues"
- "Improve the prompt for the weekly-research workflow"

### Debug Workflow
**Load when**: User needs to investigate, audit, debug, or understand a workflow, troubleshoot issues, analyze logs, or fix errors

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/debug-agentic-workflow.md

**Use cases**:
- "Why is this workflow failing?"
- "Analyze the logs for workflow X"
- "Investigate missing tool calls in run #12345"

### Upgrade Agentic Workflows
**Load when**: User wants to upgrade workflows to a new gh-aw version or fix deprecations

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/upgrade-agentic-workflows.md

**Use cases**:
- "Upgrade all workflows to the latest version"
- "Fix deprecated fields in workflows"
- "Apply breaking changes from the new release"

### Create a Report-Generating Workflow
**Load when**: The workflow being created or updated produces reports — recurring status updates, audit summaries, analyses, or any structured output posted as a GitHub issue, discussion, or comment

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/report.md

**Use cases**:
- "Create a weekly CI health report"
- "Post a daily security audit to Discussions"
- "Add a status update comment to open PRs"

### Create Shared Agentic Workflow
**Load when**: User wants to create a reusable workflow component or wrap an MCP server

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/create-shared-agentic-workflow.md

**Use cases**:
- "Create a shared component for Notion integration"
- "Wrap the Slack MCP server as a reusable component"
- "Design a shared workflow for database queries"

### Fix Dependabot PRs
**Load when**: User needs to close or fix open Dependabot PRs that update dependencies in generated manifest files (`.github/workflows/package.json`, `.github/workflows/requirements.txt`, `.github/workflows/go.mod`)

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/dependabot.md

**Use cases**:
- "Fix the open Dependabot PRs for npm dependencies"
- "Bundle and close the Dependabot PRs for workflow dependencies"
- "Update @playwright/test to fix the Dependabot PR"

### Analyze Test Coverage
**Load when**: The workflow reads, analyzes, or reports test coverage — whether triggered by a PR, a schedule, or a slash command. Always consult this prompt before designing the coverage data strategy.

**Prompt file**: https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/test-coverage.md

**Use cases**:
- "Create a workflow that comments coverage on PRs"
- "Analyze coverage trends over time"
- "Add a coverage gate that blocks PRs below a threshold"

## Instructions

When a user interacts with you:

1. **Identify the task type** from the user's request
2. **Load the appropriate prompt** from the GitHub repository URLs listed above
3. **Follow the loaded prompt's instructions** exactly
4. **If uncertain**, ask clarifying questions to determine the right prompt

## Quick Reference

```bash
# Initialize repository for agentic workflows
gh aw init

# Generate the lock file for a workflow
gh aw compile [workflow-name]

# Debug workflow runs
gh aw logs [workflow-name]
gh aw audit <run-id>

# Upgrade workflows
gh aw fix --write
gh aw compile --validate
```

## Key Features of gh-aw

- **Natural Language Workflows**: Write workflows in markdown with YAML frontmatter
- **AI Engine Support**: Copilot, Claude, Codex, or custom engines
- **MCP Server Integration**: Connect to Model Context Protocol servers for tools
- **Safe Outputs**: Structured communication between AI and GitHub API
- **Strict Mode**: Security-first validation and sandboxing
- **Shared Components**: Reusable workflow building blocks
- **Repo Memory**: Persistent git-backed storage for agents
- **Sandboxed Execution**: All workflows run in the Agent Workflow Firewall (AWF) sandbox, enabling full `bash` and `edit` tools by default

## Important Notes

- Always reference the instructions file at https://github.com/github/gh-aw/blob/v0.50.5/.github/aw/github-agentic-workflows.md for complete documentation
- Use the MCP tool `agentic-workflows` when running in GitHub Copilot Cloud
- Workflows must be compiled to `.lock.yml` files before running in GitHub Actions
- **Bash tools are enabled by default** - Don't restrict bash commands unnecessarily since workflows are sandboxed by the AWF
- Follow security best practices: minimal permissions, explicit network access, no template injection
- **Single-file output**: When creating a workflow, produce exactly **one** workflow `.md` file. Do not create separate documentation files (architecture docs, runbooks, usage guides, etc.). If documentation is needed, add a brief `## Usage` section inside the workflow file itself.
19 changes: 19 additions & 0 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
{
"entries": {
"actions/checkout@v4": {
"repo": "actions/checkout",
"version": "v4",
"sha": "34e114876b0b11c390a56381ad16ebd13914f8d5"
},
"actions/github-script@v8": {
"repo": "actions/github-script",
"version": "v8",
"sha": "ed597411d8f924073f98dfc5c65a23a2325f34cd"
},
"github/gh-aw/actions/setup@v0.50.5": {
"repo": "github/gh-aw/actions/setup",
"version": "v0.50.5",
"sha": "a7d371cc7e68f270ded0592942424548e05bf1c2"
}
}
}
82 changes: 82 additions & 0 deletions .github/workflows/agentics-maintenance.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
#
# ___ _ _
# / _ \ | | (_)
# | |_| | __ _ ___ _ __ | |_ _ ___
# | _ |/ _` |/ _ \ '_ \| __| |/ __|
# | | | | (_| | __/ | | | |_| | (__
# \_| |_/\__, |\___|_| |_|\__|_|\___|
# __/ |
# _ _ |___/
# | | | | / _| |
# | | | | ___ _ __ _ __| |_| | _____ ____
# | |/\| |/ _ \ '__| |/ /| _| |/ _ \ \ /\ / / ___|
# \ /\ / (_) | | | | ( | | | | (_) \ V V /\__ \
# \/ \/ \___/|_| |_|\_\|_| |_|\___/ \_/\_/ |___/
#
# This file was automatically generated by pkg/workflow/maintenance_workflow.go (v0.50.5). DO NOT EDIT.
#
# To regenerate this workflow, run:
# gh aw compile
# Not all edits will cause changes to this file.
#
# For more information: https://github.github.com/gh-aw/introduction/overview/
#
# Alternative regeneration methods:
# make recompile
#
# Or use the gh-aw CLI directly:
# ./gh-aw compile --validate --verbose
#
# The workflow is generated when any workflow uses the 'expires' field
# in create-discussions, create-issues, or create-pull-request safe-outputs configuration.
# Schedule frequency is automatically determined by the shortest expiration time.
#
name: Agentic Maintenance

on:
schedule:
- cron: "37 */2 * * *" # Every 2 hours (based on minimum expires: 1 days)
workflow_dispatch:

permissions: {}

jobs:
close-expired-entities:
if: ${{ !github.event.repository.fork }}
runs-on: ubuntu-slim
permissions:
discussions: write
issues: write
pull-requests: write
steps:
- name: Setup Scripts
uses: github/gh-aw/actions/setup@a7d371cc7e68f270ded0592942424548e05bf1c2 # v0.50.5
with:
destination: /opt/gh-aw/actions

- name: Close expired discussions
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
const { setupGlobals } = require('/opt/gh-aw/actions/setup_globals.cjs');
setupGlobals(core, github, context, exec, io);
const { main } = require('/opt/gh-aw/actions/close_expired_discussions.cjs');
await main();

- name: Close expired issues
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
const { setupGlobals } = require('/opt/gh-aw/actions/setup_globals.cjs');
setupGlobals(core, github, context, exec, io);
const { main } = require('/opt/gh-aw/actions/close_expired_issues.cjs');
await main();

- name: Close expired pull requests
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8
with:
script: |
const { setupGlobals } = require('/opt/gh-aw/actions/setup_globals.cjs');
setupGlobals(core, github, context, exec, io);
const { main } = require('/opt/gh-aw/actions/close_expired_pull_requests.cjs');
await main();
Loading