chore(deps): update github/gh-aw action to v0.88.7 - #8109
Open
release-workflows[bot] wants to merge 1 commit into
Open
chore(deps): update github/gh-aw action to v0.88.7#8109release-workflows[bot] wants to merge 1 commit into
release-workflows[bot] wants to merge 1 commit into
Conversation
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 13, 2026 20:11
c42b1d6 to
2e684f8
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 13, 2026 22:10
2e684f8 to
ee9d01e
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 14, 2026 02:59
ee9d01e to
ecda65f
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 14, 2026 22:06
ecda65f to
0ab8e8b
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 16, 2026 01:36
0ab8e8b to
a9fbf11
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 16, 2026 22:08
a9fbf11 to
4a778e8
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 17, 2026 01:36
4a778e8 to
e615234
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 17, 2026 04:39
e615234 to
19e5e59
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 17, 2026 08:17
19e5e59 to
7135245
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 17, 2026 18:21
7135245 to
abab8e0
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 17, 2026 23:09
abab8e0 to
be0c80f
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 18, 2026 01:36
be0c80f to
62f4b32
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 18, 2026 06:26
62f4b32 to
60ef078
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 18, 2026 20:14
60ef078 to
d35bed6
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 19, 2026 04:39
d35bed6 to
d6b5920
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 20, 2026 16:13
b2b4fe3 to
be66276
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 20, 2026 21:06
be66276 to
7bb6e08
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 00:27
7bb6e08 to
d345213
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 02:57
d345213 to
cddd18c
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 03:48
cddd18c to
314ac7c
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 05:21
314ac7c to
d8f76f8
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 18:09
d8f76f8 to
bac0698
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 21, 2026 20:06
bac0698 to
3b1e802
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 22, 2026 06:18
3b1e802 to
84850c5
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 22, 2026 16:08
84850c5 to
63dd3c5
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 23, 2026 00:29
63dd3c5 to
8c30f9c
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 23, 2026 03:05
8c30f9c to
e46061e
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 23, 2026 07:27
e46061e to
b2300f9
Compare
release-workflows
Bot
force-pushed
the
renovate/github-gh-aw-0.x
branch
from
February 23, 2026 12:16
b2300f9 to
dcac731
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.43.18→v0.88.7Release Notes
github/gh-aw (github/gh-aw)
v0.88.7Compare Source
🌟 Release Highlights
This release focuses on hardening logs tooling, tightening security around agent outputs and secrets, and polishing documentation.
✨ What's New
aw.ymlnow supports wildcard mapping destination folders (#59317).🐛 Bug Fixes & Improvements
📚 Documentation
What's Changed
Full Changelog: github/gh-aw@v0.88.6...v0.88.7
v0.88.6Compare Source
🌟 Release Highlights
This release strengthens enclave TTL handling, expands
gh aw logswith caching and audit capabilities, and lets teams enforce workspace-wide strict compilation.strict: trueat the top level of.github/workflows/aw.jsonto force strict compilation across all workflows — per-workflowstrict: falseopt-outs are rejected. Existing workflows relying on relaxed validation should confirm they pass strict checks before enabling this.✨ What's New
gh aw logs(#59270):gh aw logs --auditnow generates per-run audit reports from already-downloaded data with no extra GitHub API calls, writing/reusingaudit.jsonper run cache.gh aw logsnow fetches and caches the complete GitHub Actions run response (workflow path, repository, actor, run attempt, event, commit) asrun.json, removing the need for separategh apicalls.gh aw logs --max-storagenow reports cache usage per folder and selectively prunes the largest non-essential data from completed runs while preserving summaries, job metadata, and usage data.🐛 Bug Fixes & Improvements
max_identity_ttlin the MCP gateway delegation envelope is now correctly emitted in seconds (matching themcpgv0.4.17 wire contract), fixing an accidental encoding as nanoseconds. Fixes #59258.📚 Documentation
What's Changed
Full Changelog: github/gh-aw@v0.88.5...v0.88.6
v0.88.5Compare Source
🌟 Release Highlights
This release brings new compiler capabilities for dynamic repository access control, expanded safe-output integrations, and better observability for workflow runs.
✨ What's New
aw.yml— extend youraw.ymlconfiguration with repository labels for finer-grained workflow targeting (#58796).aw.ymlincludes — include patterns now support trailing wildcards for more flexible file matching (#58545).📊 Observability Improvements
🐛 Bug Fixes & Improvements
$refschema resolution (#58411).PATHacross privileged AWF startup (#58625).sandbox.agent: falseopt-out (#58693).🔧 Internal
The bulk of this release also includes extensive internal CI, model-configuration, and workflow-reliability maintenance across gh-aw's own agentic workflows (Codex model compatibility fixes, safe-output conformance hardening, and dead-code cleanups) — not covered in detail here as they don't affect end users of the
gh awCLI.What's Changed
$refschema resolution by @pelikhan with @Copilot in #58411sandbox.agent: falseopt-out by @pelikhan with @Copilot in #58693require-getexecoutput-exitcode-checkESLint rule to@actions/execexec()by @pelikhan with @Copilot in #58778Full Changelog: github/gh-aw@v0.88.4...v0.88.5
v0.88.4Compare Source
🌟 Release Highlights
This release focuses on hardening the agentic firewall/network layer, improving CI reliability, and expanding project tooling support.
✨ What's New
aw.jsonproject support in theaddcommand (#58267) — makes it easier to add workflows into existingaw.json-based projects.🐛 Bug Fixes & Improvements
setup-rubyPATH precedence inside the Agentic Workflow Firewall (AWF) (#58311).📚 Documentation
repo-status(#58309).🔧 Internal
What's Changed
Full Changelog: github/gh-aw@v0.88.3...v0.88.4
v0.88.3Compare Source
🌟 Release Highlights
This release focuses on package manifest composability, safer scheduled upgrades, and hardened release-time security scanning.
✨ What's New
aw.ymlmanifests can now compose subpackages via animportsfield instead of duplicating file declarations, with cycle detection and unified install resolution across local and remote packages (#58233). See the package manifest reference.aw.json— scheduled auto-upgrade workflows can now opt into pre-releasegh-awversions by passing validated CLI options (e.g.--pre-releases) declared inaw.json, with malformed or unsupported options rejected at generation time (#58266).🐛 Bug Fixes & Improvements
0were incorrectly treated as missing due to truthiness checks; defaults are now preserved with a nullish fallback, restoring correct behavior fortype: numberinputs withdefault: 0(#58291).📚 Documentation
parser,repoutil,semverutil, andsliceutil(#58209).What's Changed
Full Changelog: github/gh-aw@v0.88.2...v0.88.3
v0.88.2Compare Source
🌟 Release Highlights
A focused patch release improving safe-output reliability and CI hygiene:
call_workflowinputs no longer get dropped during samples replay, sample-coverage gaps are now surfaced as warnings, and AI credit budgets are validated more safely to close a CodeQL alert.🐛 Bug Fixes & Improvements
call_workflowsamples replay droppingworkflow_name— ingestion previously strippedworkflow_name/inputsforcall_workflowsafe outputs, causing the apply job to fail with "Workflow name is empty" (#58113).--use-samplescompilation now warns when an enabled safe output has nosamples:entries, so silent no-op replay runs are easier to catch (#58112).env:, with strict integer validation before configuring the AWF firewall budget, resolving a CodeQL code-injection alert (#58116).Full Changelog: github/gh-aw@v0.88.1...v0.88.2
What's Changed
Full Changelog: github/gh-aw@v0.88.1...v0.88.2
v0.88.1Compare Source
v0.88.0Compare Source
🌟 Release Highlights
This release focuses on hardening the sandbox runtime, simplifying browser automation with a new Playwright CLI approach, and fixing dependency resolution for nested workflow imports.
✨ What's New
🐛 Bug Fixes & Improvements
What's Changed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.