The standalone dl.google.com entry in network.allowed is fully
covered by the java ecosystem identifier, which already includes
Google's Android/JDK distribution mirrors. Using the identifier
keeps the allowlist maintainable as Google's download host layout
shifts.
Refreshed regenerated artifacts from `gh aw compile`
(compiler v0.82.13 -> v0.83.4):
- .github/workflows/repo-assist.lock.yml
- .github/aw/actions-lock.json
- .github/workflows/agentics-maintenance.yml
- .github/skills/agentic-workflows/SKILL.md
The compile pass also normalises repo-assist.md itself: the model
field moves out of the engine block into a top-level `model:`, and
the redundant nested model under safe-outputs.threat-detection
is dropped.
Consolidate Go domains under the 'go' ecosystem identifier and add
dl.google.com for the toolchain zip host so GOTOOLCHAIN can fetch
go1.26.0 when the runner's Go is older. Restore permissions: read-all
with a clarifying comment (strict mode forbids write scopes; writes
go through safe-outputs). Regenerate lock files with gh-aw v0.82.13
and commit the auto-generated agentic maintenance workflow that backs
the hide-older-comments safe-output.
* chore(ci): upgrade gh-aw to v0.82.13 for gpt-5.6 model aliases
Pin compiler and setup action to v0.82.13 so repo-assist can keep
using gpt-5.6-luna (aliases were missing from v0.81.6).
* ci: pin actions/checkout to full SHA in copilot-setup-steps
Repo policy requires full-length commit SHAs for all actions.