The standalone dl.google.com entry in network.allowed is fully
covered by the java ecosystem identifier, which already includes
Google's Android/JDK distribution mirrors. Using the identifier
keeps the allowlist maintainable as Google's download host layout
shifts.
Refreshed regenerated artifacts from `gh aw compile`
(compiler v0.82.13 -> v0.83.4):
- .github/workflows/repo-assist.lock.yml
- .github/aw/actions-lock.json
- .github/workflows/agentics-maintenance.yml
- .github/skills/agentic-workflows/SKILL.md
The compile pass also normalises repo-assist.md itself: the model
field moves out of the engine block into a top-level `model:`, and
the redundant nested model under safe-outputs.threat-detection
is dropped.
Consolidate Go domains under the 'go' ecosystem identifier and add
dl.google.com for the toolchain zip host so GOTOOLCHAIN can fetch
go1.26.0 when the runner's Go is older. Restore permissions: read-all
with a clarifying comment (strict mode forbids write scopes; writes
go through safe-outputs). Regenerate lock files with gh-aw v0.82.13
and commit the auto-generated agentic maintenance workflow that backs
the hide-older-comments safe-output.
* Initial plan
* ci: add explicit setup-go step to use Go 1.26 matching go.mod
Both testing.yml and testing-git.yml were relying on whatever Go version
shipped in ghcr.io/jguer/yay-builder:latest (Go 1.24.13), which is
incompatible with the go 1.26 / toolchain go1.26.0 declarations in
go.mod and scripts/go.mod, causing build/lint failures in PR #2917.
Add an actions/setup-go step (pinned to the same hash already used in
pages.yml) immediately after checkout so CI always picks up Go 1.26 as
read from go.mod, regardless of what the builder image contains.
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
---------
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Jguer <8071073+Jguer@users.noreply.github.com>
* chore(ci): upgrade gh-aw to v0.82.13 for gpt-5.6 model aliases
Pin compiler and setup action to v0.82.13 so repo-assist can keep
using gpt-5.6-luna (aliases were missing from v0.81.6).
* ci: pin actions/checkout to full SHA in copilot-setup-steps
Repo policy requires full-length commit SHAs for all actions.
* docs: add static docs site generator and Pages deployment
Render doc/ (man page, Lua API, init.lua template) into a static HTML site via scripts/gendocs and publish it to GitHub Pages on push to next.
* update gendoc
* cleanup arch build
* don't doubleptade
* fix pacman-git build
* fix final issues with some sandbox kernels
* use quay because docker is out of steam
* remove docker hub
* -si on testing
* fix: correct Docker manifest creation in builder image workflow
- Fix "invalid reference format" error by properly separating Docker Hub and
GitHub Container Registry tags
- Use short SHA format instead of long format for more manageable tags
- Improve manifest list creation process to handle multiple registries correctly
- Ensure proper handling of ghcr.io prefix for GitHub Container Registry
* update golangci and comment out community
* fix(ci): do not attempt to install extra packages for building pacman-git
* install needed in ci image
* fix missing pacman key
* wip
* add missing deps