Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 9 additions & 0 deletions .changeset/enclave-github-issues-profile.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

63 changes: 59 additions & 4 deletions .github/aw/actions-lock.json
Original file line number Diff line number Diff line change
Expand Up @@ -215,6 +215,16 @@
"digest": "sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.7@sha256:40a1e30b1b8d70642d4292485146cd5af612730d7a6a2e12706ddd13df375059"
},
"ghcr.io/github/gh-aw-firewall/agent:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/agent:0.28.8",
"digest": "sha256:0a94ad1b9976881fb88ba5db3aa6f4f26b91535a1b00986799fe87cdbe6105f9",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.8@sha256:0a94ad1b9976881fb88ba5db3aa6f4f26b91535a1b00986799fe87cdbe6105f9"
},
"ghcr.io/github/gh-aw-firewall/agent:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/agent:0.28.9",
"digest": "sha256:54b2fb3068efc15a4cc1bd4033f8fa056a9b1779baeba0cb80ae95ea55e7e343",
"pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.28.9@sha256:54b2fb3068efc15a4cc1bd4033f8fa056a9b1779baeba0cb80ae95ea55e7e343"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.1",
"digest": "sha256:288e7d2a12d5b430500d739f9c16e20bb1ed51b91f986f3f3eccde189f489f5c",
Expand Down Expand Up @@ -250,6 +260,16 @@
"digest": "sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.7@sha256:4f209dd4cbc74d47a6c7379956143de293429d1b1b2fb2647776cdcbf65836a1"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8",
"digest": "sha256:531fb75f54c07d66200be6973033db98838d9e838316549fd9af09329a56b848",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.8@sha256:531fb75f54c07d66200be6973033db98838d9e838316549fd9af09329a56b848"
},
"ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9",
"digest": "sha256:a0ffb1dc926c6e5a500b336893e032a8f167d3db43c869be886874ef14280bb8",
"pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.28.9@sha256:a0ffb1dc926c6e5a500b336893e032a8f167d3db43c869be886874ef14280bb8"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.1",
"digest": "sha256:f931e5e1e13f765605d03ef9511fc755d779a51b76581ea14586e9871506a610",
Expand Down Expand Up @@ -285,6 +305,31 @@
"digest": "sha256:ebc8758c9b085ca244234e3e3ee22300d150095f9bfe7312ca8a61c5acb34a78",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.7@sha256:ebc8758c9b085ca244234e3e3ee22300d150095f9bfe7312ca8a61c5acb34a78"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8",
"digest": "sha256:c10f37b8677fc208c052b57f9035c4ad1b08c76d8e6d9545ee24173e31e29023",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.8@sha256:c10f37b8677fc208c052b57f9035c4ad1b08c76d8e6d9545ee24173e31e29023"
},
"ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9",
"digest": "sha256:38d7ac0585ee5aa6a06eb71e087d514b059db36005c7783c6485e0dfd36fea35",
"pinned_image": "ghcr.io/github/gh-aw-firewall/cli-proxy:0.28.9@sha256:38d7ac0585ee5aa6a06eb71e087d514b059db36005c7783c6485e0dfd36fea35"
},
"ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9",
"digest": "sha256:8d548153f18d9b44406bebe3f71e2e080c15c89cbf8c0f72e8aa7bc0681efcf2",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-agent:0.28.9@sha256:8d548153f18d9b44406bebe3f71e2e080c15c89cbf8c0f72e8aa7bc0681efcf2"
},
"ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9",
"digest": "sha256:9edfa59fe0cf96f86c0be2f3280743a95032cf730526a204f729a06fbe7e4727",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-mcp-server:0.28.9@sha256:9edfa59fe0cf96f86c0be2f3280743a95032cf730526a204f729a06fbe7e4727"
},
"ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9",
"digest": "sha256:def4cc9669c0723cbdcdcdbd0ad4c72b6d977c02e4e0978797e9116fffd8e25d",
"pinned_image": "ghcr.io/github/gh-aw-firewall/enclave-script:0.28.9@sha256:def4cc9669c0723cbdcdcdbd0ad4c72b6d977c02e4e0978797e9116fffd8e25d"
},
"ghcr.io/github/gh-aw-firewall/squid:0.28.1": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.1",
"digest": "sha256:9d428af47899bf18ef2d5618075777d76ef344c91e76c1f44ec1aaa0ee347e5f",
Expand Down Expand Up @@ -320,10 +365,20 @@
"digest": "sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.7@sha256:fb362a08d4d2f0da6c036e3f5d3b2fd87931e857fec3ca4a241cd2f2b61131f9"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.10": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.10",
"digest": "sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.10@sha256:08bb5fa417aed94b40a14e2b7b3ae457531a5f22b143a32fe58317139d9b8f42"
"ghcr.io/github/gh-aw-firewall/squid:0.28.8": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.8",
"digest": "sha256:9ede51772d89f6c70049753e36c62d5e3690e3cbd0fef327eb6c1fdd22c61b73",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.8@sha256:9ede51772d89f6c70049753e36c62d5e3690e3cbd0fef327eb6c1fdd22c61b73"
},
"ghcr.io/github/gh-aw-firewall/squid:0.28.9": {
"image": "ghcr.io/github/gh-aw-firewall/squid:0.28.9",
"digest": "sha256:3d5dba0b0a139bbb11b5d5b8b44f277d2b18f69cf43090e3c283d750cf864baa",
"pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.28.9@sha256:3d5dba0b0a139bbb11b5d5b8b44f277d2b18f69cf43090e3c283d750cf864baa"
},
"ghcr.io/github/gh-aw-mcpg:v0.4.12": {
"image": "ghcr.io/github/gh-aw-mcpg:v0.4.12",
"digest": "sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713",
"pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.4.12@sha256:92d5377b6bd32cd5b9306b2a553f7ef3549bccff9207e46f931e7249bc718713"
},
"ghcr.io/github/gh-aw-node": {
"image": "ghcr.io/github/gh-aw-node",
Expand Down
34 changes: 34 additions & 0 deletions .github/aw/enclaves.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,4 +46,38 @@ enclaves:
- A fresh masked capability is generated per workflow run and passed only to the MCP gateway and AWF, never to the primary agent environment.
- `timeout:` per enclave entry is capped at 540 seconds (AWF reserves the final 60 seconds of its 600-second finite-disclosure bucket for cleanup). The gateway itself enforces a 630-second tool timeout (600s AWF bucket + 30s transport allowance) — treat this as an enforcement bound, not a wall-clock guarantee.

## Agent GitHub Issues profile

Use only this closed opt-in:

```yaml
sandbox:
mcp:
version: v0.4.12
enclaves:
- agent:
model: gpt-5
github:
cli: issues-read-v1
repos:
- repo: octo-org/private-service
sensitivity: confidential
```

- `issues-read-v1` permits only paginated REST GETs for issue lists, one issue,
and that issue's comments. Use `gh api --method GET`; do not promise stock
`gh issue` commands because they may use denied GraphQL calls.
- GraphQL, search, writes, and all other REST paths fail closed.
- V1 allows at most one non-`public` repository in the agent entry.
- Public data inherits explicit `tools.github.min-integrity`, or the compiler's
primary default (`approved`) when the primary GitHub tool is omitted.
- Private repository responses carry the `private:<owner>/<repo>` DIFC secrecy
label.
- The compiler starts a dedicated bridge-mode mcpg proxy holding the PAT. AWF
supplies only its own local PAT-free proxy to the enclave and keeps the
`awf-egh1` invocation capability in a mode-`0600` file.
- The primary agent receives no enclave proxy address, key, CA path, container
identity, capability, PAT, or repository catalog.
- Minimum versions are AWF `v0.28.8` and mcpg `v0.4.12`.

See also: [agent-runtime-instructions.md](agent-runtime-instructions.md) for `sandbox.agent` fields, and [network.md](network.md) for network isolation defaults.
Loading
Loading