Skip to content

Add standalone safe-output-backed ledger configuration - #64354

Merged
pelikhan merged 20 commits into
mainfrom
copilot/implement-new-ledger-design
Sep 30, 2026
Merged

pelikhan merged 20 commits into
mainfrom
copilot/implement-new-ledger-design

Conversation

Copilot AI commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Redesigns ledger configuration around standalone tools.ledger entries, Git branches under ledgers/<name>, read-only SQLite projections, and safe-output append requests instead of the legacy repo-memory MCP path.

  • Configuration

    • Supports concise default ledgers and named multi-ledger configurations.
    • Validates inline and repository-relative schemas, limits, names, and branch derivation.
    • Rejects legacy tools.repo-memory.ledger usage.
  • Agent integration

    • Adds generated prompt guidance for read-only SQLite projections and deferred persistence.
    • Registers the ledger_append safe-output capability.
  • Trusted persistence

    • Adds temporary-ID normalization with deterministic record IDs.
    • Introduces the push_ledger_changes job boundary and versioned transaction artifact reader.

Example:

tools:
  ledger:
    findings:
      schema:
        type: object
        required: [severity, subject]
        properties:
          severity:
            type: string
          subject:
            type: string

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 21.4 AIC · ⌖ 8.64 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again


Run: https://github.com/github/gh-aw/actions/runs/36658333295

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 46.3 AIC · ⌖ 8.88 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again


Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 24.9 AIC · ⌖ 8.58 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

Copilot AI linked an issue Sep 29, 2026 that may be closed by this pull request
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Redesign gh-aw ledger as standalone safe-output-backed tool Add standalone safe-output-backed ledger configuration Sep 29, 2026
Copilot AI requested a review from pelikhan September 29, 2026 21:39
@pelikhan
pelikhan marked this pull request as ready for review September 29, 2026 21:39
Copilot AI balanced review requested due to automatic review settings September 29, 2026 21:39
@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot ensure ledger changes are pushed to git upstream. Reuse repo-memory git helpers.

Comment on lines +29 to +31
const id = finalId(transactionId, index);
if (request.temp_id) mapping.set(`${ledger}:${request.temp_id}`, id);
normalized.push({ ledger, transaction_id: transactionId, record: { ...request.record, id } });

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Core safe-output handling, projection generation, validation, artifact transfer, and durable Git persistence are not yet operational.

Review effort: Balanced
Findings: 6 High severity · 3 Medium severity

Open (9)
What changed in this PR

Adds standalone tools.ledger configuration and scaffolding for safe-output-backed ledger persistence.

Changes:

  • Parses ledger configuration, schemas, limits, and prompt guidance.
  • Registers ledger_append with temporary-ID normalization.
  • Adds a trusted push_ledger_changes job boundary.
File Description
pkg/​workflow/​workflow_data.go Stores normalized ledger configuration.
pkg/​workflow/​unified_prompt_step.go Adds ledger prompt guidance.
pkg/​workflow/​tools_types.go Defines the ledger tool type.
pkg/​workflow/​tools_parser.go Parses tools.ledger.
pkg/​workflow/​safe_outputs_validation_config.go Defines append-request validation fields.
pkg/​workflow/​safe_outputs_tools_computation.go Enables the append tool.
pkg/​workflow/​safe_outputs_config_generation.go Generates append handler configuration.
pkg/​workflow/​ledger.go Implements configuration and prompt generation.
pkg/​workflow/​ledger_test.go Tests parsing and prompts.
pkg/​workflow/​ledger_job.go Generates the persistence job.
pkg/​workflow/​js/​safe_outputs_tools.json Describes the append tool.
pkg/​workflow/​jobs.go Registers the persistence job name.
pkg/​workflow/​compiler_orchestrator_workflow.go Extracts configuration and rejects legacy usage.
pkg/​workflow/​compiler_jobs.go Adds persistence and conclusion dependencies.
pkg/​parser/​schemas/​main_workflow_schema.json Allows standalone ledger frontmatter.
actions/​setup/​js/​push_ledger_changes.cjs Reads transaction artifacts and reports results.
actions/​setup/​js/​ledger_transactions.test.cjs Tests transaction normalization.
actions/​setup/​js/​ledger_transactions.cjs Normalizes IDs and references.

Comment on lines +29 to +31
const id = finalId(transactionId, index);
if (request.temp_id) mapping.set(`${ledger}:${request.temp_id}`, id);
normalized.push({ ledger, transaction_id: transactionId, record: { ...request.record, id } });

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in fed4a69: the trusted normalizer validates configured schemas and record/patch limits, rejects reserved fields, and emits only normalized records.

Comment on lines +31 to +34
result.ledgers[name] = {
requested: ledger.appends.length,
validated: ledger.appends.length,
persisted: 0,

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Implemented in cfb75e6 and wired in fed4a69: persistence hydrates and reconciles the ledger branch, commits with the repo-memory retry/CAS helpers, and reports durable counts only after the push succeeds.

Comment thread pkg/workflow/ledger.go Outdated
Comment on lines +184 to +185
case "additionalProperties", "oneOf", "anyOf":
// These keywords are accepted by the existing JSON-schema validator.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: schema validation now walks the full tree, rejects expressions recursively, and compiles the schema before accepting it.

Comment thread pkg/workflow/ledger_job.go Outdated
Comment on lines +9 to +12
func (c *Compiler) buildPushLedgerChangesJob(data *WorkflowData, threatDetectionEnabled bool) *Job {
needs := []string{string(constants.AgentJobName), string(constants.ActivationJobName)}
if IsDetectionJobEnabled(data.SafeOutputs) && threatDetectionEnabled {
needs = append(needs, string(constants.DetectionJobName))

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in fed4a69: push_ledger_changes depends on safe_outputs and downloads the versioned transaction artifact before reconciliation.

Comment on lines +57 to +58
if data.LedgerConfig != nil && data.LedgerConfig.Enabled() {
safeOutputsConfig["ledger_append"] = map[string]any{"max": 100}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in fed4a69: the safe-output manager registers ledger_append and writes the validated versioned transaction artifact.

Comment on lines +236 to +237
if data.LedgerConfig != nil && data.LedgerConfig.Enabled() {
enabledTools["ledger_append"] = struct{}{}

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: standalone ledger configuration enables the safe-output pipeline, MCP setup, and ledger_append registration without requiring unrelated safe outputs.

Comment on lines +492 to +496
workflowData.LedgerConfig = toolsConfig.Ledger
if workflowData.RepoMemoryConfig != nil {
for _, memory := range workflowData.RepoMemoryConfig.Memories {
if memory.Ledger != nil {
return errors.New("tools.repo-memory.ledger is no longer supported; migrate to tools.ledger")

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: the legacy ledger key is detected before repo-memory parsing so users receive the migration error consistently.

Comment thread pkg/workflow/ledger.go
if schema == "" || strings.HasPrefix(schema, "/") || strings.Contains(schema, "..") || strings.ContainsAny(schema, `\${{}`) {
return LedgerConfig{}, fmt.Errorf("tools.ledger.%s.schema must be a repository-relative path without expressions or traversal", name)
}
cfg.SchemaPath = schema

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: repository-relative schemas are resolved, size-bounded, validated, and serialized into the trusted ledger configuration.

Comment thread pkg/workflow/ledger.go
var b strings.Builder
b.WriteString("Persistent ledgers available (SQLite is read-only and disposable):\n")
for _, ledger := range config.Ledgers {
fmt.Fprintf(&b, "- %s: %s\n", ledger.Name, filepath.Join(ledgerProjectionRoot, ledger.Name, "ledger.db"))

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in fed4a69: the agent setup hydrates ledger branches and creates the read-only SQLite projection before execution.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

✅ Design Decision Gate 🏗️ completed the design decision gate check. See the comment below for the result and any generated ADR draft.

🏗️ ADR gate enforced by Design Decision Gate 🏗️

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

✅ PR Code Quality Reviewer completed the code quality review.

No GitHub review was submitted because safeoutputs create_pull_request_review_comment and submit_pull_request_review were both blocked with: Permission denied and could not request permission from user.

🔎 Code quality review by PR Code Quality Reviewer

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

✅ Ponytail Reviewer completed successfully!

Lean already. Ship.

Generated by Ponytail Reviewer for #64354

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

✅ Test Quality Sentinel completed test quality analysis.

Test Quality Sentinel skipped because pre-fetch PR data was unavailable: unable to fetch test file diff

🧪 Test quality analysis by Test Quality Sentinel

@github-actions

Copy link
Copy Markdown
Contributor
🏗️ ADR Required — draft added for PR #64354

Result

This PR requires ADR enforcement because it adds more than 100 new lines in business-logic directories (default_business_additions: 381). I did not find an existing ADR in the PR body, and the branch ADR set did not already cover this ledger redesign.

Evidence used

  • adr-prefetch-summary.json: has_implementation_label=false, requires_adr_by_default_volume=true
  • PR title: Add standalone safe-output-backed ledger configuration
  • PR body: redesigns ledger configuration around standalone tools.ledger, ledgers/<name> branches, read-only SQLite projections, and safe-output append requests
  • Diff files including:
    • pkg/workflow/ledger.go
    • pkg/workflow/ledger_job.go
    • pkg/workflow/js/safe_outputs_tools.json
    • actions/setup/js/ledger_transactions.cjs
    • actions/setup/js/push_ledger_changes.cjs

Action taken

I added a draft ADR here:

  • docs/adr/64354-add-standalone-safe-output-backed-ledger-configuration.md

Next action for the author

Review the draft ADR, correct any missing rationale or trade-offs, and keep it with the implementation as the design record for this ledger architecture change.

🏗️ ADR gate enforced by Design Decision Gate 🏗️ · pi · gpt54 · 20.3 AIC · ⌖ 9.81 AIC · ⊞ 10.4K · ◷
Comment /review to run again

@github-actions

Copy link
Copy Markdown
Contributor

Comment Memory

reviewed_at: 2026-09-29T21:52:51.982Z
review_event: BLOCKED
top_themes:
  - temp-id rewriting mutates arbitrary string payloads
  - malformed tools.ledger config is silently dropped in NewTools callers
  - safeoutputs review submission blocked by permission-denied errors
files_reviewed:
  - actions/setup/js/ledger_transactions.cjs
  - actions/setup/js/ledger_transactions.test.cjs
  - actions/setup/js/push_ledger_changes.cjs
  - pkg/parser/schemas/main_workflow_schema.json
  - pkg/workflow/compiler_jobs.go
  - pkg/workflow/compiler_orchestrator_workflow.go
  - pkg/workflow/jobs.go
  - pkg/workflow/js/safe_outputs_tools.json
  - pkg/workflow/ledger.go
  - pkg/workflow/ledger_job.go
  - pkg/workflow/ledger_test.go
  - pkg/workflow/safe_outputs_config_generation.go
  - pkg/workflow/safe_outputs_tools_computation.go
  - pkg/workflow/safe_outputs_validation_config.go
  - pkg/workflow/tools_parser.go
  - pkg/workflow/tools_types.go
  - pkg/workflow/unified_prompt_step.go
  - pkg/workflow/workflow_data.go
comment_count: 0

Note

This comment is managed by comment memory.

It stores persistent context for this thread in the code block at the top of this comment.
Edit only the text inside the backtick fences; workflow metadata and the footer are regenerated automatically.

Learn more about comment memory

🔎 Code quality review by PR Code Quality Reviewer · copilot · gpt54 · 73.9 AIC · ⌖ 7.1 AIC · ⊞ 20.2K · ◷
Comment /review to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Skills-Based Review 🧠

Applied /tdd and /codebase-design — requesting changes. Existing bot/Copilot inline comments already flag the critical functional gaps (no real Git persistence in push_ledger_changes.cjs, no schema/limit enforcement in normalization, missing ledger_append handler wiring, and a nil-guard that skips ledger-only workflows in computeEnabledToolNames). This review adds three test-coverage and code-quality findings on top of those.

📋 Key Themes & Highlights

Key Themes

  • Silent error swallowing: NewTools discards tools.ledger parse errors instead of propagating them, so invalid configs can silently disable the ledger rather than fail the build — this diverges from the GitHub.reposParseErr pattern already established for surfacing config errors from NewTools callers.
  • Missing test coverage on the trusted job: push_ledger_changes.cjs — the one file with contents: write permissions performing the actual (currently stubbed) persistence — ships with zero tests, unlike its sibling ledger_transactions.cjs.
  • Duplicated branches: parseLedgerToolConfig's single and len(root) == 0 cases are identical and can be collapsed.

Positive Highlights

  • ✅ Deterministic, hash-based temporary-ID generation with clear duplicate/unknown-ledger rejection in ledger_transactions.cjs, backed by a solid test file.
  • ✅ Clean separation of the untrusted normalization step from the trusted persistence job boundary, matching the existing repo-memory architecture.
  • ✅ Legacy tools.repo-memory.ledger migration is explicitly rejected with an actionable error message.

@copilot please address the review comments above.

🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · copilot · sonnet50 · 61.8 AIC · ⌖ 14.9 AIC · ⊞ 10K
Comment /matt to run again

if val, exists := toolsMap["repo-memory"]; exists {
tools.RepoMemory = parseRepoMemoryTool(val)
}
if val, exists := toolsMap["ledger"]; exists {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] NewTools silently discards tools.ledger parse errors: on failure it returns tools with Ledger unset instead of propagating the error, so an invalid tools.ledger config compiles as if ledger support were simply absent rather than failing loudly. Since ParseToolsConfig already validates this same config via parseLedgerToolConfig(raw) a few lines above (tools_types.go), the two error paths can disagree — a config could pass ParseToolsConfig but silently lose Ledger here if NewTools is called directly (e.g. mcp_cli_mount.go:183, tools.go:71, workflow_builder.go:70), none of which check for the swallowed error.

💡 Suggested fix

Mirror the GitHub.reposParseErr pattern already used for repo config: store the error on the Tools struct (e.g. tools.ledgerParseErr) so every caller path — not just ParseToolsConfig — can detect and surface it, or have NewTools itself return (*Tools, error).

A regression test asserting that an invalid tools.ledger config surfaces an error through every NewTools call site (not just ParseToolsConfig) would catch this class of silent-swallow bug.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: NewTools retains ledger parse errors and compiler validation surfaces them rather than silently dropping invalid configuration.

Comment thread pkg/workflow/ledger.go Outdated
single = true
}
}
if single {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/codebase-design] The single and len(root) == 0 branches are identical (both build parseLedgerConfig(defaultLedgerName, root) and return early) — this duplication makes the two-forms-are-unambiguous logic harder to follow and easy to diverge on the next edit.

💡 Suggested simplification
if single || len(root) == 0 {
    cfg, err := parseLedgerConfig(defaultLedgerName, root)
    if err != nil {
        return nil, err
    }
    result.Ledgers = []LedgerConfig{cfg}
    return result, nil
}

Collapsing the two branches keeps the "concise default ledger" special case in one place and reduces the surface for future logic drift between them.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Simplified in e938829: the concise default-ledger and empty configuration cases now share one branch.

@@ -0,0 +1,58 @@
// @ts-check

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[/tdd] Unlike ledger_transactions.cjs, which ships ledger_transactions.test.cjs, this new trusted-persistence entry point has no test file at all — no coverage for readTransactions() parsing/validation, the per-ledger result shape, or main()'s GITHUB_OUTPUT write path.

💡 Suggested tests
  • readTransactions() returns the empty-ledger default when GH_AW_LEDGER_TRANSACTIONS is unset.
  • readTransactions() throws on malformed JSON, wrong version, or a non-object ledgers field.
  • main() produces persisted: 0/reconciled: 0 for a well-formed artifact today (documenting the current stub behavior) so a future PR that wires in real persistence has a clear regression baseline to update deliberately rather than by accident.

Given this file is the trusted job with contents: write permissions reconciling ledger branches, it's the highest-risk file in the PR to ship without any test coverage.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in fed4a69: added persistence tests covering transaction artifact validation and the trusted push path.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot please address the current blocking review feedback (especially the ledger validation/persistence wiring and safe-output handler gaps), refresh the branch if needed, and run the pr-finisher skill before handing this back for maintainer review. Blocking review threads and requested changes are still open on the current head.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 21.4 AIC · ⌖ 8.64 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Impeccable Review — distill/extract (refactor/new-feature: standalone ledger config)

This PR introduces a large surface (config parsing, safe-output tool, trusted persistence job) but several pieces are stubs or unwired, and existing automated reviewers (GHAS, Copilot) already flagged the most severe gaps on this PR:

  • push_ledger_changes.cjs never actually persists anything (persisted: 0 hard-coded, no git commit/push).
  • ledger_append has no config-key-to-handler wiring in safe_output_handler_manager.cjs, so accepted requests are never processed.
  • No JSON Schema validation or max-record-kb/max-patch-kb enforcement is applied to agent-submitted records before they're written into the "validated" transaction artifact.
  • The JSON-Schema keyword allowlist in validateInlineLedgerSchema accepts oneOf/anyOf/additionalProperties without recursing into their values, so ${{ }} expressions can slip through inside those keywords.
  • push_ledger_changes job has no dependency on safe_outputs / no artifact-download step wiring to GH_AW_LEDGER_TRANSACTIONS, so it can't get the real transaction file.
  • The prompt (buildLedgerPromptSection) advertises a SQLite projection file that nothing ever creates.

New finding from this review: pkg/workflow/tools_parser.go (NewTools, ~line 169) — an invalid tools.ledger config makes the function return tools immediately, silently skipping parsing of every tool declared after ledger (timeout, startup-timeout, cli-proxy, all custom MCP tools). Verified locally with a unit test reproducing the silent drop. Other tool parsers in the same function (e.g. bash) log-and-continue on invalid config; ledger should do the same instead of aborting the whole function.

Given the ledger feature is not yet functionally wired end-to-end (per the existing unresolved bot comments) and this new correctness bug affects unrelated tool parsing, requesting changes before merge.

🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · copilot · sonnet50 · 153.9 AIC · ⌖ 13.3 AIC · ⊞ 8.1K

Comment thread pkg/workflow/tools_parser.go Outdated
if val, exists := toolsMap["ledger"]; exists {
ledger, err := parseLedgerToolConfig(val)
if err != nil {
return tools

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: an invalid tools.ledger config causes NewTools to return tools immediately (line 169), silently skipping parsing of every tool listed after ledger in the function — timeout, startup-timeout, cli-proxy, and all custom MCP tools (the loop that populates tools.Custom never runs). Reproduced locally: with {"ledger": {"schema": "../bad.json"}, "timeout": 30, "cli-proxy": true, "custom-tool": {...}}, tools.Timeout, tools.CLIProxy, and tools.Custom all come back empty/nil even though only the ledger config is invalid. Other tool parsers in this function (e.g. bash) log a warning and continue instead of aborting the whole function. Fix by logging the ledger parse error (like the bash case) and falling through to continue parsing, rather than returning early.

@copilot please address this.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in e938829: invalid ledger parsing records the error while continuing to parse the remaining tools; validation later surfaces the error.

@github-actions

Copy link
Copy Markdown
Contributor

🎉 Excellent work on the ledger redesign! The change has solid test coverage, a clear description, and a focused scope. It looks ready for review. 🚀

Generated by ✅ Contribution Check · copilot · auto · 34.2 AIC · ⌖ 6.84 AIC · ⊞ 9.1K · ◷

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot please address the remaining forward-progress items on the current head: re-run the JS test shard failure, close out the still-open review threads that already have author replies, refresh the branch if needed, and run the pr-finisher skill before handing this back for maintainer review. Latest context: ledger follow-up fixes were pushed through ac5791f, but JS Tests (shard 4/4) is still failing and multiple review threads remain unresolved.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 46.3 AIC · ⌖ 8.88 AIC · ⊞ 9.5K · ◷
Comment /souschef to run again

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

@copilot run pr-finisher skill

Ran the pr-finisher pass. The local checks and security re-review are complete; the final patch is fa0349c. One unrelated eslint-factory README/export parity test still fails, and review-thread resolution is unavailable in this environment.

@copilot

  • merge main, fix conflict
  • do a end-to-end review to make sure everything is wired up from the front matter, to the safe output tools description, to safe output handler, to packaging th...

The branch already included current main (13cb13c) with no conflict. I reviewed the ledger path end to end and fixed the inherited-property schema-validation bypass; the security re-review found no remaining issue in the patch. Commit: fa0349c.

@pelikhan

Copy link
Copy Markdown
Collaborator

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

@copilot fix https://github.com/github/gh-aw/actions/runs/36661139545/job/109720002273

Fixed in 5d0485b: the two setup-repository tests that change the process-wide working directory now run serially, preventing temporary checkout cleanup from breaking concurrent tests.

@pelikhan

Copy link
Copy Markdown
Collaborator

@copilot resolve the merge conflicts on this branch.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot this branch still needs forward progress before maintainer review: resolve the merge conflicts on the current head (use make merge-main), then re-run the pr-finisher skill and close out any still-open review threads that already have your follow-up replies. Latest maintainer direction is to fix the conflicts on this branch.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 18.2 AIC · ⌖ 8.69 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

…-ledger-design

# Conflicts:
#	.github/workflows/copilot-centralization-optimizer.lock.yml
#	.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml
#	.github/workflows/daily-mcp-concurrency-analysis.lock.yml
#	.github/workflows/smoke-repo-memory-ledger.lock.yml

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>

Copilot AI commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

@copilot resolve the merge conflicts on this branch.

Resolved the merge conflicts by merging the latest origin/main and regenerating the affected workflow lock files. Merge commit: 518c4189.

Copilot AI commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

pr-sous-chef
@copilot this branch still needs forward progress before maintainer review: resolve the merge conflicts on the current head (use make merge-main), then re-run the pr-finisher skill an...

Ran make merge-main; the branch was already current with origin/main and no conflicts remained. Re-ran the pr-finisher validation: fmt, lint, unit tests, full tests, and workflow recompilation pass. The prior CI unit-test failure was fixed in 5d0485b; current CI runs require maintainer re-triggering.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

pr-sous-chef
@copilot please address the remaining forward-progress items on the current head: re-run the pr-finisher skill on top of the latest merge-resolution commit, then close out any still-open review threads that already have your follow-up replies before handing this back for maintainer review. Latest context: the branch reports merge-conflict resolution and a clean validation pass at 518c4189, but the PR still has stale unresolved review feedback / thread cleanup pending.

Generated by 👨🍳 PR Sous Chef

Generated by 👨‍🍳 PR Sous Chef · pi · gpt54 · 24.9 AIC · ⌖ 8.58 AIC · ⊞ 9.7K · ◷
Comment /souschef to run again

@pelikhan
pelikhan merged commit 456c98a into main Sep 30, 2026
45 of 46 checks passed
@pelikhan
pelikhan deleted the copilot/implement-new-ledger-design branch September 30, 2026 05:03
Copilot stopped work on behalf of gh-aw-bot due to an error September 30, 2026 05:04
@github-actions

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.90.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ledger v2

5 participants