diff --git a/.github/aw/actions-lock.json b/.github/aw/actions-lock.json
new file mode 100644
index 0000000000..0837817a13
--- /dev/null
+++ b/.github/aw/actions-lock.json
@@ -0,0 +1,31 @@
+{
+ "entries": {
+ },
+ "containers": {
+ "ghcr.io/github/gh-aw-firewall/agent:0.25.58": {
+ "image": "ghcr.io/github/gh-aw-firewall/agent:0.25.58",
+ "digest": "sha256:a316a2c021accba8a9ea194c75466b0c4a166be6ac783bf8c2d0afd73373dec2",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/agent:0.25.58@sha256:a316a2c021accba8a9ea194c75466b0c4a166be6ac783bf8c2d0afd73373dec2"
+ },
+ "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58": {
+ "image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58",
+ "digest": "sha256:43a5cdbe4e1156920dcdaab26d6c6761777d5c6bdc572d7d07b11739fb34c749",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58@sha256:43a5cdbe4e1156920dcdaab26d6c6761777d5c6bdc572d7d07b11739fb34c749"
+ },
+ "ghcr.io/github/gh-aw-firewall/squid:0.25.58": {
+ "image": "ghcr.io/github/gh-aw-firewall/squid:0.25.58",
+ "digest": "sha256:558682b7b6313a5443cbb3d702899823bd732f991c8b52db6b5b8066abefe7a1",
+ "pinned_image": "ghcr.io/github/gh-aw-firewall/squid:0.25.58@sha256:558682b7b6313a5443cbb3d702899823bd732f991c8b52db6b5b8066abefe7a1"
+ },
+ "ghcr.io/github/gh-aw-mcpg:v0.3.22": {
+ "image": "ghcr.io/github/gh-aw-mcpg:v0.3.22",
+ "digest": "sha256:ce5c6f5461b077af0d8e8eb1763436e85153f8e9531117d58a7bdb23de71f00a",
+ "pinned_image": "ghcr.io/github/gh-aw-mcpg:v0.3.22@sha256:ce5c6f5461b077af0d8e8eb1763436e85153f8e9531117d58a7bdb23de71f00a"
+ },
+ "ghcr.io/github/github-mcp-server:v1.1.0": {
+ "image": "ghcr.io/github/github-mcp-server:v1.1.0",
+ "digest": "sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029",
+ "pinned_image": "ghcr.io/github/github-mcp-server:v1.1.0@sha256:71b07d9abecb83b4a2595bcd8ccb35f9a0166361a12335f9e16da1ef07172029"
+ }
+ }
+}
diff --git a/.github/workflows/supply-chain-review.lock.yml b/.github/workflows/supply-chain-review.lock.yml
index 0440374c0a..99722a435a 100644
--- a/.github/workflows/supply-chain-review.lock.yml
+++ b/.github/workflows/supply-chain-review.lock.yml
@@ -1,4 +1,4 @@
-# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"4510909d7b52684e7b58d97ce0b6c491a28acc18fd6c0b1d3adfa55860b70654","body_hash":"767dbf393fc7c7494b531bc639648d109551e1cb43bd5fa0d2d126827861ba7e","compiler_version":"v0.77.5","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4-nano"}
+# gh-aw-metadata: {"schema_version":"v4","frontmatter_hash":"835aaf34c5688fe6d4315c8eab49dde1ecd53e9bf49be43ccf4fc41bb63f34f4","body_hash":"ccb05611b0ff5785ed4beddd0e21579d44fbd292b76319f10f570c88bdc42ab4","compiler_version":"v0.77.5","strict":true,"agent_id":"copilot","agent_model":"gpt-5.4-nano"}
# gh-aw-manifest: {"version":1,"secrets":["COPILOT_GITHUB_TOKEN","GH_AW_GITHUB_MCP_SERVER_TOKEN","GH_AW_GITHUB_TOKEN","GITHUB_TOKEN"],"actions":[{"repo":"actions/checkout","sha":"de0fac2e4500dabe0009e67214ff5f5447ce83dd","version":"v6.0.2"},{"repo":"actions/download-artifact","sha":"3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c","version":"v8.0.1"},{"repo":"actions/github-script","sha":"3a2844b7e9c422d3c10d287c895573f7108da1b3","version":"v9.0.0"},{"repo":"actions/setup-node","sha":"48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e","version":"v6.4.0"},{"repo":"actions/upload-artifact","sha":"043fb46d1a93c77aae656e7c1c64a875d1fc6a0a","version":"v7.0.1"},{"repo":"github/gh-aw-actions/setup","sha":"3ea13c02d765410340d533515cb31a7eef2baaf0","version":"v0.77.5"}],"containers":[{"image":"ghcr.io/github/gh-aw-firewall/agent:0.25.58"},{"image":"ghcr.io/github/gh-aw-firewall/api-proxy:0.25.58"},{"image":"ghcr.io/github/gh-aw-firewall/squid:0.25.58"},{"image":"ghcr.io/github/gh-aw-mcpg:v0.3.22"},{"image":"ghcr.io/github/github-mcp-server:v1.1.0"},{"image":"node:lts-alpine","digest":"sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14","pinned_image":"node:lts-alpine@sha256:2bdb65ed1dab192432bc31c95f94155ca5ad7fc1392fb7eb7526ab682fa5bf14"}]}
# ___ _ _
# / _ \ | | (_)
@@ -16,14 +16,14 @@
#
# This file was automatically generated by gh-aw (v0.77.5). DO NOT EDIT.
#
-# To update this file, edit Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef and run:
+# To update this file, edit Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545 and run:
# gh aw compile
# Not all edits will cause changes to this file.
#
# For more information: https://github.github.com/gh-aw/introduction/overview/
#
#
-# Source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef
+# Source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545
#
# Secrets used:
# - COPILOT_GITHUB_TOKEN
@@ -145,7 +145,7 @@ jobs:
GH_AW_INFO_AWF_VERSION: "v0.25.58"
GH_AW_INFO_AWMG_VERSION: ""
GH_AW_INFO_FIREWALL_TYPE: "squid"
- GH_AW_INFO_FRONTMATTER_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
+ GH_AW_INFO_FRONTMATTER_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
GH_AW_INFO_BODY_MODIFIED: "false"
GH_AW_COMPILED_STRICT: "true"
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -257,20 +257,20 @@ jobs:
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/create_prompt_first.sh"
{
- cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF'
+ cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF'
- GH_AW_PROMPT_9fcd1296c4e25283_EOF
+ GH_AW_PROMPT_6740ff15455080cb_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/xpia.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/temp_folder_prompt.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/markdown.md"
cat "${RUNNER_TEMP}/gh-aw/prompts/safe_outputs_prompt.md"
- cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF'
+ cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF'
Tools: add_comment, submit_pull_request_review, add_labels, missing_tool, missing_data, noop
- GH_AW_PROMPT_9fcd1296c4e25283_EOF
+ GH_AW_PROMPT_6740ff15455080cb_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/mcp_cli_tools_prompt.md"
- cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF'
+ cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF'
The following GitHub context information is available for this workflow:
{{#if github.actor}}
@@ -299,15 +299,15 @@ jobs:
{{/if}}
- GH_AW_PROMPT_9fcd1296c4e25283_EOF
+ GH_AW_PROMPT_6740ff15455080cb_EOF
cat "${RUNNER_TEMP}/gh-aw/prompts/github_mcp_tools_with_safeoutputs_prompt.md"
if [ "$GITHUB_EVENT_NAME" = "issue_comment" ] && [ -n "$GH_AW_IS_PR_COMMENT" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review_comment" ] || [ "$GITHUB_EVENT_NAME" = "pull_request_review" ]; then
cat "${RUNNER_TEMP}/gh-aw/prompts/pr_context_prompt.md"
fi
- cat << 'GH_AW_PROMPT_9fcd1296c4e25283_EOF'
+ cat << 'GH_AW_PROMPT_6740ff15455080cb_EOF'
{{#runtime-import .github/workflows/supply-chain-review.md}}
- GH_AW_PROMPT_9fcd1296c4e25283_EOF
+ GH_AW_PROMPT_6740ff15455080cb_EOF
} > "$GH_AW_PROMPT"
- name: Interpolate variables and render templates
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
@@ -522,9 +522,9 @@ jobs:
mkdir -p "${RUNNER_TEMP}/gh-aw/safeoutputs"
mkdir -p /tmp/gh-aw/safeoutputs
mkdir -p /tmp/gh-aw/mcp-logs/safeoutputs
- cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_3d652443abcb6121_EOF'
+ cat > "${RUNNER_TEMP}/gh-aw/safeoutputs/config.json" << 'GH_AW_SAFE_OUTPUTS_CONFIG_b3e67e93cdb2db2c_EOF'
{"add_comment":{"hide_older_comments":true,"max":1},"add_labels":{"allowed":["security:low","security:medium","security:high"]},"create_report_incomplete_issue":{},"missing_data":{},"missing_tool":{},"noop":{"max":1,"report-as-issue":"true"},"report_incomplete":{},"submit_pull_request_review":{"max":1}}
- GH_AW_SAFE_OUTPUTS_CONFIG_3d652443abcb6121_EOF
+ GH_AW_SAFE_OUTPUTS_CONFIG_b3e67e93cdb2db2c_EOF
- name: Generate Safe Outputs Tools
env:
GH_AW_TOOLS_META_JSON: |
@@ -757,7 +757,7 @@ jobs:
mkdir -p /home/runner/.copilot
GH_AW_NODE=$(which node 2>/dev/null || command -v node 2>/dev/null || echo node)
- cat << GH_AW_MCP_CONFIG_df9f290c1ebfe6b7_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs"
+ cat << GH_AW_MCP_CONFIG_d2d29ce847428284_EOF | "$GH_AW_NODE" "${RUNNER_TEMP}/gh-aw/actions/start_mcp_gateway.cjs"
{
"mcpServers": {
"github": {
@@ -798,7 +798,7 @@ jobs:
"payloadDir": "${MCP_GATEWAY_PAYLOAD_DIR}"
}
}
- GH_AW_MCP_CONFIG_df9f290c1ebfe6b7_EOF
+ GH_AW_MCP_CONFIG_d2d29ce847428284_EOF
- name: Mount MCP servers as CLIs
id: mount-mcp-clis
continue-on-error: true
@@ -1098,8 +1098,8 @@ jobs:
GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
GH_AW_NOOP_MAX: "1"
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_NOOP_REPORT_AS_ISSUE: "true"
@@ -1116,8 +1116,8 @@ jobs:
env:
GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
GH_AW_DETECTION_CONCLUSION: ${{ needs.detection.outputs.detection_conclusion }}
GH_AW_DETECTION_REASON: ${{ needs.detection.outputs.detection_reason }}
@@ -1135,8 +1135,8 @@ jobs:
GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
GH_AW_MISSING_TOOL_CREATE_ISSUE: "true"
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
with:
github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
script: |
@@ -1151,8 +1151,8 @@ jobs:
GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
GH_AW_REPORT_INCOMPLETE_CREATE_ISSUE: "true"
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
with:
github-token: ${{ secrets.GH_AW_GITHUB_TOKEN || secrets.GITHUB_TOKEN }}
script: |
@@ -1167,8 +1167,8 @@ jobs:
env:
GH_AW_AGENT_OUTPUT: ${{ steps.setup-agent-output-env.outputs.GH_AW_AGENT_OUTPUT }}
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
GH_AW_RUN_URL: ${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}
GH_AW_AGENT_CONCLUSION: ${{ needs.agent.result }}
GH_AW_WORKFLOW_ID: "supply-chain-review"
@@ -1507,8 +1507,8 @@ jobs:
GH_AW_ENGINE_VERSION: "1.0.55"
GH_AW_WORKFLOW_ID: "supply-chain-review"
GH_AW_WORKFLOW_NAME: "Supply Chain Review"
- GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef"
- GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/b2070730e7482fb8d2791e97d7b288fdf3b106ef/.github/workflows/supply-chain-review.md"
+ GH_AW_WORKFLOW_SOURCE: "Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545"
+ GH_AW_WORKFLOW_SOURCE_URL: "${{ github.server_url }}/Alfresco/alfresco-build-tools/blob/52467f0241079de71fe14591f97bdec7555ab545/.github/workflows/supply-chain-review.md"
outputs:
code_push_failure_count: ${{ steps.process_safe_outputs.outputs.code_push_failure_count }}
code_push_failure_errors: ${{ steps.process_safe_outputs.outputs.code_push_failure_errors }}
diff --git a/.github/workflows/supply-chain-review.md b/.github/workflows/supply-chain-review.md
index 55ec7185d5..4806d21555 100644
--- a/.github/workflows/supply-chain-review.md
+++ b/.github/workflows/supply-chain-review.md
@@ -32,7 +32,7 @@ safe-outputs:
allowed: [security:low, security:medium, security:high]
submit-pull-request-review:
-source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@b2070730e7482fb8d2791e97d7b288fdf3b106ef
+source: Alfresco/alfresco-build-tools/.github/workflows/supply-chain-review.md@52467f0241079de71fe14591f97bdec7555ab545
---
# Supply Chain Review
@@ -65,7 +65,7 @@ Before collecting external data, identify and exclude internal/private dependenc
For each internal dependency found:
1. Remove it from the analysis pipeline — do NOT query OSV.dev, OpenSSF Scorecard, or registry APIs for these packages (they will fail or return irrelevant data).
-2. Record the package name, ecosystem, old version, and new version in a separate "Internal Dependencies (Skipped)" list.
+2. Record the package name (with `@` replaced by `(at)` for GitHub comment compatibility), ecosystem, old version, and new version in a separate "Internal Dependencies (Skipped)" list.
3. Continue with Step 2 only for the remaining external/public dependencies.
If ALL changed dependencies are internal, skip Steps 2-4 and proceed directly to Step 5, posting a report that lists the internal dependencies and notes that no external supply chain analysis was performed.
@@ -276,7 +276,18 @@ If no suspicious patterns are found, assign a score of 0-10 and risk level LOW.
## Step 5 — Post Findings as PR Comment
-Post a structured report in the following format:
+Post a structured report in the following format.
+
+**CRITICAL: Sanitize all `@` symbols before posting**
+
+GitHub enforces a maximum of 10 mentions per comment. Package names containing `@` (like `@hyland/core`, `@alfresco/js-api`) are interpreted as user/team mentions and trigger this limit, causing comment post failures.
+
+**Before generating the comment text**:
+
+1. Replace **every** `@` symbol in package names with `(at)` — e.g., `@hyland/core` → `(at)hyland/core`
+2. Apply this transformation to ALL occurrences: table cells, headings, inline code blocks, findings sections, reason columns
+3. This applies to both external and internal dependencies
+4. Do NOT skip this step — even if only a few packages are affected, GitHub counts all `@` symbols
```txt
## Supply Chain Security Review
@@ -287,15 +298,15 @@ Post a structured report in the following format:
### Internal Dependencies (Skipped)
-| Package | Ecosystem | Old Version | New Version | Reason |
-|--------------|-----------|-------------|-------------|----------------------------|
-| @hyland/core | npm | 3.1.0 | 3.2.0 | Internal (@hyland/* scope) |
+| Package | Ecosystem | Old Version | New Version | Reason |
+|-------------------|-----------|-------------|-------------|---------------------------------|
+| (at)hyland/core | npm | 3.1.0 | 3.2.0 | Internal ((at)hyland/* scope) |
_These dependencies are internal packages not available on public registries. External API checks were skipped._
### Findings
-#### `` ( -> ) —
+#### `` ( -> ) —
**Risk Score**: /100