You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is the single canonical tracking issue for action items arising from new releases of the awf dependency. The dependency version updater workflow appends a new comment to this issue for each version bump, so the most recent activity lives in the comments below.
The companion version-bump PR for the first recorded range is titled chore(deps): update AWF_VERSION to 0.28.26.
None identified. Upstream's v0.28.5 notes explicitly state "There are no breaking changes for existing awf CLI users" for the security-hardening changes below, and no other release in this range documents a removed/renamed flag, changed config schema, or removed egress/safe-output surface.
Security fixes
Stricter allowWrite filesystem-boundary enforcement (v0.28.5, PR #7634) — AWF now more strictly enforces that sandboxed agents can only write within explicitly allowed paths. Upstream's own upgrade notes ask consumers relying on allowWrite scoping to confirm existing allowlists still cover intended write paths. ado-aw should double-check any mounts it passes with write access (e.g. the ado-proxy -v "${AZ_WRAPPER_DIR}:/var/lib/ado-proxy:rw" mount in agentic_pipeline.rs) still work under the tightened enforcement.
CLI artifact redirects routed through scoped Squid egress (v0.28.5, PR #7635) — closes a bypass where CLI artifact download redirects could skip the domain-allowlist egress path. No action needed beyond the version bump; purely upstream-side hardening.
Notable features for ado-aw to adopt
--api-proxy-ca-cert <path> (v0.28.10, PR #7816) — lets the AWF api-proxy sidecar trust an additional CA certificate for upstream TLS verification. Could be useful if ado-aw ever needs to route through a corporate TLS-inspecting proxy for the Copilot/model API traffic.
--network-subnet <cidr> (v0.28.16, PR #8398) — relocates the awf-net Docker network off its default 172.30.0.0/24 subnet to avoid collisions with host/cluster networks. Worth surfacing as a compiler-level escape hatch if ADO-hosted agent pools ever collide with that default range.
--reflect (v0.28.13) — starts AWF, queries the API proxy's /reflect endpoint, and prints its JSON response; a lightweight diagnostic mode that could help ado-aw audit/trace verify API-proxy model routing without a full agent run.
GitHub REST/GraphQL API point budgets (v0.28.26, PR #8978) — adds --max-github-api-points-rest / --max-github-api-points-graphql budget controls to the api-proxy. Could let ado-aw cap GitHub API consumption per Agent job run, complementing its existing tool/network allow-listing model.
Deprecations
None identified in this range.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
index.crates.io
To allow these domains, add them to the network.allowed list in your workflow frontmatter:
Rolling upstream release action items —
awfThis is the single canonical tracking issue for action items arising from new releases of the
awfdependency. The dependency version updater workflow appends a new comment to this issue for each version bump, so the most recent activity lives in the comments below.The companion version-bump PR for the first recorded range is titled
chore(deps): update AWF_VERSION to 0.28.26.awf0.27.32→0.28.26Releases analyzed
Breaking changes
awfCLI users" for the security-hardening changes below, and no other release in this range documents a removed/renamed flag, changed config schema, or removed egress/safe-output surface.Security fixes
allowWritefilesystem-boundary enforcement (v0.28.5, PR #7634) — AWF now more strictly enforces that sandboxed agents can only write within explicitly allowed paths. Upstream's own upgrade notes ask consumers relying onallowWritescoping to confirm existing allowlists still cover intended write paths. ado-aw should double-check any mounts it passes with write access (e.g. the ado-proxy-v "${AZ_WRAPPER_DIR}:/var/lib/ado-proxy:rw"mount inagentic_pipeline.rs) still work under the tightened enforcement.Notable features for ado-aw to adopt
--api-proxy-ca-cert <path>(v0.28.10, PR #7816) — lets the AWF api-proxy sidecar trust an additional CA certificate for upstream TLS verification. Could be useful if ado-aw ever needs to route through a corporate TLS-inspecting proxy for the Copilot/model API traffic.--network-subnet <cidr>(v0.28.16, PR #8398) — relocates theawf-netDocker network off its default172.30.0.0/24subnet to avoid collisions with host/cluster networks. Worth surfacing as a compiler-level escape hatch if ADO-hosted agent pools ever collide with that default range.--reflect(v0.28.13) — starts AWF, queries the API proxy's/reflectendpoint, and prints its JSON response; a lightweight diagnostic mode that could helpado-aw audit/traceverify API-proxy model routing without a full agent run.--max-github-api-points-rest/--max-github-api-points-graphqlbudget controls to the api-proxy. Could let ado-aw cap GitHub API consumption per Agent job run, complementing its existing tool/network allow-listing model.Deprecations
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
index.crates.ioTo allow these domains, add them to the
network.allowedlist in your workflow frontmatter:See Network Configuration for more information.