[instructions] Instructions Janitor: sync network.md with release v0.89.21 hosted-web policy - #63399
Conversation
The Sep-24 sync (#63142) covered release v0.89.21, but PR #63212 (merged after that sync) added the network.hosted-web frontmatter field for Claude/Codex provider-hosted web tools without documenting it in .github/aw/network.md — only a one-line import-merge note was added to syntax-tools-imports.md. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
@copilot This PR looks ready for another pass.
|
|
🎉 Great work! This PR from the Instructions Janitor workflow looks ready for merge. The change adds much-needed documentation for the What's included:
Quality signals:
This PR aligns perfectly with the project's goal of keeping instructions current with each release. Ready to go!
|
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Ran the
Actions taken: verified the new Hand-off: a maintainer needs to re-trigger CI (close/reopen or push) before merge; the change is docs-only otherwise. |
|
@copilot Please review the current PR state, address any unresolved feedback or failing checks, refresh the branch if needed, and continue with the
|
Second
Diff remains a single docs file: Hand-off: a maintainer needs to approve the pending workflow runs and review the PR. Nothing further is actionable from my side. |
Summary
Latest release: v0.89.21 (2026-09-23). The prior sync PR (#63142, merged 2026-09-24 09:49 UTC) already brought instructions current with that release. This pass covers what changed in
.github/aw/since that sync.Release/change audit
.github/aw/since the last sync:e6374a3fandc9b6fbf9only bump.github/aw/actions-lock.json(a generated data file, no prose change needed).158f1a3(current HEAD, PR Add hosted web domain policies to workflow frontmatter #63212 "Add hosted web domain policies to workflow frontmatter") added the newnetwork.hosted-webfrontmatter field but only documented the import-merge precedence rule (one line insyntax-tools-imports.md). The field itself — syntax, semantics, deny-by-default behavior — was undocumented in.github/aw/network.md, the dedicated network reference file.Fix
network.hosted-web)" section to.github/aw/network.mdcovering: the object/falseshape,allowed/blockedmutual exclusivity,max-uses, deny-by-default whennetworkrestricts domains for Claude/Codex without an explicit policy, Claude/Codex-only scope, and a cross-link to the import-merge note insyntax-tools-imports.md.Size audit
.github/aw/*.mdfiles remain under their target limits.network.md: 185 → 205 lines (well under 400).Duplication audit
workflow-constraints.md,workflow-patterns.md,create-agentic-workflow.md,github-agentic-workflows.md— these already cross-referenceworkflow-constraints.mdrather than duplicating it. No changes needed.Accuracy audit
hosted-webfield, which is now documented. No other drift was identified while investigating that change.Test plan
network.hosted-webschema shape againstpkg/parser/schemas/main_workflow_schema.json(lines ~3599-3646) anddocs/adr/63212-add-hosted-web-domain-policies.md.wc -l .github/aw/*.md— all files under limits.🤖 Generated with [Claude Code]((claude.com/redacted)