# gh-aw-firewall

> GitHub Agentic Workflows Firewall

- **URL**: https://www.freshcrate.ai/projects/gh-aw-firewall
- **Author**: github
- **Category**: Uncategorized
- **Latest version**: `v0.25.65` (2026-06-05)
- **License**: MIT
- **Source**: https://github.com/github/gh-aw-firewall
- **Homepage**: https://github.github.com/gh-aw-firewall/
- **Language**: TypeScript
- **GitHub**: 58 stars, 17 forks
- **Registry**: github
- **Tags**: `agentic`, `github`, `typescript`, `workflows`

## Description

GitHub Agentic Workflows Firewall

## Recent releases

| Version | Date | Urgency | Changes |
| --- | --- | --- | --- |
| `v0.25.65` | 2026-06-05 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.65 -->    **Full Changelog**: https://github.com/github/gh-aw-firewall/compare/v0.25.64...v0.25.65  ## CLI Options  ``` Usage: awf [options] [command] [args...]  Network firewall for agentic workflows with domain whitelisting  Arguments:   args                                           Command and arguments to execute (use -- to separate from options)  Options:     -V, --version                                  out |
| `v0.25.58` | 2026-05-30 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.58 -->  ## What's Changed ### Other Changes * feat(api-proxy): pre-startup model validation via requestedModel config by @lpcox in https://github.com/github/gh-aw-firewall/pull/4025 * fix: synthesize identity files for ARC-DinD environments by @lpcox in https://github.com/github/gh-aw-firewall/pull/4026 * Refactor retry-logic tests to centralize shared HTTPS/stdout mocks by @Copilot in https://github.com/github/gh- |
| `v0.25.56` | 2026-05-27 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.56 -->  ## What's Changed ### Other Changes * Filter unresolvable model aliases from /reflect and models.json by @Copilot in https://github.com/github/gh-aw-firewall/pull/3803 * fix(api-proxy): prevent stream_options injection into OpenAI Responses API requests by @Copilot in https://github.com/github/gh-aw-firewall/pull/3805 * Refactor host-access port spec parsing to remove duplicate logic by @Copilot in https:// |
| `v0.25.50` | 2026-05-21 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.50 -->  ## What's Changed ### Other Changes * chore: recompile all workflow lock files by @lpcox in https://github.com/github/gh-aw-firewall/pull/3345 * refactor: split token-tracker.js into four focused modules by @Copilot in https://github.com/github/gh-aw-firewall/pull/3343 * Make `BuildConfigInputs` internal to `build-config` by @Copilot in https://github.com/github/gh-aw-firewall/pull/3358 * Refactor iptables/ |
| `v0.25.46` | 2026-05-14 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.46 -->  ## What's Changed ### Other Changes * fix: skip node --version check under QEMU emulation in agent Dockerfile by @lpcox in https://github.com/github/gh-aw-firewall/pull/3136   **Full Changelog**: https://github.com/github/gh-aw-firewall/compare/v0.25.45...v0.25.46  ## CLI Options  ``` Usage: awf [options] [command] [args...]  Network firewall for agentic workflows with domain whitelisting  Arguments:   args |
| `v0.25.42` | 2026-05-09 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.42 -->  ## What's Changed ### Documentation * [docs] docs: document Azure OpenAI OIDC (Entra-only) authentication by @github-actions[bot] in https://github.com/github/gh-aw-firewall/pull/2612 * [docs] docs: sync architecture docs with src/ refactoring by @github-actions[bot] in https://github.com/github/gh-aw-firewall/pull/2677 ### Other Changes * refactor: extract shared Docker test fixture constants to eliminate |
| `v0.25.37` | 2026-05-04 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.37 -->  ## What's Changed ### Other Changes * refactor: consolidate env-var forwarding in docker-manager.ts into typed arrays + loops by @Copilot in https://github.com/github/gh-aw-firewall/pull/2434 * refactor(pid-tracker): extract resolvePidFromTcpContent to deduplicate async/sync track logic by @Copilot in https://github.com/github/gh-aw-firewall/pull/2432 * refactor(cli-workflow): unexport internal-only interfa |
| `v0.25.29` | 2026-04-28 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.29 -->  ## What's Changed ### Other Changes * Harden api-proxy startup healthcheck to reduce early unhealthy flaps by @Copilot in https://github.com/github/gh-aw-firewall/pull/2155 * fix: correct firewall issue dispatcher tracking issue link format by @Copilot in https://github.com/github/gh-aw-firewall/pull/2161 * Ensure Copilot bootstrap can find Node.js inside AWF chroot by @Copilot in https://github.com/github/ |
| `v0.25.28` | 2026-04-22 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.28 -->  ## What's Changed ### Other Changes * chore: upgrade and recompile all workflows to gh-aw v0.69.2 by @lpcox in https://github.com/github/gh-aw-firewall/pull/2144 * chore: bump Copilot CLI to v1.0.34 in smoke-copilot by @lpcox in https://github.com/github/gh-aw-firewall/pull/2147   **Full Changelog**: https://github.com/github/gh-aw-firewall/compare/v0.25.27...v0.25.28  ## CLI Options  ``` Usage: awf [option |
| `v0.25.26` | 2026-04-21 | High | <!-- Release notes generated using configuration in .github/release.yml at v0.25.26 -->  ## What's Changed ### Documentation * [docs] docs: update --image-tag CLI reference for digest-aware format by @github-actions[bot] in https://github.com/github/gh-aw-firewall/pull/2095 ### Other Changes * Optimize `security-guard` Claude token usage via prompt cache alignment and smaller diff payloads by @Copilot in https://github.com/github/gh-aw-firewall/pull/2085 * Add digest-aware AWF runtime image pin |

## Citation

- HTML: https://www.freshcrate.ai/projects/gh-aw-firewall
- Markdown: https://www.freshcrate.ai/projects/gh-aw-firewall.md
- Dependencies JSON: https://www.freshcrate.ai/api/projects/gh-aw-firewall/deps

_Generated by freshcrate.ai. Indexes github releases for AI-agent ecosystem packages._
