GitHub shipped gh-aw (Agentic Workflows) v0.89.22 on 2026-09-27: docker-sbx/gVisor sandboxes are removed in favor of Cloud Hypervisor only; frontmatter gains network.hosted-web allow/block lists for provider-hosted Claude/Codex web tools; gh aw audit --group aggregates findings by run/code; Copilot prompts over 100 KiB stream via stdin. Also adds repo-memory backend, MCP payload size reporting, and tighter firewall checks.

Key Takeaways

  • ✓Shipped: v0.89.22 — docs at github.github.com/gh-aw / gh.io/gh-aw
  • ✓Breaking: docker-sbx/gVisor removed; set sandbox.agent.runtime to cloud-hypervisor
  • ✓network.hosted-web frontmatter policies for hosted Claude/Codex web tools
  • ✓gh aw audit --group aggregates findings; MCP payload sizes reported
  • ✓Copilot prompts >100 KiB stream via stdin; repo-memory backend for AIC guardrail
🔬

In-Depth Technical Analysis

Core Background & Industry Pain Points

Natural-language Markdown compiled into GitHub Actions is how teams scale agentic repo automation. Hosted Claude/Codex web tools can leave the Actions Workflow Firewall boundary; legacy docker-sbx/gVisor sandboxes split policy; audits lacked run/code aggregation and MCP payload visibility.

Architecture Highlights & Internals

v0.89.22 keeps isolation on Cloud Hypervisor only (#63034). Frontmatter adds [network.hosted-web](https://github.github.com/gh-aw/reference/network/) (#63212) plus enforced Copilot/web firewall checks. gh aw audit --group aggregates findings; MCP payload sizes are reported; repo-memory backs daily AIC guardrails; Copilot prompts >100 KiB stream via stdin.

Authoritative Benchmarks & Measured Scores

No public latency/throughput table ships with this release—validate on your repos via audit grouping, hosted-web deny logs, and large-prompt delivery. Do not treat release-footer AIC figures as a general benchmark.

Developer Hands-on Guide

Upgrade per docs / gh.io/gh-aw. Replace docker-sbx/gvisor with cloud-hypervisor, set network.hosted-web, and run gh aw audit --group. See the release notes.