github/gh-aw v0.90.1(2026-09-30T17:20:00Z)在 0.90.0 friction-cost/noop graders 之后,扩展 safe-output 支撑的独立 ledger(含回放投影、导入共享工作流时保留默认 ledger),并加厚审计:ledger 交易、威胁检测结果、experiment/evals、friction cost 归因。另含 add-labels 收窄、assign-to-agent 必填 labels、编译期强制自托管 Runner、sandbox frontmatter kebab-case,以及 Claude Code CLI 钉到 2.1.280。

核心要点速览 (Key Takeaways)

  • ✓发版:v0.90.1 于 2026-09-30T17:20:00Z(对照 v0.90.0)
  • ✓Ledger:standalone safe-output ledger + replay projections;导入共享工作流时保留默认 ledger(#64354/#64420/#64464)
  • ✓审计:ledger transactions、threat-detection outcomes、experiment/evals、friction costs 归因到 audit sources(#64509/#64506/#64339/#64338)
  • ✓治理:收窄 add-labels;assign-to-agent required-labels;编译期强制 self-hosted runner(#64173);sandbox frontmatter kebab-case
  • ✓引擎:Claude Code CLI 更新至 2.1.280;文档见 gh-aw README 与 GitHub Next Agentic Workflows
🧭

阅读完核心要点?进一步了解模型实力与实际开销

7 大权威镜像天梯跑分与 29+ 款主流编程套餐横向比价测算

🔬

深度技术解析与实战评估

核心背景与行业痛点 仓库级 Agentic Workflow 一旦写入 issue/PR/标签,就需要可回放的账本与威胁检测痕迹,否则合规审计只能翻 Actions 日志。上一版 [v0.90.0](https://github.com/github/gh-aw/releases/tag/v0.90.0) 已露出 friction cost 与 noop graders;0.90.1 把 ledger 独立化并强制自托管 Runner,堵住「共享工作流导入冲掉默认账本」与「在 GitHub-hosted 上跑高权限 agent」两类运维风险。国内读者应读 gh-aw README 与 GitHub Next 项目页。 ### 架构亮点与底层机制 [v0.90.1](https://github.com/github/gh-aw/releases/tag/v0.90.1)(2026-09-30T17:20:00Z)交付:standalone safe-output-backed ledgers + replay projections,导入共享工作流时保留默认 ledger(#64354/#64420/#64464);审计制品扩展 ledger transactions、threat-detection outcomes、experiment/evals 数据,以及 friction cost 对 audit sources 的归因(#64509/#64506/#64339/#64338);add-labels schema 收窄,assign-to-agent 增加 required-labels 门闩(#64179/#64266/#64174);编译期校验 self-hosted runner(#64173);sandbox frontmatter 统一 kebab-case(#64302)。引擎侧 Claude Code CLI 钉到 2.1.280,并刷新若干 action pin。 ### 权威 Benchmark 与实测跑分对比 发行说明未给出 SWE-bench 类模型分数;发布摘要提到生成流程约 13.3 AIC / 11.5K 量级(workflow 自计量),不宜当作跨产品基准。请以 tag 时间 2026-09-30T17:20:00Z 与 compare [v0.90.0...v0.90.1](https://github.com/github/gh-aw/compare/v0.90.0...v0.90.1) 为锚。建议在自有 runner 上编译含 ledger 的工作流,确认缺少 runs-on: self-hosted 时编译失败,并抽查 threat-detection / friction-cost 制品路径。 ### 开发者实战落地与开箱指南 1. 升级 CLI/动作到 [v0.90.1](https://github.com/github/gh-aw/releases/tag/v0.90.1),对照 README。 2. 为写入类工作流配置 standalone ledger,导入共享 workflow 后检查默认 ledger 是否仍在。 3. 打开 threat-detection / evals 相关步骤,核对 runtimes.node override 是否被 Setup Node 步骤尊重。 4. 确保生产 agent 工作流声明自托管 Runner;assign-to-agent 补齐 required labels。背景:GitHub Next Agentic Workflows。