About github/gh-aw
github/gh-aw is an open-source project on GitHub, mainly written in Go. GitHub Agentic Workflows It currently holds 5,321 stars and 571 forks with 0 open issues, and was last pushed on an unknown date (repository created unknown).
Project Overview
AI Homed tracks it on the Today's Trending board, currently at rank #44 with 53 new stars today.
GitHub Repository Details
README
GitHub Agentic Workflows
Agent quick links
Hello fellow agent! Welcome to GitHub Agentic Workflows = Actions + Agent + Safety. Here are some pointers to get you started in using this tool.
- Create a new workflow: https://raw.githubusercontent.com/github/gh-aw/main/create.md
- Install: https://raw.githubusercontent.com/github/gh-aw/main/install.md
- Package a workflow repository: https://raw.githubusercontent.com/github/gh-aw/main/package.md
- Reference: https://raw.githubusercontent.com/github/gh-aw/main/.github/aw/github-agentic-workflows.md
GitHub Agentic Workflows (gh-aw) lets developers define AI-powered repository automation in Markdown with YAML frontmatter and run AI agents securely through GitHub Actions. The gh-aw GitHub CLI extension compiles each agentic workflow into a standard GitHub Actions workflow.
Use conventional GitHub Actions for deterministic builds, tests, linting, deployments, and reproducible scripts. Add an agentic workflow when a task needs reasoning or interpretation, such as issue triage, pull-request review, CI failure investigation, documentation maintenance, dependency analysis, or repository reporting. GitHub Agentic Workflows complements existing CI/CD; it does not replace it.
Built-in AI engines include GitHub Copilot, Claude Code, OpenAI Codex, Google Gemini, and Pi. Agent jobs are read-only and sandboxed by default, and configured GitHub writes are normally applied through validated safe-outputs jobs with scoped permissions.
Contents
- Quick Start
- How Agentic Workflows work
- Security and permissions
- Documentation
- Contributing
- Community Contributions
- Related Projects
- Workshop
[!NOTE]
A security vulnerability was discovered in versions >= 0.83.3, < 0.85.4 and, as a result, those releases were retired as a pre-emptive measure.
Quick Start
Install the GitHub CLI extension:
gh extension install github/gh-aw
Then follow the GitHub Agentic Workflows quickstart to select an AI engine, add a sample workflow, and run it through GitHub Actions.
How Agentic Workflows work
An agentic workflow has two parts: YAML frontmatter configures triggers, permissions, tools, and the AI engine; the Markdown body tells the AI agent what to accomplish. The gh aw compile command validates this source and generates the .lock.yml workflow that GitHub Actions executes. Learn how GitHub Agentic Workflows works.
Security and permissions
Security, permissions, and controlled writes are core design concerns. The supported agent-job path defaults to read-only GitHub access and sandboxed execution. Safe outputs buffer configured writes, validate them, and apply them in separate jobs with scoped permissions. These controls are configurable, so workflow authors must review permissions, tools, network access, and generated files before deployment. Learn how GitHub Agentic Workflows handles security and permissions.
Using agentic workflows in your repository requires careful attention to security considerations and careful human supervision, and even then things can still go wrong. Use it with caution, and at your own risk.
Documentation
Use the GitHub Agentic Workflows documentation for these paths:
- Create an agentic workflow
- Choose and authenticate an AI engine
- Browse GitHub Agentic Workflows examples by task
- Review the security architecture
- Read the GitHub Agentic Workflows FAQ
Contributing
For development setup and contribution guidelines, see CONTRIBUTING.md.
Custom Go linters
To build and test repository custom linters:
go test ./pkg/linters//...go build ./cmd/lintersmake golint-custom
make golint-custom builds cmd/linters and runs the custom analyzers against ./cmd/... and ./pkg/....
🌍 Community Contributions
Community members whose issues were resolved — updated automatically.
@a-sjogren-accenture (2) @aaronspindler (1) @abbottdev (1) @abillingsley (2) @adam-cobb (1) @adamhenson (2) @adamtasteslikegood (1) @adhikjoshi (1) @ahmadabdalla (1) @ajfeldman6 (1) @akkikumar72 (1) @AkshatRaj00 (1) @alanpeabody (1) @alcastaneda (1) @AlexanderWert (1) @AlexDeMichieli (1) @alexsiilvaa (2) @alondahari (17) @alvistar (2) @AmoebaChant (1) @anthonymastreanvae (11) @aoxiangtianyu-go (1) @apenab (1) @arabkin (1) @arezero (6) @arthurfvives (8) @Artur- (1) @asatara (1) @askpaisa (1) @askpt (1) @astefan (1) @awoisoak (1) @b-dantas (1) @b2pacific (1) @babaakihiro (2) @bartul (1) @bbonafed (23) @beardofedu (1) @benissimo (10) @benvillalobos (12) @blavity-machine-user (1) @blozano-tt (9) @bmerkle (3) @boydj (2) @Bra1nFartz (1) @BrandonLewis (1) @brendanlapuma (1) @bryanchen-d (24) @bryanknox (1) @bshore-bf (1) @Calidus (8) @camposbrunocampos (2) @carlincherry (1) @carlosflorencio (1) @CatsMiaow (1) @chepa92 (1) @chrisfregly (2) @chrizbo (7) @CiscoRob (2) @ckittel (2) @cknight (2) @clementbolin (1) @cogni-ai-ee (2) @consulthys (3) @Corb3nik (3) @corygehr (20) @corymhall (1) @crmitchelmore (3) @DaanLucas (1) @dagecko (1) @Daidanny008 (1) @Dan-Albrecht (1) @Dan-Co (2) @danielmeppiel (8) @danquirk (2) @darwin-gonzales (1) @davidahmann (3) @davidslater (4) @dbudym-cs (1) @DeagleGross (4) @devantler (2) @deyaaeldeen (10) @dfrysinger (2) @dgolombek (1) @dholmes (3) @dhrapson (2) @DimaBir (1) @dkurepa (1) @dneimke (1) @DogeAmazed (1) @Dongbumlee (2) @doughgle (1) @drehelis (4) @DrPye (1) @dsfaccini (4) @dsibilio (4) @dsolteszopyn (2) @dsyme (39) @duncankmckinnon (1) @eaftan (3) @edburns (1) @edgeq (2) @ekbritecore (3) @elefthei (1) @elika56 (1) @emexelem (1) @enbw-mmattes (1) @eran-medan (1) @ericchansen (1) @ericstj (2) @Esomoire-consultancy-Company (1) @Etienne-M (5) @Evangelink (5) @fbecar22 (3) @fchareyr (1) @FDevTakima (1) @ferryhinardi (1) @flatiron32 (2) @florianbader (1) @fr4nc1sc0-r4m0n (3) @funkymonkeyjam (2) @G1Vh (1) @GandrotulaRajesh (1) @github-actions (11) @github-antoine-brechon (4) @GKersten (1) @glitch-ux (1) @golivax (1) @grahame-white (9) @graphaelli (1) @GregoireW (1) @gregsmi (2) @h-no (1) @h3y6e (2) @haavamoa (1) @haolpku (1) @HardMax71 (1) @harrisoncramer (2) @heaversm (1) @heiskr (9) @hermanho (1) @holwerda (3) @hpsin (1) @hrishikeshathalye (1) @ianreay (1) @IEvangelist (14) @ilja (5) @Infinnerty (1) @insop (1) @ivancea (9) @j-srodka (6) @JaganGopalkrish (1) @jamesadevine (4) @JamesNK (4) @JanKrivanek (4) @jaroslawgajewski (29) @JasonYeMSFT (1) [@Jasper13006 (1)](https://github.com