Top
Best
New

Posted by mooreds 12 hours ago

GitHub Agentic Workflows(github.github.io)
198 points | 110 commentspage 3
mbrumlow 4 hours ago||
I think it is funny they all these companies are spending a ton and racing to have a AI story. It’s almost like none of the executives understand AI.

If you are changing your product for AI - you don’t understand AI. AI doesn’t need you to do this, and it doesn’t make you a AI company if you do.

AI companies like Anthropic, OpenAI, and maybe Google, simply will integrate at a more human leave and use the same tools humans used in the past, but do so at a higher speed, reliability.

All this effort wasted, as AI don’t need it, and your company is spending millions maybe billions to be an AI company that likely will be severely devalued as AI advances.

snowstormsun 8 hours ago||
Surely this won't be a security nightmare.
wiether 8 hours ago|
Don't worry, you can just setup an Agentic Workflow Firewall!

https://github.com/github/gh-aw-firewall

resquawk 3 hours ago||
This firewall is enabled by default
microflash 11 hours ago||
Soon: AgentHub Git Workflows
onionisafruit 10 hours ago||
Copilot Hub Enterprise With Copilot
throwup238 11 hours ago|||
At which point the AI figures out its easier to just switch to jj
aaronharnly 10 hours ago||
WorkHub Agent Gitflows?
idan 6 hours ago||
Hello HN! The Agentic Workflows project has been on the githubnext.com website for a while, and we recently moved the documentation and repo over to the `github` org.

This is early research out of GitHub Next building on our continuous AI [1] theme, so we'd love for you to kick the tires and share your thoughts. We'd be happy to answer questions, give support, whatever you need. One of the key goals of this project is to figure out how to put guardrails around agents running in GitHub actions. You can read more about our security architecture [1], but at a high level we do the following:

- We run the agent in a sandbox, with minimal to no access to secrets

- We run the agent in a firewall, so it can only access the sites you specify

- We have created a system called "*safe outputs*" that limits what write operations the agent can perform to only the ones you specify. For example, if you create an Agentic Workflow that should only comment on an issue, it will not be able to open a new issue, propose a PR, etc.

- We run MCPs inside their own sandboxes, so an attacker can’t leverage a compromised server to break out or affect other components

We find that there's something very compelling about the shape of this — delegating chores to agents in the same way that we delegate CI to actions. It's certainly not perfect yet, but we're finding new applications for this every day and teams at GitHub are already creating agentic workflows for their own purposes, whether it's engineering or issue management or PR hygiene.

> Why is it on github.github.io and not github.com?

GitHub Pages domains are always ORGNAME.github.io. Now that we've moved the repo over to the `github` org, that's the domain. When this graduates from being a technology preview to a full-on product, we imagine it'll get a spot on github.com/somewhere.

> Why is GitHub Next exploring this?

Our job at GitHub is to build applications that leverage the latest technology. There are a lot of applications of _asynchronous_ AI which we suspect might become way bigger than _synchronous_ AI. Agentic Workflows can do things that are not possible without an LLM. For example, there's no linter in existence that can tell me if my documentation and my code has diverged. That's just one new capability. We think there's a huge category of these things here and the only way to make it good is to … make it!

> Where can I go to talk with folks about this and see what others are cooking with it?

https://gh.io/next-discord in the #continuous-ai channel!

[1] https://githubnext.com/projects/continuous-ai/

[2] https://github.github.io/gh-aw/introduction/architecture/

(edit: right I forgot that HN doesn't do markdown links)

monkaiju 5 hours ago||
Wasnt GitHub supposed to be doing a feature freeze while they move to Azure?(1) They certainly could use it as their stability has plummeted. After moving to a self-hosted Forgejo I'll never go back. My UI is instant, my actions are faster than they ever were on GH (with or without accelerators like Blacksmith.sh), I dont constantly get AI nonsense crammed into my UI, and I have way better uptime all with almost no maintenance (mostly thanks to uCore)...

GH just doesnt really have much a value proposition for anything that isnt a non-trivial, star gathering obsessed, project IMO...

1: https://thenewstack.io/github-will-prioritize-migrating-to-a...

Edit: typo

ewuhic 10 hours ago||
Go: check

YAML: check

Markdown: check

Wrong level of abstraction: check

Shit slop which will be irrelevant in less than a year time: check

Manager was not PIP'd: check

tuananh 9 hours ago||
since generation is not deterministic, how do they verify the lock file?
resquawk 3 hours ago||
Generation of the lock file is deterministic.

See here for information about determinism https://github.github.com/gh-aw/reference/faq/#determinism

onionisafruit 8 hours ago||
The generation of the workflow file from the input markdown file is deterministic. It's what the agent does when running the workflow that is non-deterministic.
dgxyz 7 hours ago||
Apologies for the bad language but this can fuck off. They need to fix everything before pasting more shit on top.

I’m getting to the point of throwing Jenkins back in it’s that bad.

GitHub gives git a bad name and reputation.

enmyj 9 hours ago|
GitHub fix your uptime then come talk to me about agentic workflows
More comments...