Skip to content

Restore external threat detection with gh-aw v0.89.21 - #69629

Merged
wtgodbe merged 2 commits into
dotnet:mainfrom
wtgodbe:wtgodbe/restore-external-threat-detection
Oct 1, 2026
Merged

wtgodbe merged 2 commits into
dotnet:mainfrom
wtgodbe:wtgodbe/restore-external-threat-detection

Conversation

@wtgodbe

@wtgodbe wtgodbe commented Oct 1, 2026

Copy link
Copy Markdown
Member

Restore external threat detection with gh-aw v0.89.21

  • You've read the Contributor Guide and Code of Conduct.
  • You've included unit or integration tests for your change, where applicable.
  • You've included inline docs for your change, where applicable.
  • There's an open issue for the PR that you are making. If you'd like to propose a new feature or change, please open an issue to discuss the change or find an existing issue.

Remove inline detector workarounds and restore the fixed external detector.

Description

github/gh-aw#61857 is included in gh-aw v0.89.21: its merge commit, 0053f61aedb203413ff12768bd4e79d402285af9, is an ancestor of the release tag. That release compiles workflows with external threat-detect v0.5.2.

  • Remove features.gh-aw-detection: false from browsertesting-deps-update, community-pr-issue-check, cswin32-update, issue-triage-agent, pr-attention-pulse, and test-quarantine.
  • Regenerate all six lockfiles with gh-aw v0.89.21 and the dotnet/aspnetcore schedule seed. No generated lockfiles were edited manually.
  • Restore test-quarantine to v0.89.21. The upgrade in Upgrade agentic workflows to gh-aw v0.89.21 #69568 was reverted for that workflow by the backflow in [main] Source code updates from dotnet/dotnet #69553.
  • Preserve detection failure handling: test-quarantine and pr-attention-pulse retain continue-on-error: false; the other four retain true. Pulse retains its explicit detector model and PAT-pool binding.
  • Update the Pulse regression assertions to require external detector installation, execution, result consumption, and failure handling.

The PAT-pool configuration problem observed in run https://github.com/dotnet/aspnetcore/actions/runs/36847957662 is being handled separately. This PR does not change credentials or PAT selection.

Validation

  • Passed: gh aw compile browsertesting-deps-update community-pr-issue-check cswin32-update issue-triage-agent pr-attention-pulse test-quarantine --schedule-seed dotnet/aspnetcore --strict --no-check-update -- six workflows compiled; rerunning after rebasing produced no changes under .github.
  • Passed: pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PulseReviewRequirements.ps1 -- all 15 controls passed. The updated external-detector control fails against the previous source/lock pair because the inline workaround is still present.
  • Passed: comparison of all six generated detection jobs against the previous lockfiles confirmed unchanged enforcement modes and external detector v0.5.2 installation, execution, and result-file consumption.
  • Passed: git diff --check upstream/main...HEAD.
  • Not green: pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PRAttentionPulse.ps1, using pinned v0.89.21 action sources via an isolated GH_CONFIG_DIR. On the rebased branch, the suite reports PublishedSnapshot/sanitizer-stable-unicode, four ContextTime cases, and Retrieval/documented-consumer failures. Retrieval encounters a PowerShell Get-Item error for its generated hidden fixture directory on macOS. These failures are not changed by this PR.
  • Tooling limitation: compilation with --actionlint cannot invoke its Docker-backed linter because Docker is unavailable locally. A direct native actionlint run reports existing syntax/expression diagnostics; comparing baseline and changed YAML produced identical diagnostic sets for all six workflows, with no additional diagnostics.

Outstanding live validation

Representative scheduled or manually dispatched runs must still complete external detection and safe outputs after the separately managed PAT-pool configuration is restored. This PR does not claim that end-to-end acceptance criterion is verified.

Fixes #69420

Remove the six inline-detector workarounds and regenerate their workflows with threat-detect v0.5.2 while preserving detection enforcement modes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 15:50
@wtgodbe
wtgodbe requested a review from a team as a code owner October 1, 2026 15:50

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Live acceptance remains unverified, and the regression test does not enforce the required detector digest pins.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Restores external threat detection for six agentic workflows using gh-aw v0.89.21.

Changes:

  • Removes legacy inline-detector overrides.
  • Regenerates lockfiles with pinned threat-detect v0.5.2.
  • Updates Pulse regression checks for external detection.
File Description
.github/​workflows/​test-quarantine.md Removes inline-detector workaround.
.github/​workflows/​test-quarantine.lock.yml Regenerates workflow with v0.89.21.
.github/​workflows/​pr-attention-pulse.md Enables external detection.
.github/​workflows/​pr-attention-pulse.lock.yml Adds external detector pipeline.
.github/​workflows/​pr-attention-pulse-tests/​Test-PulseReviewRequirements.ps1 Updates detector regression controls.
.github/​workflows/​issue-triage-agent.md Removes inline-detector workaround.
.github/​workflows/​issue-triage-agent.lock.yml Regenerates external detection job.
.github/​workflows/​cswin32-update.md Removes inline-detector workaround.
.github/​workflows/​cswin32-update.lock.yml Regenerates external detection job.
.github/​workflows/​community-pr-issue-check.md Removes inline-detector workaround.
.github/​workflows/​community-pr-issue-check.lock.yml Regenerates external detection job.
.github/​workflows/​browsertesting-deps-update.md Removes inline-detector workaround.
.github/​workflows/​browsertesting-deps-update.lock.yml Regenerates external detection job.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Assert-True ($workflow -match "(?m)^ gh-aw-detection: false\r?$") "The inline-detector workaround must remain enabled."
Assert-True ($detector.Contains("copilot_harness.cjs") -and $detector.Contains("parse_threat_detection_results.cjs")) "The generated detector must execute and parse inline detection."
Assert-True ($workflow -notmatch "(?m)^ gh-aw-detection: false\r?$") "The inline-detector workaround must be removed."
Assert-True ($detector.Contains('install_threat_detect_binary.sh" v0.5.2 ')) "The generated detector must install the fixed v0.5.2 release."
if: always() && steps.detection_guard.outputs.run_detection == 'true'
continue-on-error: true
run: |
bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.2 --artifact-base-url https://github.com/github/gh-aw-threat-detection/releases/download --sha256-amd64 b4ecda6a8f1ee09913c40b58e5e9d3337d2173618d41b1bfdef9207e4e7959b9 --sha256-arm64 f6260a0f9ad72bcb67c7af19c4ce262ca34e2c3d5ccbf912832a8bd277200904
Check both v0.5.2 Linux digests on the same installer invocation. Reject missing, stale, uppercase, and separately placed digest arguments.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@wtgodbe
wtgodbe merged commit fa28c8a into dotnet:main Oct 1, 2026
13 checks passed
@dotnet-milestone-bot dotnet-milestone-bot Bot added this to the 12.0-preview1 milestone Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Remove inline threat detection workaround after gh-aw update

2 participants