Repository navigation
Restore external threat detection with gh-aw v0.89.21 - #69629
Merged
wtgodbe merged 2 commits intoOct 1, 2026
Merged
Conversation
Remove the six inline-detector workarounds and regenerate their workflows with threat-detect v0.5.2 while preserving detection enforcement modes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Live acceptance remains unverified, and the regression test does not enforce the required detector digest pins.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Restores external threat detection for six agentic workflows using gh-aw v0.89.21.
Changes:
- Removes legacy inline-detector overrides.
- Regenerates lockfiles with pinned threat-detect v0.5.2.
- Updates Pulse regression checks for external detection.
| File | Description |
|---|---|
.github/workflows/test-quarantine.md |
Removes inline-detector workaround. |
.github/workflows/test-quarantine.lock.yml |
Regenerates workflow with v0.89.21. |
.github/workflows/pr-attention-pulse.md |
Enables external detection. |
.github/workflows/pr-attention-pulse.lock.yml |
Adds external detector pipeline. |
.github/workflows/pr-attention-pulse-tests/Test-PulseReviewRequirements.ps1 |
Updates detector regression controls. |
.github/workflows/issue-triage-agent.md |
Removes inline-detector workaround. |
.github/workflows/issue-triage-agent.lock.yml |
Regenerates external detection job. |
.github/workflows/cswin32-update.md |
Removes inline-detector workaround. |
.github/workflows/cswin32-update.lock.yml |
Regenerates external detection job. |
.github/workflows/community-pr-issue-check.md |
Removes inline-detector workaround. |
.github/workflows/community-pr-issue-check.lock.yml |
Regenerates external detection job. |
.github/workflows/browsertesting-deps-update.md |
Removes inline-detector workaround. |
.github/workflows/browsertesting-deps-update.lock.yml |
Regenerates external detection job. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
| Assert-True ($workflow -match "(?m)^ gh-aw-detection: false\r?$") "The inline-detector workaround must remain enabled." | ||
| Assert-True ($detector.Contains("copilot_harness.cjs") -and $detector.Contains("parse_threat_detection_results.cjs")) "The generated detector must execute and parse inline detection." | ||
| Assert-True ($workflow -notmatch "(?m)^ gh-aw-detection: false\r?$") "The inline-detector workaround must be removed." | ||
| Assert-True ($detector.Contains('install_threat_detect_binary.sh" v0.5.2 ')) "The generated detector must install the fixed v0.5.2 release." |
| if: always() && steps.detection_guard.outputs.run_detection == 'true' | ||
| continue-on-error: true | ||
| run: | | ||
| bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.5.2 --artifact-base-url https://github.com/github/gh-aw-threat-detection/releases/download --sha256-amd64 b4ecda6a8f1ee09913c40b58e5e9d3337d2173618d41b1bfdef9207e4e7959b9 --sha256-arm64 f6260a0f9ad72bcb67c7af19c4ce262ca34e2c3d5ccbf912832a8bd277200904 |
Check both v0.5.2 Linux digests on the same installer invocation. Reject missing, stale, uppercase, and separately placed digest arguments. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Restore external threat detection with gh-aw v0.89.21
Remove inline detector workarounds and restore the fixed external detector.
Description
github/gh-aw#61857 is included in gh-aw v0.89.21: its merge commit,
0053f61aedb203413ff12768bd4e79d402285af9, is an ancestor of the release tag. That release compiles workflows with externalthreat-detectv0.5.2.features.gh-aw-detection: falsefrombrowsertesting-deps-update,community-pr-issue-check,cswin32-update,issue-triage-agent,pr-attention-pulse, andtest-quarantine.dotnet/aspnetcoreschedule seed. No generated lockfiles were edited manually.test-quarantineto v0.89.21. The upgrade in Upgrade agentic workflows to gh-aw v0.89.21 #69568 was reverted for that workflow by the backflow in [main] Source code updates from dotnet/dotnet #69553.test-quarantineandpr-attention-pulseretaincontinue-on-error: false; the other four retaintrue. Pulse retains its explicit detector model and PAT-pool binding.The PAT-pool configuration problem observed in run https://github.com/dotnet/aspnetcore/actions/runs/36847957662 is being handled separately. This PR does not change credentials or PAT selection.
Validation
gh aw compile browsertesting-deps-update community-pr-issue-check cswin32-update issue-triage-agent pr-attention-pulse test-quarantine --schedule-seed dotnet/aspnetcore --strict --no-check-update-- six workflows compiled; rerunning after rebasing produced no changes under.github.pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PulseReviewRequirements.ps1-- all 15 controls passed. The updated external-detector control fails against the previous source/lock pair because the inline workaround is still present.git diff --check upstream/main...HEAD.pwsh -NoProfile -File .github/workflows/pr-attention-pulse-tests/Test-PRAttentionPulse.ps1, using pinned v0.89.21 action sources via an isolatedGH_CONFIG_DIR. On the rebased branch, the suite reportsPublishedSnapshot/sanitizer-stable-unicode, fourContextTimecases, andRetrieval/documented-consumerfailures. Retrieval encounters a PowerShellGet-Itemerror for its generated hidden fixture directory on macOS. These failures are not changed by this PR.--actionlintcannot invoke its Docker-backed linter because Docker is unavailable locally. A direct native actionlint run reports existing syntax/expression diagnostics; comparing baseline and changed YAML produced identical diagnostic sets for all six workflows, with no additional diagnostics.Outstanding live validation
Representative scheduled or manually dispatched runs must still complete external detection and safe outputs after the separately managed PAT-pool configuration is restored. This PR does not claim that end-to-end acceptance criterion is verified.
Fixes #69420