From 40772df64f63b6823f997c7c9e1eb43446bbdc5a Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 13 Aug 2026 03:05:13 +0000 Subject: [PATCH 1/3] Initial plan From 2c89ff22abbcf0ebae8ea212fa02d60898de67da Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 13 Aug 2026 03:19:06 +0000 Subject: [PATCH 2/3] Add continue-on-error to threat-detect binary install step Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 1 + .github/workflows/agent-job-health.lock.yml | 1 + .../agent-performance-analyzer.lock.yml | 1 + .../workflows/agent-persona-explorer.lock.yml | 1 + .../agentic-token-trend-audit.lock.yml | 1 + .../workflows/api-consumption-report.lock.yml | 1 + .github/workflows/approach-validator.lock.yml | 1 + .github/workflows/archie.lock.yml | 1 + .../workflows/architecture-guardian.lock.yml | 1 + ...rchivx-agentic-workflows-analyzer.lock.yml | 1 + .github/workflows/artifacts-summary.lock.yml | 1 + .github/workflows/audit-workflows.lock.yml | 1 + .github/workflows/auto-triage-issues.lock.yml | 1 + .github/workflows/avenger.lock.yml | 1 + .../aw-failure-investigator.lock.yml | 1 + .github/workflows/blog-auditor.lock.yml | 1 + .../breaking-change-checker.lock.yml | 1 + .github/workflows/changeset.lock.yml | 1 + .../workflows/chaos-pr-bundle-fuzzer.lock.yml | 1 + .github/workflows/ci-coach.lock.yml | 1 + .github/workflows/ci-doctor.lock.yml | 1 + .../claude-code-user-docs-review.lock.yml | 1 + .../cli-consistency-checker.lock.yml | 1 + .../workflows/cli-version-checker.lock.yml | 1 + .github/workflows/cloclo.lock.yml | 1 + .../workflows/code-scanning-fixer.lock.yml | 1 + .../commit-changes-analyzer.lock.yml | 1 + .../constraint-solving-potd.lock.yml | 1 + .github/workflows/contribution-check.lock.yml | 1 + .../workflows/copilot-agent-analysis.lock.yml | 1 + .../copilot-cli-deep-research.lock.yml | 1 + .github/workflows/copilot-opt.lock.yml | 1 + .../copilot-pr-merged-report.lock.yml | 1 + .../copilot-pr-nlp-analysis.lock.yml | 1 + .../copilot-pr-prompt-analysis.lock.yml | 1 + .../copilot-session-insights.lock.yml | 1 + .github/workflows/craft.lock.yml | 1 + ...aily-agent-of-the-day-blog-writer.lock.yml | 1 + .../daily-agentrx-trace-optimizer.lock.yml | 1 + .../daily-ambient-context-optimizer.lock.yml | 1 + .../daily-architecture-diagram.lock.yml | 1 + .../daily-assign-issue-to-user.lock.yml | 1 + ...strostylelite-markdown-spellcheck.lock.yml | 1 + ...daily-aw-cross-repo-compile-check.lock.yml | 1 + ...daily-awf-spec-compiler-surfacing.lock.yml | 1 + .../workflows/daily-byok-ollama-test.lock.yml | 1 + .../daily-cache-strategy-analyzer.lock.yml | 1 + .../daily-caveman-optimizer.lock.yml | 1 + .github/workflows/daily-choice-test.lock.yml | 1 + .../workflows/daily-cli-performance.lock.yml | 1 + .../workflows/daily-cli-tools-tester.lock.yml | 1 + .github/workflows/daily-code-metrics.lock.yml | 1 + .../daily-community-attribution.lock.yml | 1 + .../workflows/daily-compiler-quality.lock.yml | 1 + ...ly-compiler-threat-spec-optimizer.lock.yml | 1 + .../daily-credit-limit-test.lock.yml | 1 + .github/workflows/daily-doc-healer.lock.yml | 1 + .github/workflows/daily-doc-updater.lock.yml | 1 + .../daily-elixir-credo-snippet-audit.lock.yml | 1 + .github/workflows/daily-evals-report.lock.yml | 1 + .../daily-experiment-report.lock.yml | 1 + .github/workflows/daily-fact.lock.yml | 1 + .github/workflows/daily-file-diet.lock.yml | 1 + .../daily-formal-spec-verifier.lock.yml | 1 + .../workflows/daily-function-namer.lock.yml | 1 + .../workflows/daily-geo-optimizer.lock.yml | 1 + .../daily-graft-intelligence.lock.yml | 1 + .github/workflows/daily-hippo-learn.lock.yml | 1 + .../workflows/daily-issues-report.lock.yml | 1 + .../daily-max-ai-credits-test.lock.yml | 1 + .../daily-mcp-concurrency-analysis.lock.yml | 1 + .../workflows/daily-model-inventory.lock.yml | 1 + .../workflows/daily-model-resolution.lock.yml | 1 + .../daily-multi-device-docs-tester.lock.yml | 1 + .github/workflows/daily-news.lock.yml | 1 + .../daily-observability-report.lock.yml | 1 + .../daily-performance-summary.lock.yml | 1 + .github/workflows/daily-regulatory.lock.yml | 1 + .../daily-reliability-review.lock.yml | 1 + .../daily-rendering-scripts-verifier.lock.yml | 1 + .../workflows/daily-repo-chronicle.lock.yml | 1 + .../daily-testify-uber-super-expert.lock.yml | 1 + .../daily-token-consumption-report.lock.yml | 1 + .github/workflows/deep-report.lock.yml | 1 + .../deployment-incident-monitor.lock.yml | 1 + .../workflows/design-decision-gate.lock.yml | 1 + .../detection-analysis-report.lock.yml | 1 + .github/workflows/docs-noob-tester.lock.yml | 1 + .../duplicate-code-detector.lock.yml | 1 + .github/workflows/eslint-monster.lock.yml | 1 + .../example-workflow-analyzer.lock.yml | 1 + .../github-mcp-structural-analysis.lock.yml | 1 + .../github-remote-mcp-auth-test.lock.yml | 1 + .../impeccable-skills-reviewer.lock.yml | 1 + .github/workflows/issue-monster.lock.yml | 1 + .../mattpocock-skills-reviewer.lock.yml | 1 + .github/workflows/ponytail-reviewer.lock.yml | 1 + .../pr-code-quality-reviewer.lock.yml | 1 + .../workflows/pr-description-caveman.lock.yml | 1 + .github/workflows/pr-sous-chef.lock.yml | 1 + .../prompt-clustering-analysis.lock.yml | 1 + .github/workflows/q.lock.yml | 1 + .../workflows/test-quality-sentinel.lock.yml | 1 + .github/workflows/typist.lock.yml | 1 + .../threat_detection_isolation_test.go | 14 ++++++++ pkg/workflow/threat_detection_steps.go | 34 ++++++++++++++++--- 106 files changed, 148 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index 90ca9cb91ad..3ee61727ed6 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -1410,6 +1410,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index ee497c1cd98..2ac47a1b175 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -1667,6 +1667,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index d632f363c6b..7034c7ab343 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -1671,6 +1671,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index 7e0908a6c52..8072c336e1c 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -1529,6 +1529,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index bf4b456c015..dd9f0df98ee 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -1519,6 +1519,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 617eb533560..b9c1f88f954 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -1649,6 +1649,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index 0a43616ffb0..fbbeebddf15 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -1637,6 +1637,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 9d5f9070d3d..63455c833c5 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -1524,6 +1524,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index f47f37c986c..a69cc1932fa 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -1455,6 +1455,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index 90e317e9a5d..d8e67359124 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -1558,6 +1558,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index 8d28523e8ec..b7eb0b4ed29 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -1402,6 +1402,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 0559baa6ff3..bd332c9e1d2 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -1744,6 +1744,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index 21f7350ccc7..49d9e5e1c5b 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1433,6 +1433,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index f03572e1ad1..19683f4df3e 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -1568,6 +1568,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index 4f33aa116ca..32fe488735d 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -1680,6 +1680,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 28060fc85b3..5d6d63acab3 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -1558,6 +1558,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index 52e26da6d03..b90934b9104 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -1498,6 +1498,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index 06ad8b05577..eb313608387 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -1541,6 +1541,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index 242650dd18b..1c8a8fc7086 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -1395,6 +1395,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index 750ee26d534..bdee2f7533a 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -1555,6 +1555,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index b930d0980a3..57dd1b88165 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1734,6 +1734,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index 85d64004c66..bf430e6d674 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -1522,6 +1522,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index 804f06822d4..86ab6766963 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -1414,6 +1414,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index a8e1bc72568..63d0bf43de8 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -1508,6 +1508,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index 5d3ee277b90..93af0886134 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -1834,6 +1834,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index e0bbcb6c1bd..88c57110e37 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -1525,6 +1525,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 47f98fa7390..f5da6b22d1c 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -1346,6 +1346,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index 607302e3379..dc390e97eb9 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -1422,6 +1422,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index 551c65b767e..8ee830bb299 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -1595,6 +1595,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 07938284c18..4f4faaae083 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -1608,6 +1608,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index 3700c0f407a..128ad66ea0c 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -1462,6 +1462,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index 549c5cba01b..7b5204579ba 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -1520,6 +1520,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 779cc2cee30..cbbda242d69 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -1406,6 +1406,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index 896152b3765..c28f70d423c 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -1574,6 +1574,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index 31c7651984d..9ee4d4ec016 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -1514,6 +1514,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 53c96b3cade..db8626b5bff 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -1624,6 +1624,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index d3c891a62ff..f5242fe03ae 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -1524,6 +1524,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 5aee8c484ad..49c84ed57e9 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -1656,6 +1656,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index 78b5f07bf6b..105078647aa 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -1727,6 +1727,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index e2f0ca9d484..c34799275a0 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -1563,6 +1563,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index e7cf26ce0d2..28607018372 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -1616,6 +1616,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index 713b939882b..ed17d747363 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -1482,6 +1482,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index 9f6a1484309..42aad05579d 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -1560,6 +1560,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index f080401423b..55e262ebdc6 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -1552,6 +1552,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index b5b039dad0c..49933ec943b 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -1442,6 +1442,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index dbfd40a5f5b..c4650673042 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -1428,6 +1428,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index 595cfc999ac..f82e0a59651 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -1736,6 +1736,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index 64f3e8e6318..3277e3d64c2 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -1604,6 +1604,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index 5feae3ca025..80d49fce1b6 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -1476,6 +1476,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 30f66654fc1..0ff586cf07b 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -1772,6 +1772,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index 765dbbacfc4..bdfe69e330a 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -1525,6 +1525,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index 525c4f33073..c25b63e2485 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -1765,6 +1765,7 @@ jobs: run: crush --version - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index d8e6beac912..db0076a3b2f 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -1651,6 +1651,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index dc087f87164..72655747b89 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -1610,6 +1610,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index a021cebc112..592a0b7d859 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -1533,6 +1533,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index d31fc670fb4..034833a0da5 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -1389,6 +1389,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index a33ec9d9a2f..2f15184a5b2 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -1711,6 +1711,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index fc44fc9fa67..515191a6813 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -1511,6 +1511,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index 81ab9ad565a..9083727658d 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -1491,6 +1491,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index 1d92bf92b0f..04e1d07d9b9 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -1639,6 +1639,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 0783c64679a..793c3cf0d11 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -1604,6 +1604,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index d6848c900bd..931143c64e2 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -1660,6 +1660,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 85ca10fb59a..fbc9680240c 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -1521,6 +1521,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 98695752126..53e1a8606f9 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -1534,6 +1534,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index 1593d97c0b2..6a71207ad65 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -1468,6 +1468,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index c0600b90f1e..419e2187596 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -1481,6 +1481,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 71b89d6982b..ef428c57d87 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -1463,6 +1463,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index 085685e5e32..8d279907254 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -1562,6 +1562,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 4572cdcebc2..e06c4eef82f 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -1747,6 +1747,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index 5fbaa87754d..85690f23725 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -1248,6 +1248,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index d371cf41c40..901d68f615c 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -1572,6 +1572,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 35081266d9a..f08c3c9930b 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -1754,6 +1754,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 7a625dfc2dd..d0a05a5f549 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -1493,6 +1493,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 44830c83294..1c683405f8b 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -1475,6 +1475,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index a31081d6255..0204a8ca058 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -1672,6 +1672,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 2e5ddf84269..7966fa2da08 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -1549,6 +1549,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index fe455410c21..edd2df84a9b 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -2031,6 +2031,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 734ab59d66c..42e879043f3 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -1927,6 +1927,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index 4d46372f3c1..fbb50aad6a6 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -1493,6 +1493,7 @@ jobs: run: opencode --version - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index ad241173cf8..25b6c0f699b 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -1680,6 +1680,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index a95ca392d9d..f612520c8d3 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -1507,6 +1507,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index 32eb431e05e..88e3aec6784 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -1535,6 +1535,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index e566b7ef115..4d829da8c3a 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -1668,6 +1668,7 @@ jobs: package-manager-cache: false - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index 5e9eaf89e83..1d3741e59ff 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -2316,6 +2316,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index 889cbd7eb75..4e4e3b38af4 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -1427,6 +1427,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index adb64b386c6..f897dd90730 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -1644,6 +1644,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index 4eae635f69c..27241ff90fe 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -1653,6 +1653,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 8bc4ab9c4ba..328e4448ef6 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -1466,6 +1466,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index ab960dba38f..d1ad4aea771 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -1511,6 +1511,7 @@ jobs: chmod 600 "${RUNNER_TEMP}/gh-aw/mcp-config/config.toml" "/tmp/gh-aw/mcp-config/config.toml" - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index be7b6c1d826..409ec74a88d 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -1533,6 +1533,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index c46d6ff66ee..ef75a25cf8a 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -1518,6 +1518,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index fb14f080cc1..9b2d5598423 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -1817,6 +1817,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index b54e22f7430..e7d3d1e7542 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -1401,6 +1401,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index ae19bc3187a..7d609cda721 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -1584,6 +1584,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index ee8d7daadff..c42729f0fc4 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -1886,6 +1886,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 977de5952cb..2cfa9f4b2ac 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -1725,6 +1725,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index ab039e51d3f..d3d9d59d76f 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -1612,6 +1612,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index ba60a25677e..6ce4e25053d 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -1589,6 +1589,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index 120a4d69935..c9fc09d9a5b 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -1424,6 +1424,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index fefa7f726d0..ddc8253d2d9 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -1850,6 +1850,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 80f2a8e8740..859f99c0d8f 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -1662,6 +1662,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index 4380bcbb6b9..ae1ff141a48 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -1676,6 +1676,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index 5dd797b7e40..d86bad51ffa 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -1606,6 +1606,7 @@ jobs: GH_AW_COMPILED_VERSION: dev - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index ef142bc5967..87c3720f93a 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -1547,6 +1547,7 @@ jobs: run: npm install -g @anthropic-ai/claude-code@2.1.227 - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' + continue-on-error: true run: | bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF diff --git a/pkg/workflow/threat_detection_isolation_test.go b/pkg/workflow/threat_detection_isolation_test.go index 85b54b0c0ca..49f0746139d 100644 --- a/pkg/workflow/threat_detection_isolation_test.go +++ b/pkg/workflow/threat_detection_isolation_test.go @@ -213,6 +213,20 @@ Test workflow` if !strings.Contains(detectionSection, "install_threat_detect_binary.sh") { t.Error("External detector path must emit 'install_threat_detect_binary.sh' install step") } + // In warn mode (continue-on-error default: true), the install step itself must be + // continue-on-error so a transient download failure doesn't mark the detection job + // as failure when the workflow logic already tolerates a missing binary. + installStepIdx := strings.Index(detectionSection, "Install threat-detect binary") + if installStepIdx == -1 { + t.Fatal("Could not find 'Install threat-detect binary' step in detection section") + } + installStepBlock := detectionSection[installStepIdx:] + if nextStepIdx := strings.Index(installStepBlock[1:], "\n - name:"); nextStepIdx != -1 { + installStepBlock = installStepBlock[:nextStepIdx+1] + } + if !strings.Contains(installStepBlock, "continue-on-error: true") { + t.Error("Install threat-detect binary step must set continue-on-error: true in warn mode") + } if !strings.Contains(detectionSection, "install_copilot_cli.sh") { t.Error("External detector path must emit engine installation step for copilot") } diff --git a/pkg/workflow/threat_detection_steps.go b/pkg/workflow/threat_detection_steps.go index 1aabe2d9c6e..f28109364ee 100644 --- a/pkg/workflow/threat_detection_steps.go +++ b/pkg/workflow/threat_detection_steps.go @@ -79,7 +79,7 @@ func (c *Compiler) buildDetectionJobSteps(data *WorkflowData) []string { steps = append(steps, c.buildPrepareDetectionEngineConfigForExternalDetectorStep(data)...) // Step 10: Install the threat-detect binary from GitHub Releases - steps = append(steps, c.buildInstallThreatDetectStep()...) + steps = append(steps, c.buildInstallThreatDetectStep(data)...) // Step 11: Run threat-detect under AWF with a read-write mount for the result file steps = append(steps, c.buildExternalDetectorExecutionStep(data)...) @@ -510,12 +510,38 @@ func (c *Compiler) buildRenderDetectionLogStep(data *WorkflowData) []string { // buildInstallThreatDetectStep creates a step that installs the threat-detect binary // from GitHub Releases at the pinned version. This is used when the gh-aw-detection // feature flag is set, replacing the inline engine installation steps. -func (c *Compiler) buildInstallThreatDetectStep() []string { +// +// The detection job already tolerates a missing threat-detect binary when continue-on-error +// (warn mode) is in effect: buildDetectionConclusionStep and buildThreatDetectionAnalysisStep +// treat a failed/absent binary as a non-fatal detection failure via +// GH_AW_DETECTION_CONTINUE_ON_ERROR. Without continue-on-error on this install step, a +// transient download failure (e.g. a GitHub Releases CDN blip) would still mark this step — +// and therefore the whole detection job — as `failure`, even though the workflow logic +// already treats a missing binary as non-fatal. Marking the step itself continue-on-error +// in warn mode keeps the job conclusion consistent with that tolerance. +func (c *Compiler) buildInstallThreatDetectStep(data *WorkflowData) []string { version := string(constants.DefaultThreatDetectVersion) - return []string{ + + // Determine continue-on-error mode (same logic as buildDetectionConclusionStep). + continueOnError := true + var continueOnErrorExpr *string + if data.SafeOutputs != nil && data.SafeOutputs.ThreatDetection != nil { + continueOnError = data.SafeOutputs.ThreatDetection.IsContinueOnError() + continueOnErrorExpr = data.SafeOutputs.ThreatDetection.ContinueOnErrorExpr + } + + steps := []string{ " - name: Install threat-detect binary\n", fmt.Sprintf(" if: %s\n", detectionStepCondition), + } + if continueOnErrorExpr != nil { + steps = append(steps, fmt.Sprintf(" continue-on-error: %s\n", *continueOnErrorExpr)) + } else if continueOnError { + steps = append(steps, " continue-on-error: true\n") + } + steps = append(steps, " run: |\n", fmt.Sprintf(" bash \"${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh\" %s\n", version), - } + ) + return steps } From d79379e0bbe6b2b7776497d506d68af78b2fc0d5 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 13 Aug 2026 18:24:02 +0000 Subject: [PATCH 3/3] Apply remaining changes Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com> --- .github/skills/agentic-workflows/SKILL.md | 1 + pkg/workflow/threat_detection_steps.go | 21 +++------------------ 2 files changed, 4 insertions(+), 18 deletions(-) diff --git a/.github/skills/agentic-workflows/SKILL.md b/.github/skills/agentic-workflows/SKILL.md index 742a125b032..d0c9af823a8 100644 --- a/.github/skills/agentic-workflows/SKILL.md +++ b/.github/skills/agentic-workflows/SKILL.md @@ -34,6 +34,7 @@ Load these files from `github/gh-aw` (they are not available locally). - `.github/aw/deployment-status.md` - `.github/aw/designer-mappings.md` - `.github/aw/designer.md` +- `.github/aw/enclaves.md` - `.github/aw/evals.md` - `.github/aw/experiments.md` - `.github/aw/github-agentic-workflows.md` diff --git a/pkg/workflow/threat_detection_steps.go b/pkg/workflow/threat_detection_steps.go index f28109364ee..41795313ca4 100644 --- a/pkg/workflow/threat_detection_steps.go +++ b/pkg/workflow/threat_detection_steps.go @@ -211,12 +211,7 @@ func (c *Compiler) buildDetectionConclusionStep(data *WorkflowData) []string { // Determine continue-on-error mode (default: true — detection failures produce warnings). // When ContinueOnErrorExpr is set the value is resolved at runtime; compile-time we use // true as a safe default so the step-level continue-on-error is included (permissive). - continueOnError := true - var continueOnErrorExpr *string - if data.SafeOutputs != nil && data.SafeOutputs.ThreatDetection != nil { - continueOnError = data.SafeOutputs.ThreatDetection.IsContinueOnError() - continueOnErrorExpr = data.SafeOutputs.ThreatDetection.ContinueOnErrorExpr - } + continueOnError, continueOnErrorExpr := resolveThreatDetectionContinueOnError(data) steps := []string{ " - name: Parse and conclude threat detection\n", @@ -283,12 +278,7 @@ func (c *Compiler) buildThreatDetectionAnalysisStep(data *WorkflowData) []string var steps []string // Determine continue-on-error mode (same logic as buildDetectionConclusionStep). - continueOnError := true - var continueOnErrorExpr *string - if data.SafeOutputs != nil && data.SafeOutputs.ThreatDetection != nil { - continueOnError = data.SafeOutputs.ThreatDetection.IsContinueOnError() - continueOnErrorExpr = data.SafeOutputs.ThreatDetection.ContinueOnErrorExpr - } + continueOnError, continueOnErrorExpr := resolveThreatDetectionContinueOnError(data) // Setup step steps = append(steps, []string{ @@ -523,12 +513,7 @@ func (c *Compiler) buildInstallThreatDetectStep(data *WorkflowData) []string { version := string(constants.DefaultThreatDetectVersion) // Determine continue-on-error mode (same logic as buildDetectionConclusionStep). - continueOnError := true - var continueOnErrorExpr *string - if data.SafeOutputs != nil && data.SafeOutputs.ThreatDetection != nil { - continueOnError = data.SafeOutputs.ThreatDetection.IsContinueOnError() - continueOnErrorExpr = data.SafeOutputs.ThreatDetection.ContinueOnErrorExpr - } + continueOnError, continueOnErrorExpr := resolveThreatDetectionContinueOnError(data) steps := []string{ " - name: Install threat-detect binary\n",