From 3497bed63ccffc6c143ea16d5036e6a3b1914b9e Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Fri, 7 Aug 2026 17:32:05 +0000 Subject: [PATCH] chore: bind gh-aw-detection to latest release instead of pinned version Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com> --- .github/workflows/ab-testing-advisor.lock.yml | 2 +- .../agent-performance-analyzer.lock.yml | 2 +- .../workflows/agent-persona-explorer.lock.yml | 2 +- .../workflows/agentic-token-trend-audit.lock.yml | 2 +- .../workflows/api-consumption-report.lock.yml | 2 +- .github/workflows/approach-validator.lock.yml | 2 +- .github/workflows/archie.lock.yml | 2 +- .github/workflows/architecture-guardian.lock.yml | 2 +- .../archivx-agentic-workflows-analyzer.lock.yml | 2 +- .github/workflows/artifacts-summary.lock.yml | 2 +- .github/workflows/audit-workflows.lock.yml | 2 +- .github/workflows/auto-triage-issues.lock.yml | 2 +- .github/workflows/avenger.lock.yml | 2 +- .../workflows/aw-failure-investigator.lock.yml | 2 +- .github/workflows/blog-auditor.lock.yml | 2 +- .../workflows/breaking-change-checker.lock.yml | 2 +- .github/workflows/changeset.lock.yml | 2 +- .../workflows/chaos-pr-bundle-fuzzer.lock.yml | 2 +- .github/workflows/ci-coach.lock.yml | 2 +- .github/workflows/ci-doctor.lock.yml | 2 +- .../claude-code-user-docs-review.lock.yml | 2 +- .../workflows/cli-consistency-checker.lock.yml | 2 +- .github/workflows/cli-version-checker.lock.yml | 2 +- .github/workflows/cloclo.lock.yml | 2 +- .github/workflows/code-scanning-fixer.lock.yml | 2 +- .../workflows/commit-changes-analyzer.lock.yml | 2 +- .../workflows/constraint-solving-potd.lock.yml | 2 +- .github/workflows/contribution-check.lock.yml | 2 +- .../workflows/copilot-agent-analysis.lock.yml | 2 +- .../workflows/copilot-cli-deep-research.lock.yml | 2 +- .github/workflows/copilot-opt.lock.yml | 2 +- .../workflows/copilot-pr-merged-report.lock.yml | 2 +- .../workflows/copilot-pr-nlp-analysis.lock.yml | 2 +- .../copilot-pr-prompt-analysis.lock.yml | 2 +- .../workflows/copilot-session-insights.lock.yml | 2 +- .github/workflows/craft.lock.yml | 2 +- .../daily-agent-of-the-day-blog-writer.lock.yml | 2 +- .../daily-agentrx-trace-optimizer.lock.yml | 2 +- .../daily-ambient-context-optimizer.lock.yml | 2 +- .../daily-architecture-diagram.lock.yml | 2 +- .../daily-assign-issue-to-user.lock.yml | 2 +- ...y-astrostylelite-markdown-spellcheck.lock.yml | 2 +- .../daily-aw-cross-repo-compile-check.lock.yml | 2 +- .../daily-awf-spec-compiler-surfacing.lock.yml | 2 +- .../workflows/daily-byok-ollama-test.lock.yml | 2 +- .../daily-cache-strategy-analyzer.lock.yml | 2 +- .../workflows/daily-caveman-optimizer.lock.yml | 2 +- .github/workflows/daily-choice-test.lock.yml | 2 +- .github/workflows/daily-cli-performance.lock.yml | 2 +- .../workflows/daily-cli-tools-tester.lock.yml | 2 +- .github/workflows/daily-code-metrics.lock.yml | 2 +- .../daily-community-attribution.lock.yml | 2 +- .../workflows/daily-compiler-quality.lock.yml | 2 +- ...daily-compiler-threat-spec-optimizer.lock.yml | 2 +- .../workflows/daily-credit-limit-test.lock.yml | 2 +- .github/workflows/daily-doc-healer.lock.yml | 2 +- .github/workflows/daily-doc-updater.lock.yml | 2 +- .../daily-elixir-credo-snippet-audit.lock.yml | 2 +- .github/workflows/daily-evals-report.lock.yml | 2 +- .../workflows/daily-experiment-report.lock.yml | 2 +- .github/workflows/daily-fact.lock.yml | 2 +- .github/workflows/daily-file-diet.lock.yml | 2 +- .../daily-formal-spec-verifier.lock.yml | 2 +- .github/workflows/daily-function-namer.lock.yml | 2 +- .github/workflows/daily-geo-optimizer.lock.yml | 2 +- .../workflows/daily-graft-intelligence.lock.yml | 2 +- .github/workflows/daily-hippo-learn.lock.yml | 2 +- .github/workflows/daily-issues-report.lock.yml | 2 +- .../workflows/daily-max-ai-credits-test.lock.yml | 2 +- .../daily-mcp-concurrency-analysis.lock.yml | 2 +- .github/workflows/daily-model-inventory.lock.yml | 2 +- .../workflows/daily-model-resolution.lock.yml | 2 +- .../daily-multi-device-docs-tester.lock.yml | 2 +- .github/workflows/daily-news.lock.yml | 2 +- .../daily-observability-report.lock.yml | 2 +- .../workflows/daily-performance-summary.lock.yml | 2 +- .../workflows/daily-reliability-review.lock.yml | 2 +- .../daily-rendering-scripts-verifier.lock.yml | 2 +- .github/workflows/daily-repo-chronicle.lock.yml | 2 +- .../daily-testify-uber-super-expert.lock.yml | 2 +- .../daily-token-consumption-report.lock.yml | 2 +- .github/workflows/design-decision-gate.lock.yml | 2 +- .../workflows/detection-analysis-report.lock.yml | 2 +- .github/workflows/docs-noob-tester.lock.yml | 2 +- .../workflows/duplicate-code-detector.lock.yml | 2 +- .../workflows/example-workflow-analyzer.lock.yml | 2 +- .../github-mcp-structural-analysis.lock.yml | 2 +- .../github-remote-mcp-auth-test.lock.yml | 2 +- .../impeccable-skills-reviewer.lock.yml | 2 +- .github/workflows/issue-monster.lock.yml | 2 +- .../mattpocock-skills-reviewer.lock.yml | 2 +- .../workflows/pr-code-quality-reviewer.lock.yml | 2 +- .../workflows/pr-description-caveman.lock.yml | 2 +- .github/workflows/pr-sous-chef.lock.yml | 2 +- .../prompt-clustering-analysis.lock.yml | 2 +- .github/workflows/test-quality-sentinel.lock.yml | 2 +- .github/workflows/typist.lock.yml | 2 +- actions/setup/sh/install_threat_detect_binary.sh | 16 +++++++++++++++- pkg/constants/feature_constants.go | 2 +- pkg/constants/version_constants.go | 11 ++++++----- pkg/workflow/threat_detection_isolation_test.go | 4 ++-- 101 files changed, 121 insertions(+), 106 deletions(-) diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index 2dad2fa1d0c..d10d6d630c9 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -1444,7 +1444,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index 217a6c72a08..c210b219f4d 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -1705,7 +1705,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index f3dc5061fc6..db2e9a73806 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -1563,7 +1563,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index 1fea138dc2c..9b91ed1f8bd 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -1551,7 +1551,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index e5b5dc0b6f3..4f17ef9f2a4 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -1922,7 +1922,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index 8bb418c9e69..f052c7caeab 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -1641,7 +1641,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 8ac0b2a2c89..c893f426e79 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -1541,7 +1541,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index e0eb0c36abc..16e36f1bd4c 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -1564,7 +1564,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index fc4a30f3f27..65e9ae8906f 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -1578,7 +1578,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index a7d65172e0c..cd5711c1ce7 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -1433,7 +1433,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 21479af0f3e..9251be72a87 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -1772,7 +1772,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index c390e1c5520..a2b344bc4d7 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1466,7 +1466,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index f9911656147..a7094ba55bb 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -1602,7 +1602,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index ca74dac64bc..a17f49c28c9 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -1715,7 +1715,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index 0959a147253..9308f1c23d5 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -1594,7 +1594,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index df61d9bfa4a..af319ccb693 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -1528,7 +1528,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index b03e1f0b0c8..37cf83794a7 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -1569,7 +1569,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index 4eb5317ab6e..3f50b7f07c9 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -1428,7 +1428,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index 9ec69dc4cd8..9280465d65f 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -1586,7 +1586,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index f0cf19a67ed..668dd41298f 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1754,7 +1754,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index 36bf2d978ca..d7f965b8d32 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -1558,7 +1558,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index 53472afbbad..2f3460864df 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -1445,7 +1445,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index c95cb3775ba..e25497caca9 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -1544,7 +1544,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index 08bae7b8216..d4286fc0ca3 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -1856,7 +1856,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index 2f8bc1197e9..204c8d415dd 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -1556,7 +1556,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index f04e08d925b..e2c0392ed24 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -1382,7 +1382,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index 467f50bf68b..7214dece2c1 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -1457,7 +1457,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index 6847e0f2d5b..9f9b26aef1c 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -1608,7 +1608,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 5652b9f780a..4ce88233627 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -1638,7 +1638,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index d35d6d37660..e4549eddd60 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -1487,7 +1487,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index 68836f98fdf..0dfe2d1dc4a 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -1554,7 +1554,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index 559df2bc095..4af1d8f72a2 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -1411,7 +1411,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index 72bfe64c5a8..29900d11b92 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -1601,7 +1601,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index a52cc0e408d..31d78695db6 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -1540,7 +1540,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 743b96835a3..31f1032872a 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -1655,7 +1655,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index d4285e46ab8..3826033cd53 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -1542,7 +1542,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 420dffbc640..af8947a58ec 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -1644,7 +1644,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index 8e2bfe7802a..2b69b575e4c 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -1724,7 +1724,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index ff10dd84646..03c8db54ccd 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -1592,7 +1592,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index 0f0b832c943..31e7c119733 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -1614,7 +1614,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index 0a8dbf532de..a012ce2cf59 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -1461,7 +1461,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index 794e91d2c95..0ff4cd82727 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -1554,7 +1554,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index d12b1a38fbd..cf6e6c33c9b 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -1549,7 +1549,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index ef7bcf984b2..c45e9252c37 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -1432,7 +1432,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index bace0f0f5fe..5dcbea359bb 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -1434,7 +1434,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index b5584c2948e..3c99a735b6e 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -1733,7 +1733,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index add0598a6f8..856ab11892f 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -1600,7 +1600,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index fe117e5e5d2..40378bcb2a0 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -1472,7 +1472,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 7e5aa57be72..68c64b8a459 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -1742,7 +1742,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index 3ffa4afc8f2..0ea96f454fa 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -1559,7 +1559,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index c3019ef513b..5152967a9e0 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -1767,7 +1767,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index 480f21f8d6b..5af21a3c59c 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -1638,7 +1638,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index 3bac7506156..0d46c7853cf 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -1611,7 +1611,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index f86c62d047c..2b0cdba8700 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -1529,7 +1529,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index 4f69569c884..5d746b39d5b 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -1386,7 +1386,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 29d5aa95dbb..6f9171c6718 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -1707,7 +1707,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index f6ac1980b49..cb1928adc69 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -1510,7 +1510,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index 9bd73ab3352..580192eb3df 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -1486,7 +1486,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index ef27b839ecd..5322a5ca637 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -1635,7 +1635,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index 734ffb61667..2d1e3b28ae2 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -1585,7 +1585,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index e0784acf2af..1b6bda01656 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -1733,7 +1733,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index 52270d2d754..4590c51ae9a 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -1521,7 +1521,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index 8929ceb9b94..afc8fd501c2 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -1560,7 +1560,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index 7b7d0411da0..f9ac8f1dea2 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -1507,7 +1507,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index dad4a154661..090eaf9af24 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -1515,7 +1515,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index 224ec2a024e..ef749dfb7b9 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -1497,7 +1497,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index 410413c3dcc..3611c3ed79f 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -1599,7 +1599,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index 6f3236c399e..b82c2ed6fc8 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -1783,7 +1783,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index c61b56d6d8c..5d911fad370 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -1282,7 +1282,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index 2769e72efe0..e50fe56162a 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -1609,7 +1609,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 4ca512276b0..2ec19851b21 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -1791,7 +1791,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 2ddd7a3266e..3971a806b8c 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -1527,7 +1527,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index 7bf56d8be95..632dcd5f500 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -1497,7 +1497,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index 55226af8a92..d11bac35e83 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -1686,7 +1686,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index 64bf6d58115..e56e36f1393 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -1587,7 +1587,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 1cd1fed44cf..e220040994c 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -2067,7 +2067,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index ac166d674e6..94c99d95e76 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -1531,7 +1531,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 065ab26c0bc..f07a1ef743d 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -1718,7 +1718,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 0ba729112b0..b3edfa28975 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -1543,7 +1543,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index 3720f9452ec..123e2202cc8 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -1562,7 +1562,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 7450d7297de..3f15f21d08e 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -1706,7 +1706,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index 2317e190a0b..fb690c9b65a 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -1668,7 +1668,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index b2947911439..628d07ea772 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -1693,7 +1693,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 8cf4b23ea7d..5cc7994a356 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -1502,7 +1502,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 2b15f0a9f1e..c4a67fde71c 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -1551,7 +1551,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index a69543037ea..245d2d7c06f 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -1556,7 +1556,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 086ddeb8a82..d198ac2ebfb 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -1857,7 +1857,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index 2e0205a59a5..9328487bf64 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -1435,7 +1435,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index 0314e40738c..ff3cba3162d 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -1552,7 +1552,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index 8019511cea5..f76dd2cf831 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -1903,7 +1903,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 52cc16e43fc..efefd50741a 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -1724,7 +1724,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 7b150d7e067..09a4b48f406 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -1644,7 +1644,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index 11f6abda8ee..514591c3e11 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -1452,7 +1452,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index 0546bb3aa8b..0a0f513958a 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -1879,7 +1879,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index b13d2e8e7b0..9c363bdaa76 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -1702,7 +1702,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index 13c79dc7ae1..8c795015df2 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -1624,7 +1624,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index 19e304e4e36..c66fc513f64 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -1587,7 +1587,7 @@ jobs: - name: Install threat-detect binary if: always() && steps.detection_guard.outputs.run_detection == 'true' run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.0 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" latest - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/actions/setup/sh/install_threat_detect_binary.sh b/actions/setup/sh/install_threat_detect_binary.sh index 6bdd581dab9..ea4b58bcdbd 100755 --- a/actions/setup/sh/install_threat_detect_binary.sh +++ b/actions/setup/sh/install_threat_detect_binary.sh @@ -8,7 +8,8 @@ set +o histexpand # Usage: install_threat_detect_binary.sh VERSION [--rootless] # # Arguments: -# VERSION - threat-detect version to install (e.g., v0.2.2) +# VERSION - threat-detect version to install (e.g., v0.2.2) or "latest" to +# resolve and install the latest release from GitHub # --rootless - Install to ~/.local/bin without sudo; appends that directory to # $GITHUB_PATH so subsequent steps find the binary. Use this on # ARC/DinD runners that enforce allowPrivilegeEscalation: false. @@ -55,6 +56,19 @@ if [ -z "$THREAT_DETECT_VERSION" ]; then exit 1 fi +# Resolve "latest" to the actual release tag via the GitHub API +if [ "$THREAT_DETECT_VERSION" = "latest" ]; then + echo "Resolving latest threat-detect version from GitHub API..." + THREAT_DETECT_VERSION=$(curl -fsSL --retry 5 --retry-delay 10 --retry-max-time 180 \ + "https://api.github.com/repos/${THREAT_DETECT_REPO}/releases/latest" | \ + grep '"tag_name"' | sed 's/.*"tag_name": *"\([^"]*\)".*/\1/') + if [ -z "$THREAT_DETECT_VERSION" ]; then + echo "ERROR: Could not resolve latest threat-detect version from GitHub API" >&2 + exit 1 + fi + echo "Resolved latest threat-detect version: ${THREAT_DETECT_VERSION}" +fi + # In rootless mode, install into the user's home directory instead of /usr/local/bin # so that ARC/DinD runners with allowPrivilegeEscalation: false can run without sudo. if [ "$ROOTLESS" = "true" ]; then diff --git a/pkg/constants/feature_constants.go b/pkg/constants/feature_constants.go index 017665f7303..0562b3d2404 100644 --- a/pkg/constants/feature_constants.go +++ b/pkg/constants/feature_constants.go @@ -90,7 +90,7 @@ const ( // When enabled, the compiler emits a detection job that downloads and runs // the threat-detect binary from GitHub Releases under AWF, writing a structured // detection_result.json instead of using the inline engine execution path. - // The binary version is hard-pinned via DefaultThreatDetectVersion in version_constants.go. + // The binary version is resolved at runtime via DefaultThreatDetectVersion in version_constants.go. // // Workflow frontmatter usage: // diff --git a/pkg/constants/version_constants.go b/pkg/constants/version_constants.go index 41a12f75792..ec63591926d 100644 --- a/pkg/constants/version_constants.go +++ b/pkg/constants/version_constants.go @@ -172,11 +172,12 @@ const DefaultMCPSDKVersion Version = "1.24.0" // DefaultGitHubScriptVersion is the default version of the actions/github-script action const DefaultGitHubScriptVersion Version = "v9" -// DefaultThreatDetectVersion is the default version of the gh-aw-threat-detection binary. -// This version is downloaded from GitHub Releases when `features: gh-aw-detection: true` -// is set in the workflow frontmatter, enabling the external threat-detect binary path instead -// of the inline engine execution path. -const DefaultThreatDetectVersion Version = "v0.4.0" +// DefaultThreatDetectVersion is the version of the gh-aw-threat-detection binary to install. +// When set to "latest", the install script resolves the actual release tag from the GitHub API +// at runtime. This is used when `features: gh-aw-detection: true` is set in the workflow +// frontmatter, enabling the external threat-detect binary path instead of the inline engine +// execution path. +const DefaultThreatDetectVersion Version = "latest" // GhSkillsMinVersion is the minimum gh CLI version required for frontmatter skill support // (installing gh extensions via `gh extension install`). Workflows that install frontmatter diff --git a/pkg/workflow/threat_detection_isolation_test.go b/pkg/workflow/threat_detection_isolation_test.go index 83d2eb4d4a4..449872dabf3 100644 --- a/pkg/workflow/threat_detection_isolation_test.go +++ b/pkg/workflow/threat_detection_isolation_test.go @@ -216,9 +216,9 @@ Test workflow` if !strings.Contains(detectionSection, "install_copilot_cli.sh") { t.Error("External detector path must emit engine installation step for copilot") } - // The install step must pass the pinned DefaultThreatDetectVersion to the script + // The install step must pass the DefaultThreatDetectVersion to the script if !strings.Contains(detectionSection, string(constants.DefaultThreatDetectVersion)) { - t.Errorf("External detector path must use pinned version %q from DefaultThreatDetectVersion", constants.DefaultThreatDetectVersion) + t.Errorf("External detector path must use version %q from DefaultThreatDetectVersion", constants.DefaultThreatDetectVersion) } // The AWF execution step must use threat-detect as the command