diff --git a/.github/workflows/ab-testing-advisor.lock.yml b/.github/workflows/ab-testing-advisor.lock.yml index f4d1d55aca7..ae38d9e85c2 100644 --- a/.github/workflows/ab-testing-advisor.lock.yml +++ b/.github/workflows/ab-testing-advisor.lock.yml @@ -1521,7 +1521,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agent-job-health.lock.yml b/.github/workflows/agent-job-health.lock.yml index b9218bd81be..48ebce02448 100644 --- a/.github/workflows/agent-job-health.lock.yml +++ b/.github/workflows/agent-job-health.lock.yml @@ -1770,7 +1770,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agent-performance-analyzer.lock.yml b/.github/workflows/agent-performance-analyzer.lock.yml index 4fe389531e6..ff50d8e7a38 100644 --- a/.github/workflows/agent-performance-analyzer.lock.yml +++ b/.github/workflows/agent-performance-analyzer.lock.yml @@ -1774,7 +1774,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agent-persona-explorer.lock.yml b/.github/workflows/agent-persona-explorer.lock.yml index ecbbfe0e1cb..d923752d347 100644 --- a/.github/workflows/agent-persona-explorer.lock.yml +++ b/.github/workflows/agent-persona-explorer.lock.yml @@ -1624,7 +1624,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agentic-token-audit.lock.yml b/.github/workflows/agentic-token-audit.lock.yml index 3e16c414247..f29cabdcf6e 100644 --- a/.github/workflows/agentic-token-audit.lock.yml +++ b/.github/workflows/agentic-token-audit.lock.yml @@ -1673,7 +1673,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/agentic-token-trend-audit.lock.yml b/.github/workflows/agentic-token-trend-audit.lock.yml index 6f4837f991e..26008df4ff8 100644 --- a/.github/workflows/agentic-token-trend-audit.lock.yml +++ b/.github/workflows/agentic-token-trend-audit.lock.yml @@ -1615,7 +1615,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/api-consumption-report.lock.yml b/.github/workflows/api-consumption-report.lock.yml index 2b04dc8cc49..9f299717319 100644 --- a/.github/workflows/api-consumption-report.lock.yml +++ b/.github/workflows/api-consumption-report.lock.yml @@ -1767,7 +1767,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/approach-validator.lock.yml b/.github/workflows/approach-validator.lock.yml index 3326b16f496..8b789c26b57 100644 --- a/.github/workflows/approach-validator.lock.yml +++ b/.github/workflows/approach-validator.lock.yml @@ -1766,7 +1766,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/archie.lock.yml b/.github/workflows/archie.lock.yml index 478b4c23ae3..0ef493216dc 100644 --- a/.github/workflows/archie.lock.yml +++ b/.github/workflows/archie.lock.yml @@ -1664,7 +1664,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/architecture-guardian.lock.yml b/.github/workflows/architecture-guardian.lock.yml index d30941395f1..bfde83e6599 100644 --- a/.github/workflows/architecture-guardian.lock.yml +++ b/.github/workflows/architecture-guardian.lock.yml @@ -1575,7 +1575,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml index 397f30d5347..23d6e1da7c1 100644 --- a/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml +++ b/.github/workflows/archivx-agentic-workflows-analyzer.lock.yml @@ -1688,7 +1688,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/artifacts-summary.lock.yml b/.github/workflows/artifacts-summary.lock.yml index ab5470e81c2..a4fa51dad01 100644 --- a/.github/workflows/artifacts-summary.lock.yml +++ b/.github/workflows/artifacts-summary.lock.yml @@ -1563,7 +1563,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/audit-workflows.lock.yml b/.github/workflows/audit-workflows.lock.yml index 4cf52d57712..921924551a6 100644 --- a/.github/workflows/audit-workflows.lock.yml +++ b/.github/workflows/audit-workflows.lock.yml @@ -1867,7 +1867,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/auto-triage-issues.lock.yml b/.github/workflows/auto-triage-issues.lock.yml index a643ea0cd9f..cddaf98e2cd 100644 --- a/.github/workflows/auto-triage-issues.lock.yml +++ b/.github/workflows/auto-triage-issues.lock.yml @@ -1544,7 +1544,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/avenger.lock.yml b/.github/workflows/avenger.lock.yml index 4235ce2a529..323b94bf2e1 100644 --- a/.github/workflows/avenger.lock.yml +++ b/.github/workflows/avenger.lock.yml @@ -1764,7 +1764,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/aw-failure-investigator.lock.yml b/.github/workflows/aw-failure-investigator.lock.yml index 86bbbe393ca..0ba88892071 100644 --- a/.github/workflows/aw-failure-investigator.lock.yml +++ b/.github/workflows/aw-failure-investigator.lock.yml @@ -1784,7 +1784,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/blog-auditor.lock.yml b/.github/workflows/blog-auditor.lock.yml index ef566e03144..f52962b2ec4 100644 --- a/.github/workflows/blog-auditor.lock.yml +++ b/.github/workflows/blog-auditor.lock.yml @@ -1696,7 +1696,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/breaking-change-checker.lock.yml b/.github/workflows/breaking-change-checker.lock.yml index bdb087a25cb..925d6dae2e8 100644 --- a/.github/workflows/breaking-change-checker.lock.yml +++ b/.github/workflows/breaking-change-checker.lock.yml @@ -1622,7 +1622,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/changeset.lock.yml b/.github/workflows/changeset.lock.yml index 4ef579756f1..e5181d5dc93 100644 --- a/.github/workflows/changeset.lock.yml +++ b/.github/workflows/changeset.lock.yml @@ -1675,7 +1675,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml index 90f8269f7a0..0681abf9a69 100644 --- a/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml +++ b/.github/workflows/chaos-pr-bundle-fuzzer.lock.yml @@ -1520,7 +1520,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ci-coach.lock.yml b/.github/workflows/ci-coach.lock.yml index c99f6cc43f7..070786ff4f6 100644 --- a/.github/workflows/ci-coach.lock.yml +++ b/.github/workflows/ci-coach.lock.yml @@ -1753,7 +1753,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ci-doctor.lock.yml b/.github/workflows/ci-doctor.lock.yml index f1fa387f9f1..aa4f48fd2ba 100644 --- a/.github/workflows/ci-doctor.lock.yml +++ b/.github/workflows/ci-doctor.lock.yml @@ -1867,7 +1867,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/claude-code-user-docs-review.lock.yml b/.github/workflows/claude-code-user-docs-review.lock.yml index abc5f84ebf8..be44051e5fe 100644 --- a/.github/workflows/claude-code-user-docs-review.lock.yml +++ b/.github/workflows/claude-code-user-docs-review.lock.yml @@ -1639,7 +1639,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cli-consistency-checker.lock.yml b/.github/workflows/cli-consistency-checker.lock.yml index da3495a6c2f..b42e2d44075 100644 --- a/.github/workflows/cli-consistency-checker.lock.yml +++ b/.github/workflows/cli-consistency-checker.lock.yml @@ -1536,7 +1536,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cli-version-checker.lock.yml b/.github/workflows/cli-version-checker.lock.yml index 56bfd394837..b3027703c8b 100644 --- a/.github/workflows/cli-version-checker.lock.yml +++ b/.github/workflows/cli-version-checker.lock.yml @@ -1643,7 +1643,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/cloclo.lock.yml b/.github/workflows/cloclo.lock.yml index 934683e8cff..e400b4e123d 100644 --- a/.github/workflows/cloclo.lock.yml +++ b/.github/workflows/cloclo.lock.yml @@ -2043,7 +2043,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/code-scanning-fixer.lock.yml b/.github/workflows/code-scanning-fixer.lock.yml index 5c8c7857ff8..7b639c7d080 100644 --- a/.github/workflows/code-scanning-fixer.lock.yml +++ b/.github/workflows/code-scanning-fixer.lock.yml @@ -1760,7 +1760,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/code-simplifier.lock.yml b/.github/workflows/code-simplifier.lock.yml index e6626552155..753ad4dbd0e 100644 --- a/.github/workflows/code-simplifier.lock.yml +++ b/.github/workflows/code-simplifier.lock.yml @@ -1648,7 +1648,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/commit-changes-analyzer.lock.yml b/.github/workflows/commit-changes-analyzer.lock.yml index 804ec5d9728..613a931abad 100644 --- a/.github/workflows/commit-changes-analyzer.lock.yml +++ b/.github/workflows/commit-changes-analyzer.lock.yml @@ -1458,7 +1458,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/constraint-solving-potd.lock.yml b/.github/workflows/constraint-solving-potd.lock.yml index 15a1848470c..11735c23d2c 100644 --- a/.github/workflows/constraint-solving-potd.lock.yml +++ b/.github/workflows/constraint-solving-potd.lock.yml @@ -1543,7 +1543,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/contribution-check.lock.yml b/.github/workflows/contribution-check.lock.yml index c01101d2e7d..4347021e7ce 100644 --- a/.github/workflows/contribution-check.lock.yml +++ b/.github/workflows/contribution-check.lock.yml @@ -1715,7 +1715,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-agent-analysis.lock.yml b/.github/workflows/copilot-agent-analysis.lock.yml index 8e8e18d0f75..787bf8a1845 100644 --- a/.github/workflows/copilot-agent-analysis.lock.yml +++ b/.github/workflows/copilot-agent-analysis.lock.yml @@ -1775,7 +1775,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-centralization-drilldown.lock.yml b/.github/workflows/copilot-centralization-drilldown.lock.yml index ea7585c99ff..6005e183d1c 100644 --- a/.github/workflows/copilot-centralization-drilldown.lock.yml +++ b/.github/workflows/copilot-centralization-drilldown.lock.yml @@ -1503,7 +1503,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-centralization-optimizer.lock.yml b/.github/workflows/copilot-centralization-optimizer.lock.yml index 37406a05a4c..f5face4bfd2 100644 --- a/.github/workflows/copilot-centralization-optimizer.lock.yml +++ b/.github/workflows/copilot-centralization-optimizer.lock.yml @@ -1568,7 +1568,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-cli-deep-research.lock.yml b/.github/workflows/copilot-cli-deep-research.lock.yml index 339a0766517..d21b48a27bd 100644 --- a/.github/workflows/copilot-cli-deep-research.lock.yml +++ b/.github/workflows/copilot-cli-deep-research.lock.yml @@ -1581,7 +1581,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-opt.lock.yml b/.github/workflows/copilot-opt.lock.yml index 2eae09f9a60..6110134ac8e 100644 --- a/.github/workflows/copilot-opt.lock.yml +++ b/.github/workflows/copilot-opt.lock.yml @@ -1640,7 +1640,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-merged-report.lock.yml b/.github/workflows/copilot-pr-merged-report.lock.yml index bb5696599a0..14747b7fcfe 100644 --- a/.github/workflows/copilot-pr-merged-report.lock.yml +++ b/.github/workflows/copilot-pr-merged-report.lock.yml @@ -1527,7 +1527,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-nlp-analysis.lock.yml b/.github/workflows/copilot-pr-nlp-analysis.lock.yml index bd2654c09c3..698f3bb2de5 100644 --- a/.github/workflows/copilot-pr-nlp-analysis.lock.yml +++ b/.github/workflows/copilot-pr-nlp-analysis.lock.yml @@ -1704,7 +1704,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-pr-prompt-analysis.lock.yml b/.github/workflows/copilot-pr-prompt-analysis.lock.yml index e2711dcea52..e109262c1de 100644 --- a/.github/workflows/copilot-pr-prompt-analysis.lock.yml +++ b/.github/workflows/copilot-pr-prompt-analysis.lock.yml @@ -1637,7 +1637,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/copilot-session-insights.lock.yml b/.github/workflows/copilot-session-insights.lock.yml index 73d583d2097..8604c4358a4 100644 --- a/.github/workflows/copilot-session-insights.lock.yml +++ b/.github/workflows/copilot-session-insights.lock.yml @@ -1749,7 +1749,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/craft.lock.yml b/.github/workflows/craft.lock.yml index 33b9c641eff..a4270162cc4 100644 --- a/.github/workflows/craft.lock.yml +++ b/.github/workflows/craft.lock.yml @@ -1651,7 +1651,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-action-setup-security-audit.lock.yml b/.github/workflows/daily-action-setup-security-audit.lock.yml index 935833d87d4..f9ef4b06f38 100644 --- a/.github/workflows/daily-action-setup-security-audit.lock.yml +++ b/.github/workflows/daily-action-setup-security-audit.lock.yml @@ -1618,7 +1618,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml index 85877c45182..951d57d8a39 100644 --- a/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml +++ b/.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml @@ -1828,7 +1828,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml index 58c2d9153cd..dd14202ef8e 100644 --- a/.github/workflows/daily-agentrx-trace-optimizer.lock.yml +++ b/.github/workflows/daily-agentrx-trace-optimizer.lock.yml @@ -1821,7 +1821,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-ambient-context-optimizer.lock.yml b/.github/workflows/daily-ambient-context-optimizer.lock.yml index cc0c3aa30f0..13384a4e7a5 100644 --- a/.github/workflows/daily-ambient-context-optimizer.lock.yml +++ b/.github/workflows/daily-ambient-context-optimizer.lock.yml @@ -1661,7 +1661,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-architecture-diagram.lock.yml b/.github/workflows/daily-architecture-diagram.lock.yml index aa583fea949..b44696e1f6b 100644 --- a/.github/workflows/daily-architecture-diagram.lock.yml +++ b/.github/workflows/daily-architecture-diagram.lock.yml @@ -1838,7 +1838,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-arxiv-researcher.lock.yml b/.github/workflows/daily-arxiv-researcher.lock.yml index 64b1839f1fa..5d6fdaf4e49 100644 --- a/.github/workflows/daily-arxiv-researcher.lock.yml +++ b/.github/workflows/daily-arxiv-researcher.lock.yml @@ -1752,7 +1752,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-assign-issue-to-user.lock.yml b/.github/workflows/daily-assign-issue-to-user.lock.yml index 34a800e6cdd..67f098bee92 100644 --- a/.github/workflows/daily-assign-issue-to-user.lock.yml +++ b/.github/workflows/daily-assign-issue-to-user.lock.yml @@ -1602,7 +1602,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml index bc584400b65..0d3ba3a779f 100644 --- a/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml +++ b/.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml @@ -1733,7 +1733,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml index e4821a2cfa7..e680e7861e6 100644 --- a/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml +++ b/.github/workflows/daily-aw-cross-repo-compile-check.lock.yml @@ -1673,7 +1673,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml index ebec1923648..1e63d91bcee 100644 --- a/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml +++ b/.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml @@ -1557,7 +1557,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-byok-ollama-test.lock.yml b/.github/workflows/daily-byok-ollama-test.lock.yml index d99c7b20736..98adbbe1a4d 100644 --- a/.github/workflows/daily-byok-ollama-test.lock.yml +++ b/.github/workflows/daily-byok-ollama-test.lock.yml @@ -1512,7 +1512,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cache-strategy-analyzer.lock.yml b/.github/workflows/daily-cache-strategy-analyzer.lock.yml index 56a3d0403fa..786483db5fd 100644 --- a/.github/workflows/daily-cache-strategy-analyzer.lock.yml +++ b/.github/workflows/daily-cache-strategy-analyzer.lock.yml @@ -1852,7 +1852,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-caveman-optimizer.lock.yml b/.github/workflows/daily-caveman-optimizer.lock.yml index 506b15a6ff6..bfab82e0cfd 100644 --- a/.github/workflows/daily-caveman-optimizer.lock.yml +++ b/.github/workflows/daily-caveman-optimizer.lock.yml @@ -1803,7 +1803,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-choice-test.lock.yml b/.github/workflows/daily-choice-test.lock.yml index 85b9213ab13..fde70ae0238 100644 --- a/.github/workflows/daily-choice-test.lock.yml +++ b/.github/workflows/daily-choice-test.lock.yml @@ -1594,7 +1594,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cli-performance.lock.yml b/.github/workflows/daily-cli-performance.lock.yml index 120b20f1cae..f85196c6070 100644 --- a/.github/workflows/daily-cli-performance.lock.yml +++ b/.github/workflows/daily-cli-performance.lock.yml @@ -1953,7 +1953,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-cli-tools-tester.lock.yml b/.github/workflows/daily-cli-tools-tester.lock.yml index 9b56049fc67..cdd5d22ecaa 100644 --- a/.github/workflows/daily-cli-tools-tester.lock.yml +++ b/.github/workflows/daily-cli-tools-tester.lock.yml @@ -1627,7 +1627,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-code-debt-aider.lock.yml b/.github/workflows/daily-code-debt-aider.lock.yml index 3030bf3dd8e..1767fd98038 100644 --- a/.github/workflows/daily-code-debt-aider.lock.yml +++ b/.github/workflows/daily-code-debt-aider.lock.yml @@ -1571,7 +1571,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-code-metrics.lock.yml b/.github/workflows/daily-code-metrics.lock.yml index e9fd1657f91..2f44261f9e9 100644 --- a/.github/workflows/daily-code-metrics.lock.yml +++ b/.github/workflows/daily-code-metrics.lock.yml @@ -1923,7 +1923,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-community-attribution.lock.yml b/.github/workflows/daily-community-attribution.lock.yml index 3ba10d5c8c6..34d6f54760f 100644 --- a/.github/workflows/daily-community-attribution.lock.yml +++ b/.github/workflows/daily-community-attribution.lock.yml @@ -1849,7 +1849,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-compiler-quality.lock.yml b/.github/workflows/daily-compiler-quality.lock.yml index bc90dc6a616..c2a3f9672e2 100644 --- a/.github/workflows/daily-compiler-quality.lock.yml +++ b/.github/workflows/daily-compiler-quality.lock.yml @@ -1747,7 +1747,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml index ba99be547f8..18b4311a776 100644 --- a/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml +++ b/.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml @@ -1729,7 +1729,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-credit-limit-test.lock.yml b/.github/workflows/daily-credit-limit-test.lock.yml index 392079cdf18..6f0fcccc6b1 100644 --- a/.github/workflows/daily-credit-limit-test.lock.yml +++ b/.github/workflows/daily-credit-limit-test.lock.yml @@ -1539,7 +1539,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-doc-healer.lock.yml b/.github/workflows/daily-doc-healer.lock.yml index 19c1887b17e..839d21f8bea 100644 --- a/.github/workflows/daily-doc-healer.lock.yml +++ b/.github/workflows/daily-doc-healer.lock.yml @@ -1911,7 +1911,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-doc-updater.lock.yml b/.github/workflows/daily-doc-updater.lock.yml index 159753551a2..bdd85d1aa77 100644 --- a/.github/workflows/daily-doc-updater.lock.yml +++ b/.github/workflows/daily-doc-updater.lock.yml @@ -1705,7 +1705,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-documentation-diagram.lock.yml b/.github/workflows/daily-documentation-diagram.lock.yml index 1a505c8c8ae..ac1b0432885 100644 --- a/.github/workflows/daily-documentation-diagram.lock.yml +++ b/.github/workflows/daily-documentation-diagram.lock.yml @@ -1657,7 +1657,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml index 56d95f80d53..c47796f487e 100644 --- a/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml +++ b/.github/workflows/daily-elixir-credo-snippet-audit.lock.yml @@ -1682,7 +1682,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-evals-report.lock.yml b/.github/workflows/daily-evals-report.lock.yml index 4f18ec2b4fa..a02dee83587 100644 --- a/.github/workflows/daily-evals-report.lock.yml +++ b/.github/workflows/daily-evals-report.lock.yml @@ -1749,7 +1749,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-experiment-report.lock.yml b/.github/workflows/daily-experiment-report.lock.yml index dd410d0b89b..aa594ee9889 100644 --- a/.github/workflows/daily-experiment-report.lock.yml +++ b/.github/workflows/daily-experiment-report.lock.yml @@ -1691,7 +1691,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-fact.lock.yml b/.github/workflows/daily-fact.lock.yml index b015bb5b059..63ca6a9d7b3 100644 --- a/.github/workflows/daily-fact.lock.yml +++ b/.github/workflows/daily-fact.lock.yml @@ -1798,7 +1798,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-file-diet.lock.yml b/.github/workflows/daily-file-diet.lock.yml index f656c7218be..32a0ebc059c 100644 --- a/.github/workflows/daily-file-diet.lock.yml +++ b/.github/workflows/daily-file-diet.lock.yml @@ -1653,7 +1653,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-firewall-report.lock.yml b/.github/workflows/daily-firewall-report.lock.yml index 150e5f379c2..f22ef45b97d 100644 --- a/.github/workflows/daily-firewall-report.lock.yml +++ b/.github/workflows/daily-firewall-report.lock.yml @@ -1680,7 +1680,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-formal-spec-verifier.lock.yml b/.github/workflows/daily-formal-spec-verifier.lock.yml index b2c8b310fce..8d49d62b59e 100644 --- a/.github/workflows/daily-formal-spec-verifier.lock.yml +++ b/.github/workflows/daily-formal-spec-verifier.lock.yml @@ -1653,7 +1653,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-function-namer.lock.yml b/.github/workflows/daily-function-namer.lock.yml index b806bab891a..6c266aca175 100644 --- a/.github/workflows/daily-function-namer.lock.yml +++ b/.github/workflows/daily-function-namer.lock.yml @@ -1592,7 +1592,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-geo-optimizer.lock.yml b/.github/workflows/daily-geo-optimizer.lock.yml index b338f156673..5138a8adcf0 100644 --- a/.github/workflows/daily-geo-optimizer.lock.yml +++ b/.github/workflows/daily-geo-optimizer.lock.yml @@ -1600,7 +1600,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-go-test-parallelizer.lock.yml b/.github/workflows/daily-go-test-parallelizer.lock.yml index a686444ffa3..6b98ea55bb2 100644 --- a/.github/workflows/daily-go-test-parallelizer.lock.yml +++ b/.github/workflows/daily-go-test-parallelizer.lock.yml @@ -1648,7 +1648,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-go-test-stubs-aider.lock.yml b/.github/workflows/daily-go-test-stubs-aider.lock.yml index 261402dface..6b8f5790f2d 100644 --- a/.github/workflows/daily-go-test-stubs-aider.lock.yml +++ b/.github/workflows/daily-go-test-stubs-aider.lock.yml @@ -1571,7 +1571,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-graft-intelligence.lock.yml b/.github/workflows/daily-graft-intelligence.lock.yml index b7140a1b0ce..98ff88d3580 100644 --- a/.github/workflows/daily-graft-intelligence.lock.yml +++ b/.github/workflows/daily-graft-intelligence.lock.yml @@ -1580,7 +1580,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-hippo-learn.lock.yml b/.github/workflows/daily-hippo-learn.lock.yml index df73c691f13..101dba36f4d 100644 --- a/.github/workflows/daily-hippo-learn.lock.yml +++ b/.github/workflows/daily-hippo-learn.lock.yml @@ -1676,7 +1676,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-issues-report.lock.yml b/.github/workflows/daily-issues-report.lock.yml index c806f83ee7e..59a3ed1b49b 100644 --- a/.github/workflows/daily-issues-report.lock.yml +++ b/.github/workflows/daily-issues-report.lock.yml @@ -1880,7 +1880,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-max-ai-credits-test.lock.yml b/.github/workflows/daily-max-ai-credits-test.lock.yml index e5a19224ed2..d716ec5dcf5 100644 --- a/.github/workflows/daily-max-ai-credits-test.lock.yml +++ b/.github/workflows/daily-max-ai-credits-test.lock.yml @@ -1430,7 +1430,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml index db1ae9e9e3b..a3e8212faed 100644 --- a/.github/workflows/daily-mcp-concurrency-analysis.lock.yml +++ b/.github/workflows/daily-mcp-concurrency-analysis.lock.yml @@ -1696,7 +1696,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-model-inventory.lock.yml b/.github/workflows/daily-model-inventory.lock.yml index 294f0b30410..75b4b415866 100644 --- a/.github/workflows/daily-model-inventory.lock.yml +++ b/.github/workflows/daily-model-inventory.lock.yml @@ -1877,7 +1877,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-model-resolution.lock.yml b/.github/workflows/daily-model-resolution.lock.yml index 650c752b4ef..30e1d1c319e 100644 --- a/.github/workflows/daily-model-resolution.lock.yml +++ b/.github/workflows/daily-model-resolution.lock.yml @@ -1592,7 +1592,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-multi-device-docs-tester.lock.yml b/.github/workflows/daily-multi-device-docs-tester.lock.yml index cb3d2870d26..1ee0ccdc3a3 100644 --- a/.github/workflows/daily-multi-device-docs-tester.lock.yml +++ b/.github/workflows/daily-multi-device-docs-tester.lock.yml @@ -1585,7 +1585,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-news.lock.yml b/.github/workflows/daily-news.lock.yml index ab57cb13599..825799a98ba 100644 --- a/.github/workflows/daily-news.lock.yml +++ b/.github/workflows/daily-news.lock.yml @@ -1792,7 +1792,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-observability-report.lock.yml b/.github/workflows/daily-observability-report.lock.yml index fd507c339e3..f98d2ff6104 100644 --- a/.github/workflows/daily-observability-report.lock.yml +++ b/.github/workflows/daily-observability-report.lock.yml @@ -1658,7 +1658,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-performance-summary.lock.yml b/.github/workflows/daily-performance-summary.lock.yml index 7a38b0d967d..73038243190 100644 --- a/.github/workflows/daily-performance-summary.lock.yml +++ b/.github/workflows/daily-performance-summary.lock.yml @@ -2308,7 +2308,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-pr-review-cursor.lock.yml b/.github/workflows/daily-pr-review-cursor.lock.yml index 3510d6ba8a3..251df74ade5 100644 --- a/.github/workflows/daily-pr-review-cursor.lock.yml +++ b/.github/workflows/daily-pr-review-cursor.lock.yml @@ -1544,7 +1544,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-regression-audit-kiro.lock.yml b/.github/workflows/daily-regression-audit-kiro.lock.yml index e2344a56bb7..5115a77756f 100644 --- a/.github/workflows/daily-regression-audit-kiro.lock.yml +++ b/.github/workflows/daily-regression-audit-kiro.lock.yml @@ -1549,7 +1549,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-regulatory.lock.yml b/.github/workflows/daily-regulatory.lock.yml index 941ec137fe1..8974d524854 100644 --- a/.github/workflows/daily-regulatory.lock.yml +++ b/.github/workflows/daily-regulatory.lock.yml @@ -2148,7 +2148,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-reliability-review.lock.yml b/.github/workflows/daily-reliability-review.lock.yml index 288823611e1..60c0fc34c56 100644 --- a/.github/workflows/daily-reliability-review.lock.yml +++ b/.github/workflows/daily-reliability-review.lock.yml @@ -1604,7 +1604,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-rendering-scripts-verifier.lock.yml b/.github/workflows/daily-rendering-scripts-verifier.lock.yml index 5b50b2b356d..9b8553b382f 100644 --- a/.github/workflows/daily-rendering-scripts-verifier.lock.yml +++ b/.github/workflows/daily-rendering-scripts-verifier.lock.yml @@ -1853,7 +1853,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-repo-chronicle.lock.yml b/.github/workflows/daily-repo-chronicle.lock.yml index 6e8674916d5..88f8e3fa349 100644 --- a/.github/workflows/daily-repo-chronicle.lock.yml +++ b/.github/workflows/daily-repo-chronicle.lock.yml @@ -1674,7 +1674,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-safe-output-integrator.lock.yml b/.github/workflows/daily-safe-output-integrator.lock.yml index 89ca82276d9..1d7602b296b 100644 --- a/.github/workflows/daily-safe-output-integrator.lock.yml +++ b/.github/workflows/daily-safe-output-integrator.lock.yml @@ -1650,7 +1650,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-safe-output-optimizer.lock.yml b/.github/workflows/daily-safe-output-optimizer.lock.yml index a1a0db7f56c..3553ba2cd19 100644 --- a/.github/workflows/daily-safe-output-optimizer.lock.yml +++ b/.github/workflows/daily-safe-output-optimizer.lock.yml @@ -1832,7 +1832,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-safe-outputs-conformance.lock.yml b/.github/workflows/daily-safe-outputs-conformance.lock.yml index 0d98205358e..3b7d8c22873 100644 --- a/.github/workflows/daily-safe-outputs-conformance.lock.yml +++ b/.github/workflows/daily-safe-outputs-conformance.lock.yml @@ -1607,7 +1607,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml index 091366e81e5..fdec8faac8d 100644 --- a/.github/workflows/daily-safeoutputs-git-simulator.lock.yml +++ b/.github/workflows/daily-safeoutputs-git-simulator.lock.yml @@ -1738,7 +1738,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-schema-audit-cursor.lock.yml b/.github/workflows/daily-schema-audit-cursor.lock.yml index 208c3f2ef97..c743ada742d 100644 --- a/.github/workflows/daily-schema-audit-cursor.lock.yml +++ b/.github/workflows/daily-schema-audit-cursor.lock.yml @@ -1547,7 +1547,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-secrets-analysis.lock.yml b/.github/workflows/daily-secrets-analysis.lock.yml index 086c6423e56..4cd9f453037 100644 --- a/.github/workflows/daily-secrets-analysis.lock.yml +++ b/.github/workflows/daily-secrets-analysis.lock.yml @@ -1525,7 +1525,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-security-observability.lock.yml b/.github/workflows/daily-security-observability.lock.yml index c1791d589e4..a52d546bd9a 100644 --- a/.github/workflows/daily-security-observability.lock.yml +++ b/.github/workflows/daily-security-observability.lock.yml @@ -1752,7 +1752,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-security-red-team.lock.yml b/.github/workflows/daily-security-red-team.lock.yml index 47d299b5047..4d953cab285 100644 --- a/.github/workflows/daily-security-red-team.lock.yml +++ b/.github/workflows/daily-security-red-team.lock.yml @@ -1681,7 +1681,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-semgrep-scan.lock.yml b/.github/workflows/daily-semgrep-scan.lock.yml index 8c9613cc4a6..cf3721633aa 100644 --- a/.github/workflows/daily-semgrep-scan.lock.yml +++ b/.github/workflows/daily-semgrep-scan.lock.yml @@ -1574,7 +1574,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-spdd-spec-planner.lock.yml b/.github/workflows/daily-spdd-spec-planner.lock.yml index 6fcd45ff76c..796442e2235 100644 --- a/.github/workflows/daily-spdd-spec-planner.lock.yml +++ b/.github/workflows/daily-spdd-spec-planner.lock.yml @@ -1614,7 +1614,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-spec-coverage-kiro.lock.yml b/.github/workflows/daily-spec-coverage-kiro.lock.yml index 89ee67353c8..acc4cecb339 100644 --- a/.github/workflows/daily-spec-coverage-kiro.lock.yml +++ b/.github/workflows/daily-spec-coverage-kiro.lock.yml @@ -1547,7 +1547,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-spending-forecast.lock.yml b/.github/workflows/daily-spending-forecast.lock.yml index 87df445676b..d9c4b4ee59b 100644 --- a/.github/workflows/daily-spending-forecast.lock.yml +++ b/.github/workflows/daily-spending-forecast.lock.yml @@ -1680,7 +1680,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-squid-image-scan.lock.yml b/.github/workflows/daily-squid-image-scan.lock.yml index fc7d5c15d8f..be0a9021716 100644 --- a/.github/workflows/daily-squid-image-scan.lock.yml +++ b/.github/workflows/daily-squid-image-scan.lock.yml @@ -1646,7 +1646,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-storify.lock.yml b/.github/workflows/daily-storify.lock.yml index 7c682239ac9..6bae9420661 100644 --- a/.github/workflows/daily-storify.lock.yml +++ b/.github/workflows/daily-storify.lock.yml @@ -1698,7 +1698,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-syntax-error-quality.lock.yml b/.github/workflows/daily-syntax-error-quality.lock.yml index 3846ff78c2e..90e1b2b776c 100644 --- a/.github/workflows/daily-syntax-error-quality.lock.yml +++ b/.github/workflows/daily-syntax-error-quality.lock.yml @@ -1548,7 +1548,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-team-evolution-insights.lock.yml b/.github/workflows/daily-team-evolution-insights.lock.yml index 443696b91f0..d8c203da003 100644 --- a/.github/workflows/daily-team-evolution-insights.lock.yml +++ b/.github/workflows/daily-team-evolution-insights.lock.yml @@ -1726,7 +1726,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-team-status.lock.yml b/.github/workflows/daily-team-status.lock.yml index db3d84260b9..98701c8159c 100644 --- a/.github/workflows/daily-team-status.lock.yml +++ b/.github/workflows/daily-team-status.lock.yml @@ -1518,7 +1518,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-testify-uber-super-expert.lock.yml b/.github/workflows/daily-testify-uber-super-expert.lock.yml index e87ec27284a..aa5ffd6ea7c 100644 --- a/.github/workflows/daily-testify-uber-super-expert.lock.yml +++ b/.github/workflows/daily-testify-uber-super-expert.lock.yml @@ -1666,7 +1666,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-token-consumption-report.lock.yml b/.github/workflows/daily-token-consumption-report.lock.yml index 7c731f01c62..92c28181eb7 100644 --- a/.github/workflows/daily-token-consumption-report.lock.yml +++ b/.github/workflows/daily-token-consumption-report.lock.yml @@ -1779,7 +1779,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-trajectory-grader-implementer.lock.yml b/.github/workflows/daily-trajectory-grader-implementer.lock.yml index e88e558037f..9eb6ba40d62 100644 --- a/.github/workflows/daily-trajectory-grader-implementer.lock.yml +++ b/.github/workflows/daily-trajectory-grader-implementer.lock.yml @@ -1638,7 +1638,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-vulnhunter-scan.lock.yml b/.github/workflows/daily-vulnhunter-scan.lock.yml index 08b57167560..56c95ee6b49 100644 --- a/.github/workflows/daily-vulnhunter-scan.lock.yml +++ b/.github/workflows/daily-vulnhunter-scan.lock.yml @@ -1591,7 +1591,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml index bc7dde407ee..58616ad0c26 100644 --- a/.github/workflows/daily-windows-terminal-integration-builder.lock.yml +++ b/.github/workflows/daily-windows-terminal-integration-builder.lock.yml @@ -1489,7 +1489,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-workflow-updater.lock.yml b/.github/workflows/daily-workflow-updater.lock.yml index 00e6369a228..7930a63e7b0 100644 --- a/.github/workflows/daily-workflow-updater.lock.yml +++ b/.github/workflows/daily-workflow-updater.lock.yml @@ -1613,7 +1613,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/daily-yamllint-fixer.lock.yml b/.github/workflows/daily-yamllint-fixer.lock.yml index 64f23e42d38..e9bbd1934a8 100644 --- a/.github/workflows/daily-yamllint-fixer.lock.yml +++ b/.github/workflows/daily-yamllint-fixer.lock.yml @@ -1675,7 +1675,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml index 8b28d48f485..390c1f2ce56 100644 --- a/.github/workflows/dataflow-pr-discussion-dataset.lock.yml +++ b/.github/workflows/dataflow-pr-discussion-dataset.lock.yml @@ -1987,7 +1987,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dead-code-remover.lock.yml b/.github/workflows/dead-code-remover.lock.yml index bfec20c8d21..32964128010 100644 --- a/.github/workflows/dead-code-remover.lock.yml +++ b/.github/workflows/dead-code-remover.lock.yml @@ -1671,7 +1671,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/deep-report.lock.yml b/.github/workflows/deep-report.lock.yml index 7e259f0666e..c7d5dee03ec 100644 --- a/.github/workflows/deep-report.lock.yml +++ b/.github/workflows/deep-report.lock.yml @@ -2433,7 +2433,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/deepsec-security-scan.lock.yml b/.github/workflows/deepsec-security-scan.lock.yml index da7844a4ed7..ae94c40aac3 100644 --- a/.github/workflows/deepsec-security-scan.lock.yml +++ b/.github/workflows/deepsec-security-scan.lock.yml @@ -1626,7 +1626,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/delight.lock.yml b/.github/workflows/delight.lock.yml index 4b1f05ee38d..9a02877c3be 100644 --- a/.github/workflows/delight.lock.yml +++ b/.github/workflows/delight.lock.yml @@ -1653,7 +1653,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dependabot-burner.lock.yml b/.github/workflows/dependabot-burner.lock.yml index 8c3affd2956..8aa7abde207 100644 --- a/.github/workflows/dependabot-burner.lock.yml +++ b/.github/workflows/dependabot-burner.lock.yml @@ -1804,7 +1804,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dependabot-go-checker.lock.yml b/.github/workflows/dependabot-go-checker.lock.yml index ae6d61d8aa6..e297f13c718 100644 --- a/.github/workflows/dependabot-go-checker.lock.yml +++ b/.github/workflows/dependabot-go-checker.lock.yml @@ -1636,7 +1636,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/deployment-incident-monitor.lock.yml b/.github/workflows/deployment-incident-monitor.lock.yml index 7b566733919..6e63d17c925 100644 --- a/.github/workflows/deployment-incident-monitor.lock.yml +++ b/.github/workflows/deployment-incident-monitor.lock.yml @@ -1546,7 +1546,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/design-decision-gate.lock.yml b/.github/workflows/design-decision-gate.lock.yml index 3b033b9c732..24ef154286a 100644 --- a/.github/workflows/design-decision-gate.lock.yml +++ b/.github/workflows/design-decision-gate.lock.yml @@ -1774,7 +1774,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/designer-drift-audit.lock.yml b/.github/workflows/designer-drift-audit.lock.yml index ed6a03a0ff8..d98cc5cfe6d 100644 --- a/.github/workflows/designer-drift-audit.lock.yml +++ b/.github/workflows/designer-drift-audit.lock.yml @@ -1476,7 +1476,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/detection-analysis-report.lock.yml b/.github/workflows/detection-analysis-report.lock.yml index ff257554f1e..9973fc71c3e 100644 --- a/.github/workflows/detection-analysis-report.lock.yml +++ b/.github/workflows/detection-analysis-report.lock.yml @@ -1774,7 +1774,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dev-hawk.lock.yml b/.github/workflows/dev-hawk.lock.yml index 4d01589aba3..46a50672c39 100644 --- a/.github/workflows/dev-hawk.lock.yml +++ b/.github/workflows/dev-hawk.lock.yml @@ -1689,7 +1689,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dev.lock.yml b/.github/workflows/dev.lock.yml index ec74c021f79..1ec628d0520 100644 --- a/.github/workflows/dev.lock.yml +++ b/.github/workflows/dev.lock.yml @@ -1668,7 +1668,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/developer-docs-consolidator.lock.yml b/.github/workflows/developer-docs-consolidator.lock.yml index 5fe713a6343..8eb02bb37ff 100644 --- a/.github/workflows/developer-docs-consolidator.lock.yml +++ b/.github/workflows/developer-docs-consolidator.lock.yml @@ -1871,7 +1871,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/dictation-prompt.lock.yml b/.github/workflows/dictation-prompt.lock.yml index 59d1f6fcedd..bab30ac2936 100644 --- a/.github/workflows/dictation-prompt.lock.yml +++ b/.github/workflows/dictation-prompt.lock.yml @@ -1608,7 +1608,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/docs-noob-tester.lock.yml b/.github/workflows/docs-noob-tester.lock.yml index 540ecba1720..8291a6f1284 100644 --- a/.github/workflows/docs-noob-tester.lock.yml +++ b/.github/workflows/docs-noob-tester.lock.yml @@ -1587,7 +1587,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/draft-pr-cleanup.lock.yml b/.github/workflows/draft-pr-cleanup.lock.yml index 3369829b71b..1b6d432f468 100644 --- a/.github/workflows/draft-pr-cleanup.lock.yml +++ b/.github/workflows/draft-pr-cleanup.lock.yml @@ -1586,7 +1586,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/duplicate-code-detector.lock.yml b/.github/workflows/duplicate-code-detector.lock.yml index 9f415afc5ab..64fa4597e25 100644 --- a/.github/workflows/duplicate-code-detector.lock.yml +++ b/.github/workflows/duplicate-code-detector.lock.yml @@ -1653,7 +1653,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/eslint-miner.lock.yml b/.github/workflows/eslint-miner.lock.yml index eaef1a227be..08d43240a06 100644 --- a/.github/workflows/eslint-miner.lock.yml +++ b/.github/workflows/eslint-miner.lock.yml @@ -1636,7 +1636,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/eslint-monster.lock.yml b/.github/workflows/eslint-monster.lock.yml index 263b00fe1ce..04ba0af4b23 100644 --- a/.github/workflows/eslint-monster.lock.yml +++ b/.github/workflows/eslint-monster.lock.yml @@ -1646,7 +1646,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/eslint-refiner.lock.yml b/.github/workflows/eslint-refiner.lock.yml index 5f2d9c27392..a0b13e3fbe4 100644 --- a/.github/workflows/eslint-refiner.lock.yml +++ b/.github/workflows/eslint-refiner.lock.yml @@ -1677,7 +1677,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/evoskill-evolver.lock.yml b/.github/workflows/evoskill-evolver.lock.yml index 66bb8ebe3d2..cc50a5731f2 100644 --- a/.github/workflows/evoskill-evolver.lock.yml +++ b/.github/workflows/evoskill-evolver.lock.yml @@ -1651,7 +1651,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/example-failure-category-filter.lock.yml b/.github/workflows/example-failure-category-filter.lock.yml index f005938dce3..3a2ee78537a 100644 --- a/.github/workflows/example-failure-category-filter.lock.yml +++ b/.github/workflows/example-failure-category-filter.lock.yml @@ -1468,7 +1468,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/example-workflow-analyzer.lock.yml b/.github/workflows/example-workflow-analyzer.lock.yml index a4dc2db0b35..d840fac0f74 100644 --- a/.github/workflows/example-workflow-analyzer.lock.yml +++ b/.github/workflows/example-workflow-analyzer.lock.yml @@ -1657,7 +1657,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/firewall-escape.lock.yml b/.github/workflows/firewall-escape.lock.yml index 51c50c747a1..bd1a025f826 100644 --- a/.github/workflows/firewall-escape.lock.yml +++ b/.github/workflows/firewall-escape.lock.yml @@ -1638,7 +1638,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/functional-pragmatist.lock.yml b/.github/workflows/functional-pragmatist.lock.yml index cd5ad60eb46..2432f8c0211 100644 --- a/.github/workflows/functional-pragmatist.lock.yml +++ b/.github/workflows/functional-pragmatist.lock.yml @@ -1622,7 +1622,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/github-mcp-structural-analysis.lock.yml b/.github/workflows/github-mcp-structural-analysis.lock.yml index 56880f605dd..0f5352ceb7e 100644 --- a/.github/workflows/github-mcp-structural-analysis.lock.yml +++ b/.github/workflows/github-mcp-structural-analysis.lock.yml @@ -1961,7 +1961,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/github-mcp-tools-report.lock.yml b/.github/workflows/github-mcp-tools-report.lock.yml index 62283380ff3..1546c3ec78d 100644 --- a/.github/workflows/github-mcp-tools-report.lock.yml +++ b/.github/workflows/github-mcp-tools-report.lock.yml @@ -1742,7 +1742,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/github-remote-mcp-auth-test.lock.yml b/.github/workflows/github-remote-mcp-auth-test.lock.yml index bb5cd0228ec..d130b52ed84 100644 --- a/.github/workflows/github-remote-mcp-auth-test.lock.yml +++ b/.github/workflows/github-remote-mcp-auth-test.lock.yml @@ -1523,7 +1523,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/glossary-maintainer.lock.yml b/.github/workflows/glossary-maintainer.lock.yml index 8a4fb2a7617..47f1b635067 100644 --- a/.github/workflows/glossary-maintainer.lock.yml +++ b/.github/workflows/glossary-maintainer.lock.yml @@ -1818,7 +1818,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/go-fan.lock.yml b/.github/workflows/go-fan.lock.yml index 0eb8dec3969..fb36cacb165 100644 --- a/.github/workflows/go-fan.lock.yml +++ b/.github/workflows/go-fan.lock.yml @@ -1742,7 +1742,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/go-logger.lock.yml b/.github/workflows/go-logger.lock.yml index 1cb9f9a5f3d..38d1f7427df 100644 --- a/.github/workflows/go-logger.lock.yml +++ b/.github/workflows/go-logger.lock.yml @@ -1762,7 +1762,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/go-pattern-detector.lock.yml b/.github/workflows/go-pattern-detector.lock.yml index 79ed463b4f6..8851c04d918 100644 --- a/.github/workflows/go-pattern-detector.lock.yml +++ b/.github/workflows/go-pattern-detector.lock.yml @@ -1649,7 +1649,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/gpclean.lock.yml b/.github/workflows/gpclean.lock.yml index d48aac52c4d..55f591878b2 100644 --- a/.github/workflows/gpclean.lock.yml +++ b/.github/workflows/gpclean.lock.yml @@ -1637,7 +1637,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/grumpy-reviewer.lock.yml b/.github/workflows/grumpy-reviewer.lock.yml index a4f3a58bbd9..d04ce5abca1 100644 --- a/.github/workflows/grumpy-reviewer.lock.yml +++ b/.github/workflows/grumpy-reviewer.lock.yml @@ -1750,7 +1750,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/hourly-ci-cleaner.lock.yml b/.github/workflows/hourly-ci-cleaner.lock.yml index d1606521be5..b4fa4f1999b 100644 --- a/.github/workflows/hourly-ci-cleaner.lock.yml +++ b/.github/workflows/hourly-ci-cleaner.lock.yml @@ -1771,7 +1771,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/impeccable-skills-reviewer.lock.yml b/.github/workflows/impeccable-skills-reviewer.lock.yml index b78038ca9c7..5548803633b 100644 --- a/.github/workflows/impeccable-skills-reviewer.lock.yml +++ b/.github/workflows/impeccable-skills-reviewer.lock.yml @@ -1736,7 +1736,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/instructions-janitor.lock.yml b/.github/workflows/instructions-janitor.lock.yml index c23988d2b21..2dfcd782691 100644 --- a/.github/workflows/instructions-janitor.lock.yml +++ b/.github/workflows/instructions-janitor.lock.yml @@ -1727,7 +1727,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/issue-arborist.lock.yml b/.github/workflows/issue-arborist.lock.yml index e0bb6d63902..35cd79b4e74 100644 --- a/.github/workflows/issue-arborist.lock.yml +++ b/.github/workflows/issue-arborist.lock.yml @@ -1775,7 +1775,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/issue-monster.lock.yml b/.github/workflows/issue-monster.lock.yml index 2cb95f4b6be..fe8d5c25972 100644 --- a/.github/workflows/issue-monster.lock.yml +++ b/.github/workflows/issue-monster.lock.yml @@ -2144,7 +2144,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/issue-triage-agent.lock.yml b/.github/workflows/issue-triage-agent.lock.yml index 02d9b098d7d..ddba7d26797 100644 --- a/.github/workflows/issue-triage-agent.lock.yml +++ b/.github/workflows/issue-triage-agent.lock.yml @@ -1720,7 +1720,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/jsweep.lock.yml b/.github/workflows/jsweep.lock.yml index a0ba40f5c07..dc9309a03c9 100644 --- a/.github/workflows/jsweep.lock.yml +++ b/.github/workflows/jsweep.lock.yml @@ -1648,7 +1648,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/layout-spec-maintainer.lock.yml b/.github/workflows/layout-spec-maintainer.lock.yml index 992ce299976..845f8ef0513 100644 --- a/.github/workflows/layout-spec-maintainer.lock.yml +++ b/.github/workflows/layout-spec-maintainer.lock.yml @@ -1659,7 +1659,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/lint-monster.lock.yml b/.github/workflows/lint-monster.lock.yml index 51d37e20b94..d74071b0404 100644 --- a/.github/workflows/lint-monster.lock.yml +++ b/.github/workflows/lint-monster.lock.yml @@ -1627,7 +1627,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/linter-miner.lock.yml b/.github/workflows/linter-miner.lock.yml index b20fd91c35c..6cc02345491 100644 --- a/.github/workflows/linter-miner.lock.yml +++ b/.github/workflows/linter-miner.lock.yml @@ -1742,7 +1742,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/lockfile-stats.lock.yml b/.github/workflows/lockfile-stats.lock.yml index 6975a2ea982..139ab0a7ec6 100644 --- a/.github/workflows/lockfile-stats.lock.yml +++ b/.github/workflows/lockfile-stats.lock.yml @@ -1613,7 +1613,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/mattpocock-skills-reviewer.lock.yml b/.github/workflows/mattpocock-skills-reviewer.lock.yml index 05209893253..0d5e7dfa2f0 100644 --- a/.github/workflows/mattpocock-skills-reviewer.lock.yml +++ b/.github/workflows/mattpocock-skills-reviewer.lock.yml @@ -1862,7 +1862,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/mcp-inspector.lock.yml b/.github/workflows/mcp-inspector.lock.yml index 9d60d0f64de..793cb8996bb 100644 --- a/.github/workflows/mcp-inspector.lock.yml +++ b/.github/workflows/mcp-inspector.lock.yml @@ -1891,7 +1891,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/mergefest.lock.yml b/.github/workflows/mergefest.lock.yml index 8240f8c03dd..d1ea12b3010 100644 --- a/.github/workflows/mergefest.lock.yml +++ b/.github/workflows/mergefest.lock.yml @@ -1632,7 +1632,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/metrics-collector.lock.yml b/.github/workflows/metrics-collector.lock.yml index c2f3007d00a..4904cbf2958 100644 --- a/.github/workflows/metrics-collector.lock.yml +++ b/.github/workflows/metrics-collector.lock.yml @@ -1683,7 +1683,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/necromancer.lock.yml b/.github/workflows/necromancer.lock.yml index fbf6849eab6..2710e578bbc 100644 --- a/.github/workflows/necromancer.lock.yml +++ b/.github/workflows/necromancer.lock.yml @@ -1719,7 +1719,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/objective-impact-report.lock.yml b/.github/workflows/objective-impact-report.lock.yml index 98ae30c92dc..ab89f5b543b 100644 --- a/.github/workflows/objective-impact-report.lock.yml +++ b/.github/workflows/objective-impact-report.lock.yml @@ -1570,7 +1570,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/org-health-report.lock.yml b/.github/workflows/org-health-report.lock.yml index 8b6386721e4..7340d86478c 100644 --- a/.github/workflows/org-health-report.lock.yml +++ b/.github/workflows/org-health-report.lock.yml @@ -1656,7 +1656,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/outcome-collector.lock.yml b/.github/workflows/outcome-collector.lock.yml index 4ff47eb17d5..d1e2e2e34fd 100644 --- a/.github/workflows/outcome-collector.lock.yml +++ b/.github/workflows/outcome-collector.lock.yml @@ -1627,7 +1627,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pdf-summary.lock.yml b/.github/workflows/pdf-summary.lock.yml index 8646104dcf1..03e47aa7055 100644 --- a/.github/workflows/pdf-summary.lock.yml +++ b/.github/workflows/pdf-summary.lock.yml @@ -1767,7 +1767,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/plan.lock.yml b/.github/workflows/plan.lock.yml index 125d62eedf2..c71b3c41e49 100644 --- a/.github/workflows/plan.lock.yml +++ b/.github/workflows/plan.lock.yml @@ -1735,7 +1735,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/poem-bot.lock.yml b/.github/workflows/poem-bot.lock.yml index f0b100bc784..d558cc38751 100644 --- a/.github/workflows/poem-bot.lock.yml +++ b/.github/workflows/poem-bot.lock.yml @@ -1991,7 +1991,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ponytail-reviewer.lock.yml b/.github/workflows/ponytail-reviewer.lock.yml index 0aabccbd033..6e36ada3b8b 100644 --- a/.github/workflows/ponytail-reviewer.lock.yml +++ b/.github/workflows/ponytail-reviewer.lock.yml @@ -1813,7 +1813,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/portfolio-analyst.lock.yml b/.github/workflows/portfolio-analyst.lock.yml index a4d020ec916..bd5252d795d 100644 --- a/.github/workflows/portfolio-analyst.lock.yml +++ b/.github/workflows/portfolio-analyst.lock.yml @@ -1763,7 +1763,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-code-quality-reviewer.lock.yml b/.github/workflows/pr-code-quality-reviewer.lock.yml index 92add1464b7..1b7039471d9 100644 --- a/.github/workflows/pr-code-quality-reviewer.lock.yml +++ b/.github/workflows/pr-code-quality-reviewer.lock.yml @@ -1718,7 +1718,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-description-caveman.lock.yml b/.github/workflows/pr-description-caveman.lock.yml index faa655a1c4b..749e5278bb1 100644 --- a/.github/workflows/pr-description-caveman.lock.yml +++ b/.github/workflows/pr-description-caveman.lock.yml @@ -1541,7 +1541,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-nitpick-reviewer.lock.yml b/.github/workflows/pr-nitpick-reviewer.lock.yml index 0632121a6f1..4209bc6a744 100644 --- a/.github/workflows/pr-nitpick-reviewer.lock.yml +++ b/.github/workflows/pr-nitpick-reviewer.lock.yml @@ -1730,7 +1730,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-sous-chef.lock.yml b/.github/workflows/pr-sous-chef.lock.yml index 09a9499fd9d..eaf40ff061b 100644 --- a/.github/workflows/pr-sous-chef.lock.yml +++ b/.github/workflows/pr-sous-chef.lock.yml @@ -2039,7 +2039,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/pr-triage-agent.lock.yml b/.github/workflows/pr-triage-agent.lock.yml index 8f8f1fb762f..9333b9b741c 100644 --- a/.github/workflows/pr-triage-agent.lock.yml +++ b/.github/workflows/pr-triage-agent.lock.yml @@ -2036,7 +2036,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/prompt-clustering-analysis.lock.yml b/.github/workflows/prompt-clustering-analysis.lock.yml index 0824f3697e5..792476a749f 100644 --- a/.github/workflows/prompt-clustering-analysis.lock.yml +++ b/.github/workflows/prompt-clustering-analysis.lock.yml @@ -1770,7 +1770,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/purelock.lock.yml b/.github/workflows/purelock.lock.yml index b8dbe0d0271..7d7affd995f 100644 --- a/.github/workflows/purelock.lock.yml +++ b/.github/workflows/purelock.lock.yml @@ -1785,7 +1785,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/python-data-charts.lock.yml b/.github/workflows/python-data-charts.lock.yml index f92a9dab3af..8417f4004c1 100644 --- a/.github/workflows/python-data-charts.lock.yml +++ b/.github/workflows/python-data-charts.lock.yml @@ -1772,7 +1772,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/q.lock.yml b/.github/workflows/q.lock.yml index e449a15d26e..e824866e3a0 100644 --- a/.github/workflows/q.lock.yml +++ b/.github/workflows/q.lock.yml @@ -1857,7 +1857,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/refactoring-cadence.lock.yml b/.github/workflows/refactoring-cadence.lock.yml index 9456e66f5a5..2d58f1bf09e 100644 --- a/.github/workflows/refactoring-cadence.lock.yml +++ b/.github/workflows/refactoring-cadence.lock.yml @@ -1618,7 +1618,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/refiner.lock.yml b/.github/workflows/refiner.lock.yml index 3c3d2784817..2a0088b301e 100644 --- a/.github/workflows/refiner.lock.yml +++ b/.github/workflows/refiner.lock.yml @@ -1859,7 +1859,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/repo-audit-analyzer.lock.yml b/.github/workflows/repo-audit-analyzer.lock.yml index 092b2db9c46..4f4a3b984c3 100644 --- a/.github/workflows/repo-audit-analyzer.lock.yml +++ b/.github/workflows/repo-audit-analyzer.lock.yml @@ -1578,7 +1578,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/repo-tree-map.lock.yml b/.github/workflows/repo-tree-map.lock.yml index bcae4fafe4a..2b4f23b6d09 100644 --- a/.github/workflows/repo-tree-map.lock.yml +++ b/.github/workflows/repo-tree-map.lock.yml @@ -1567,7 +1567,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/repository-quality-improver.lock.yml b/.github/workflows/repository-quality-improver.lock.yml index 639557ef116..90cc6db4697 100644 --- a/.github/workflows/repository-quality-improver.lock.yml +++ b/.github/workflows/repository-quality-improver.lock.yml @@ -1564,7 +1564,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/research.lock.yml b/.github/workflows/research.lock.yml index 42a89a7dbc1..43729bbfb07 100644 --- a/.github/workflows/research.lock.yml +++ b/.github/workflows/research.lock.yml @@ -1621,7 +1621,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ruflo-backed-task.lock.yml b/.github/workflows/ruflo-backed-task.lock.yml index b49600e17a3..161f0998c47 100644 --- a/.github/workflows/ruflo-backed-task.lock.yml +++ b/.github/workflows/ruflo-backed-task.lock.yml @@ -1823,7 +1823,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/safe-output-health.lock.yml b/.github/workflows/safe-output-health.lock.yml index 4525c1c949f..a8b151e3964 100644 --- a/.github/workflows/safe-output-health.lock.yml +++ b/.github/workflows/safe-output-health.lock.yml @@ -1718,7 +1718,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/schema-consistency-checker.lock.yml b/.github/workflows/schema-consistency-checker.lock.yml index 14164e187e4..348a023dbfb 100644 --- a/.github/workflows/schema-consistency-checker.lock.yml +++ b/.github/workflows/schema-consistency-checker.lock.yml @@ -1532,7 +1532,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/schema-feature-coverage.lock.yml b/.github/workflows/schema-feature-coverage.lock.yml index f85982debdd..fc86dfb6730 100644 --- a/.github/workflows/schema-feature-coverage.lock.yml +++ b/.github/workflows/schema-feature-coverage.lock.yml @@ -1608,7 +1608,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/scout.lock.yml b/.github/workflows/scout.lock.yml index 74583b6cc5e..c1a8b4a55dd 100644 --- a/.github/workflows/scout.lock.yml +++ b/.github/workflows/scout.lock.yml @@ -1842,7 +1842,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/security-compliance.lock.yml b/.github/workflows/security-compliance.lock.yml index 0fb4fb97183..2ce6abf3603 100644 --- a/.github/workflows/security-compliance.lock.yml +++ b/.github/workflows/security-compliance.lock.yml @@ -1581,7 +1581,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/security-review.lock.yml b/.github/workflows/security-review.lock.yml index 395dd07a7df..7fb8d00f17f 100644 --- a/.github/workflows/security-review.lock.yml +++ b/.github/workflows/security-review.lock.yml @@ -1973,7 +1973,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/semantic-function-refactor.lock.yml b/.github/workflows/semantic-function-refactor.lock.yml index 0e5de1dfce3..33c5fa716d0 100644 --- a/.github/workflows/semantic-function-refactor.lock.yml +++ b/.github/workflows/semantic-function-refactor.lock.yml @@ -1682,7 +1682,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/sergo.lock.yml b/.github/workflows/sergo.lock.yml index 5405b49dd0c..340520d9a19 100644 --- a/.github/workflows/sergo.lock.yml +++ b/.github/workflows/sergo.lock.yml @@ -1718,7 +1718,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/sighthound-security-scan.lock.yml b/.github/workflows/sighthound-security-scan.lock.yml index bd6856b82b1..e75fba34d01 100644 --- a/.github/workflows/sighthound-security-scan.lock.yml +++ b/.github/workflows/sighthound-security-scan.lock.yml @@ -1488,7 +1488,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/skillet.lock.yml b/.github/workflows/skillet.lock.yml index f8d5e7aba2b..798e529be62 100644 --- a/.github/workflows/skillet.lock.yml +++ b/.github/workflows/skillet.lock.yml @@ -1753,7 +1753,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/slide-deck-maintainer.lock.yml b/.github/workflows/slide-deck-maintainer.lock.yml index 259797cf553..bf6075f1646 100644 --- a/.github/workflows/slide-deck-maintainer.lock.yml +++ b/.github/workflows/slide-deck-maintainer.lock.yml @@ -1764,7 +1764,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/smoke-claude-on-copilot.lock.yml b/.github/workflows/smoke-claude-on-copilot.lock.yml index bb30a3953a0..e16302ea92e 100644 --- a/.github/workflows/smoke-claude-on-copilot.lock.yml +++ b/.github/workflows/smoke-claude-on-copilot.lock.yml @@ -1603,7 +1603,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/smoke-gemini.lock.yml b/.github/workflows/smoke-gemini.lock.yml index 60827b750bb..128f73e4ef1 100644 --- a/.github/workflows/smoke-gemini.lock.yml +++ b/.github/workflows/smoke-gemini.lock.yml @@ -1806,7 +1806,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/smoke-github-claude.lock.yml b/.github/workflows/smoke-github-claude.lock.yml index b766ce80f30..f9a3949058c 100644 --- a/.github/workflows/smoke-github-claude.lock.yml +++ b/.github/workflows/smoke-github-claude.lock.yml @@ -1603,7 +1603,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/spec-enforcer.lock.yml b/.github/workflows/spec-enforcer.lock.yml index 47c83305cf5..6ca4ee76570 100644 --- a/.github/workflows/spec-enforcer.lock.yml +++ b/.github/workflows/spec-enforcer.lock.yml @@ -1651,7 +1651,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/spec-extractor.lock.yml b/.github/workflows/spec-extractor.lock.yml index d6881d1641c..135f8435287 100644 --- a/.github/workflows/spec-extractor.lock.yml +++ b/.github/workflows/spec-extractor.lock.yml @@ -1735,7 +1735,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/spec-librarian.lock.yml b/.github/workflows/spec-librarian.lock.yml index 30e3919cd08..ef16074ce0a 100644 --- a/.github/workflows/spec-librarian.lock.yml +++ b/.github/workflows/spec-librarian.lock.yml @@ -1618,7 +1618,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/squad-game-planner.lock.yml b/.github/workflows/squad-game-planner.lock.yml index 8476d64059d..2bfab4bfc3b 100644 --- a/.github/workflows/squad-game-planner.lock.yml +++ b/.github/workflows/squad-game-planner.lock.yml @@ -1538,7 +1538,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/squad-implement-worker.lock.yml b/.github/workflows/squad-implement-worker.lock.yml index e56e723747d..6b7b3762597 100644 --- a/.github/workflows/squad-implement-worker.lock.yml +++ b/.github/workflows/squad-implement-worker.lock.yml @@ -1702,7 +1702,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/squad-plan.lock.yml b/.github/workflows/squad-plan.lock.yml index d43981a6880..8667c136333 100644 --- a/.github/workflows/squad-plan.lock.yml +++ b/.github/workflows/squad-plan.lock.yml @@ -1618,7 +1618,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/squad.lock.yml b/.github/workflows/squad.lock.yml index 966ae0c763c..6d241302d77 100644 --- a/.github/workflows/squad.lock.yml +++ b/.github/workflows/squad.lock.yml @@ -2261,7 +2261,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/stale-pr-cleanup.lock.yml b/.github/workflows/stale-pr-cleanup.lock.yml index 6467d027ed2..0ba5ce22ff5 100644 --- a/.github/workflows/stale-pr-cleanup.lock.yml +++ b/.github/workflows/stale-pr-cleanup.lock.yml @@ -1581,7 +1581,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/stale-repo-identifier.lock.yml b/.github/workflows/stale-repo-identifier.lock.yml index 09071ad0d5d..53f08c0974a 100644 --- a/.github/workflows/stale-repo-identifier.lock.yml +++ b/.github/workflows/stale-repo-identifier.lock.yml @@ -1883,7 +1883,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/static-analysis-report.lock.yml b/.github/workflows/static-analysis-report.lock.yml index 019798dc3b2..17b87ccf8cc 100644 --- a/.github/workflows/static-analysis-report.lock.yml +++ b/.github/workflows/static-analysis-report.lock.yml @@ -1745,7 +1745,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/step-name-alignment.lock.yml b/.github/workflows/step-name-alignment.lock.yml index 621b8c694a6..3461d6f0ee4 100644 --- a/.github/workflows/step-name-alignment.lock.yml +++ b/.github/workflows/step-name-alignment.lock.yml @@ -1636,7 +1636,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/sub-issue-closer.lock.yml b/.github/workflows/sub-issue-closer.lock.yml index 489564283ce..31c7a701d3b 100644 --- a/.github/workflows/sub-issue-closer.lock.yml +++ b/.github/workflows/sub-issue-closer.lock.yml @@ -1671,7 +1671,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/super-linter.lock.yml b/.github/workflows/super-linter.lock.yml index bd70230e59a..21bd49bc64b 100644 --- a/.github/workflows/super-linter.lock.yml +++ b/.github/workflows/super-linter.lock.yml @@ -1640,7 +1640,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/technical-doc-writer.lock.yml b/.github/workflows/technical-doc-writer.lock.yml index 2f493b850f5..cda3d5543ac 100644 --- a/.github/workflows/technical-doc-writer.lock.yml +++ b/.github/workflows/technical-doc-writer.lock.yml @@ -1817,7 +1817,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/terminal-stylist.lock.yml b/.github/workflows/terminal-stylist.lock.yml index 02962351075..c43b4ebb547 100644 --- a/.github/workflows/terminal-stylist.lock.yml +++ b/.github/workflows/terminal-stylist.lock.yml @@ -1616,7 +1616,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/test-quality-sentinel.lock.yml b/.github/workflows/test-quality-sentinel.lock.yml index 6de61430240..203950198c8 100644 --- a/.github/workflows/test-quality-sentinel.lock.yml +++ b/.github/workflows/test-quality-sentinel.lock.yml @@ -1738,7 +1738,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/tidy.lock.yml b/.github/workflows/tidy.lock.yml index d5b90df805b..d87d9a1aca9 100644 --- a/.github/workflows/tidy.lock.yml +++ b/.github/workflows/tidy.lock.yml @@ -1764,7 +1764,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/typist.lock.yml b/.github/workflows/typist.lock.yml index a1c1b0f567d..3198d53debd 100644 --- a/.github/workflows/typist.lock.yml +++ b/.github/workflows/typist.lock.yml @@ -1726,7 +1726,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/ubuntu-image-analyzer.lock.yml b/.github/workflows/ubuntu-image-analyzer.lock.yml index e65dae59944..3efd9c6c9ac 100644 --- a/.github/workflows/ubuntu-image-analyzer.lock.yml +++ b/.github/workflows/ubuntu-image-analyzer.lock.yml @@ -1644,7 +1644,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/uk-ai-operational-resilience.lock.yml b/.github/workflows/uk-ai-operational-resilience.lock.yml index 77c4df46946..38f1fae9ad5 100644 --- a/.github/workflows/uk-ai-operational-resilience.lock.yml +++ b/.github/workflows/uk-ai-operational-resilience.lock.yml @@ -1588,7 +1588,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/unbloat-docs.lock.yml b/.github/workflows/unbloat-docs.lock.yml index 3a64059f102..5ba2dd45a0d 100644 --- a/.github/workflows/unbloat-docs.lock.yml +++ b/.github/workflows/unbloat-docs.lock.yml @@ -1743,7 +1743,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/update-astro.lock.yml b/.github/workflows/update-astro.lock.yml index ee44ea7fca5..332e413327e 100644 --- a/.github/workflows/update-astro.lock.yml +++ b/.github/workflows/update-astro.lock.yml @@ -1673,7 +1673,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/video-analyzer.lock.yml b/.github/workflows/video-analyzer.lock.yml index 44f89cc3b24..2f9b5b8fd94 100644 --- a/.github/workflows/video-analyzer.lock.yml +++ b/.github/workflows/video-analyzer.lock.yml @@ -1588,7 +1588,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/visual-regression-checker.lock.yml b/.github/workflows/visual-regression-checker.lock.yml index ebb0cde02c7..d129be297e3 100644 --- a/.github/workflows/visual-regression-checker.lock.yml +++ b/.github/workflows/visual-regression-checker.lock.yml @@ -1595,7 +1595,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/weekly-blog-post-writer.lock.yml b/.github/workflows/weekly-blog-post-writer.lock.yml index a7f75ee51b1..d0f22758222 100644 --- a/.github/workflows/weekly-blog-post-writer.lock.yml +++ b/.github/workflows/weekly-blog-post-writer.lock.yml @@ -1850,7 +1850,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/weekly-editors-health-check.lock.yml b/.github/workflows/weekly-editors-health-check.lock.yml index 3452e561e52..8ceb30a1d54 100644 --- a/.github/workflows/weekly-editors-health-check.lock.yml +++ b/.github/workflows/weekly-editors-health-check.lock.yml @@ -1675,7 +1675,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/weekly-issue-summary.lock.yml b/.github/workflows/weekly-issue-summary.lock.yml index 980ac63cdaa..9b65940f61a 100644 --- a/.github/workflows/weekly-issue-summary.lock.yml +++ b/.github/workflows/weekly-issue-summary.lock.yml @@ -1655,7 +1655,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/weekly-network-domains-audit.lock.yml b/.github/workflows/weekly-network-domains-audit.lock.yml index 7b3b31cf252..3557f4067d6 100644 --- a/.github/workflows/weekly-network-domains-audit.lock.yml +++ b/.github/workflows/weekly-network-domains-audit.lock.yml @@ -1571,7 +1571,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml index d36abc5f529..75c4d7f25b1 100644 --- a/.github/workflows/weekly-safe-outputs-spec-review.lock.yml +++ b/.github/workflows/weekly-safe-outputs-spec-review.lock.yml @@ -1663,7 +1663,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/workflow-generator.lock.yml b/.github/workflows/workflow-generator.lock.yml index 17f35d868a6..18a6d354b0d 100644 --- a/.github/workflows/workflow-generator.lock.yml +++ b/.github/workflows/workflow-generator.lock.yml @@ -1627,7 +1627,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/workflow-health-manager.lock.yml b/.github/workflows/workflow-health-manager.lock.yml index 3b62c91f65c..c8fe41a9545 100644 --- a/.github/workflows/workflow-health-manager.lock.yml +++ b/.github/workflows/workflow-health-manager.lock.yml @@ -1668,7 +1668,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/workflow-normalizer.lock.yml b/.github/workflows/workflow-normalizer.lock.yml index 1ca2dea6ffb..8abc998e1aa 100644 --- a/.github/workflows/workflow-normalizer.lock.yml +++ b/.github/workflows/workflow-normalizer.lock.yml @@ -1646,7 +1646,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/.github/workflows/workflow-skill-extractor.lock.yml b/.github/workflows/workflow-skill-extractor.lock.yml index 8c57fabec33..e8052be3a76 100644 --- a/.github/workflows/workflow-skill-extractor.lock.yml +++ b/.github/workflows/workflow-skill-extractor.lock.yml @@ -1572,7 +1572,7 @@ jobs: if: always() && steps.detection_guard.outputs.run_detection == 'true' continue-on-error: true run: | - bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.11 + bash "${RUNNER_TEMP}/gh-aw/actions/install_threat_detect_binary.sh" v0.4.12 - name: Execute threat detection with AWF id: detection_agentic_execution if: always() && steps.detection_guard.outputs.run_detection == 'true' diff --git a/docs/adr/55532-expose-threat-detect-per-attempt-controls-via-frontmatter.md b/docs/adr/55532-expose-threat-detect-per-attempt-controls-via-frontmatter.md new file mode 100644 index 00000000000..4f8900342a3 --- /dev/null +++ b/docs/adr/55532-expose-threat-detect-per-attempt-controls-via-frontmatter.md @@ -0,0 +1,42 @@ +# ADR-55532: Expose Threat-Detect Per-Attempt Controls via Frontmatter + +**Date**: 2026-08-24 +**Status**: Accepted +**Deciders**: gh-aw maintainers + +--- + +### Context + +`gh-aw-threat-detection` added per-attempt controls (`--engine-timeout`, `--max-turns`, `--retries`) to the `threat-detect` binary to let callers cap AI resource usage and retry behavior on each invocation. However, `gh-aw` had no mechanism to pass these controls per workflow — all compiled workflows invoked `threat-detect` with its binary compiled-in defaults and no override path. Workflow authors running cost- or time-sensitive security scans could not constrain the detector without patching the upstream binary. This PR closes that gap by surfacing the three flags in the `safe-outputs.threat-detection` frontmatter block and forwarding them to `threat-detect` only when explicitly configured. + +### Decision + +We will add three optional fields — `engine-timeout` (Go duration string or `0`), `max-turns` (non-negative integer), and `retries` (non-negative integer) — to the `safe-outputs.threat-detection` frontmatter section. When a field is set, the corresponding CLI flag is appended to the `threat-detect` invocation. When a field is absent, no flag is emitted and `threat-detect` applies its own compiled-in default. Schema-level validation rejects invalid values at compile time so errors surface before CI starts. + +### Alternatives Considered + +#### Alternative 1: Environment Variables + +Pass per-workflow overrides via environment variables (e.g., `GH_AW_ENGINE_TIMEOUT`, extending the existing `GH_AW_MAX_TURNS` pattern). Environment variables are already used for some `threat-detect` settings. This approach was not chosen because env vars are process-wide and bleed across concurrent jobs or child processes running in the same environment; they cannot be scoped to a single `threat-detect` invocation without additional shell gymnastics. CLI flags are explicit, per-invocation, and composable, making the intent and scope unambiguous. + +#### Alternative 2: Global Workflow-Level Frontmatter Controls + +Expose `engine-timeout`, `max-turns`, and `retries` at the top-level workflow frontmatter rather than scoped under `safe-outputs.threat-detection`. This was considered to keep the API surface flat. It was not chosen because these controls are threat-detector-specific operational parameters, not workflow-wide settings. Placing them under `threat-detection` config preserves clear semantic ownership, avoids any risk of the values being misapplied to other engines or compile steps, and keeps the footprint of the change minimal. + +### Consequences + +#### Positive +- Workflow authors can cap threat-detection engine runtime, AI turn count, and retry attempts on a per-workflow basis, enabling cost and time governance without upstream changes. +- Threat-detect compiled-in defaults remain unchanged for all existing workflows: fields omitted from frontmatter produce no flag emission, so backward compatibility is guaranteed. +- Schema validation at compile time means invalid values (negative integers, malformed duration strings) are caught before any CI runner is allocated. + +#### Negative +- Three new schema fields increase the surface area of the workflow specification that must be kept in sync with `threat-detect`'s CLI interface over time. +- YAML's flexible type system (integers, strings, floats can all represent the value `0`) required a defensive multi-case parser (`parseThreatDetectionEngineTimeout`), adding implementation complexity and maintenance burden. + +#### Neutral +- The `buildThreatDetectCommand` helper function extracted from the inline `fmt.Sprintf` call improves testability of command construction but is an internal package change with no external API impact. +- The PR references `GH_AW_MAX_TURNS` as a fallback in `threat-detect`; this ADR does not address whether the env-var fallback should eventually be deprecated in favour of the new frontmatter field. + +--- diff --git a/pkg/constants/version_constants.go b/pkg/constants/version_constants.go index 6ac44ff3ee3..23b544e4431 100644 --- a/pkg/constants/version_constants.go +++ b/pkg/constants/version_constants.go @@ -208,7 +208,7 @@ const DefaultGitHubScriptVersion Version = "v9" // This is used by the default external threat-detection path and when // `features: gh-aw-detection: true` is set in the workflow frontmatter, enabling the external // threat-detect binary path instead of the inline engine execution path. -const DefaultThreatDetectVersion Version = "v0.4.11" +const DefaultThreatDetectVersion Version = "v0.4.12" // GhSkillsMinVersion is the minimum gh CLI version required for frontmatter skill support // (installing gh extensions via `gh extension install`). Workflows that install frontmatter diff --git a/pkg/parser/schemas/main_workflow_schema.json b/pkg/parser/schemas/main_workflow_schema.json index a1af5a68e6a..9920e820101 100644 --- a/pkg/parser/schemas/main_workflow_schema.json +++ b/pkg/parser/schemas/main_workflow_schema.json @@ -11325,6 +11325,29 @@ "type": "string", "description": "Model override for threat detection engine execution." }, + "engine-timeout": { + "oneOf": [ + { + "type": "string", + "pattern": "^(0|([0-9]+(\\.[0-9]+)?(ns|us|µs|ms|s|m|h))+)$" + }, + { + "type": "integer", + "const": 0 + } + ], + "description": "Per-attempt timeout for threat detection engine execution as a Go duration (for example '90s', '10m', '1h30m'). Set to 0 to disable timeout enforcement in threat-detect." + }, + "max-turns": { + "type": "integer", + "minimum": 0, + "description": "Detector-only per-attempt max-turns override passed to threat-detect. When omitted, threat-detect falls back to GH_AW_MAX_TURNS (if set) and then to its own built-in default." + }, + "retries": { + "type": "integer", + "minimum": 0, + "description": "Detector-only retry count passed to threat-detect for clean exits without a verdict." + }, "steps": { "type": "array", "description": "Array of extra job steps to run before engine execution", diff --git a/pkg/workflow/threat_detection_config.go b/pkg/workflow/threat_detection_config.go index 05c15f1afcb..25d0e9a1698 100644 --- a/pkg/workflow/threat_detection_config.go +++ b/pkg/workflow/threat_detection_config.go @@ -1,13 +1,19 @@ // Package workflow - data model and config parsing for threat detection. package workflow -import "strings" +import ( + "strconv" + "strings" +) // ThreatDetectionConfig holds configuration for threat detection in agent output type ThreatDetectionConfig struct { Prompt string `yaml:"prompt,omitempty"` // Additional custom prompt instructions to append Steps []any `yaml:"steps,omitempty"` // Array of extra job steps to run before engine execution PostSteps []any `yaml:"post-steps,omitempty"` // Array of extra job steps to run after engine execution + EngineTimeout *string `yaml:"engine-timeout,omitempty"` // Per-attempt wall-clock timeout passed to threat-detect (--engine-timeout) + MaxTurns *int `yaml:"max-turns,omitempty"` // Detector-only max turns override passed to threat-detect (--max-turns) + Retries *int `yaml:"retries,omitempty"` // Detector-only retries override passed to threat-detect (--retries) MaxAICredits int64 `yaml:"max-ai-credits,omitempty"` // Maximum AI credits budget for threat-detection engine execution Model string `yaml:"model,omitempty"` // Model override for threat detection engine execution EngineConfig *EngineConfig `yaml:"engine-config,omitempty"` // Extended engine configuration for threat detection @@ -138,6 +144,27 @@ func (c *Compiler) parseThreatDetectionObjectConfig(configMap map[string]any) *T threatConfig.MaxAICredits = parseMaxAICreditsValue(maxAICredits) } + // Parse engine-timeout field + if rawEngineTimeout, exists := configMap["engine-timeout"]; exists { + if parsedEngineTimeout := parseThreatDetectionEngineTimeout(rawEngineTimeout); parsedEngineTimeout != nil { + threatConfig.EngineTimeout = parsedEngineTimeout + } + } + + // Parse max-turns field + if rawMaxTurns, exists := configMap["max-turns"]; exists { + if parsedMaxTurns := parseThreatDetectionNonNegativeInt(rawMaxTurns); parsedMaxTurns != nil { + threatConfig.MaxTurns = parsedMaxTurns + } + } + + // Parse retries field + if rawRetries, exists := configMap["retries"]; exists { + if parsedRetries := parseThreatDetectionNonNegativeInt(rawRetries); parsedRetries != nil { + threatConfig.Retries = parsedRetries + } + } + // Parse runs-on field if runOn, exists := configMap["runs-on"]; exists { threatConfig.RunsOn = renderRunsOnSnippet(runOn) @@ -195,3 +222,87 @@ func extractRawExpression(expr string) string { s = strings.TrimSuffix(s, "}}") return strings.TrimSpace(s) } + +func parseThreatDetectionEngineTimeout(raw any) *string { + switch v := raw.(type) { + case string: + trimmed := strings.TrimSpace(v) + if trimmed == "" { + return nil + } + return &trimmed + case int: + if v != 0 { + threatLog.Printf("Ignoring invalid numeric threat-detection.engine-timeout value %d; use a Go duration string such as '10m' or 0", v) + return nil + } + zero := "0" + return &zero + case int64: + if v != 0 { + threatLog.Printf("Ignoring invalid numeric threat-detection.engine-timeout value %d; use a Go duration string such as '10m' or 0", v) + return nil + } + zero := "0" + return &zero + case uint64: + if v != 0 { + threatLog.Printf("Ignoring invalid numeric threat-detection.engine-timeout value %d; use a Go duration string such as '10m' or 0", v) + return nil + } + zero := "0" + return &zero + case float64: + if v != 0 { + threatLog.Printf("Ignoring invalid numeric threat-detection.engine-timeout value %v; use a Go duration string such as '10m' or 0", v) + return nil + } + zero := "0" + return &zero + default: + return nil + } +} + +func parseThreatDetectionNonNegativeInt(raw any) *int { + switch v := raw.(type) { + case int: + if v < 0 { + return nil + } + value := v + return &value + case int64: + if v < 0 { + return nil + } + value := int(v) + return &value + case uint64: + // Guard conversion on 32-bit platforms where int max is smaller than uint64. + if v > uint64(^uint(0)>>1) { + return nil + } + value := int(v) + return &value + case float64: + if v < 0 || v != float64(int(v)) { + return nil + } + value := int(v) + return &value + case string: + trimmed := strings.TrimSpace(v) + if trimmed == "" { + return nil + } + parsed, err := strconv.Atoi(trimmed) + if err != nil || parsed < 0 { + return nil + } + value := parsed + return &value + default: + return nil + } +} diff --git a/pkg/workflow/threat_detection_config_test.go b/pkg/workflow/threat_detection_config_test.go index 62352b7eb1a..2d4c0b8eef0 100644 --- a/pkg/workflow/threat_detection_config_test.go +++ b/pkg/workflow/threat_detection_config_test.go @@ -3,8 +3,12 @@ package workflow import ( + "os" + "path/filepath" "strings" "testing" + + "github.com/github/gh-aw/pkg/testutil" ) func TestParseThreatDetectionConfig(t *testing.T) { @@ -53,6 +57,48 @@ func TestParseThreatDetectionConfig(t *testing.T) { expectedConfig: nil, }, + { + name: "object with detector kill switch overrides", + outputMap: map[string]any{ + "threat-detection": map[string]any{ + "engine-timeout": "10m", + "max-turns": 100, + "retries": 1, + }, + }, + expectedConfig: &ThreatDetectionConfig{ + EngineTimeout: strPtr("10m"), + MaxTurns: func() *int { + v := 100 + return &v + }(), + Retries: func() *int { + v := 1 + return &v + }(), + }, + }, + { + name: "object with detector kill switch overrides parsed from uint64", + outputMap: map[string]any{ + "threat-detection": map[string]any{ + "engine-timeout": uint64(0), + "max-turns": uint64(100), + "retries": uint64(1), + }, + }, + expectedConfig: &ThreatDetectionConfig{ + EngineTimeout: strPtr("0"), + MaxTurns: func() *int { + v := 100 + return &v + }(), + Retries: func() *int { + v := 1 + return &v + }(), + }, + }, { name: "object with custom steps", outputMap: map[string]any{ @@ -256,6 +302,21 @@ func TestParseThreatDetectionConfig(t *testing.T) { if result.MaxAICredits != tt.expectedConfig.MaxAICredits { t.Errorf("Expected MaxAICredits %d, got %d", tt.expectedConfig.MaxAICredits, result.MaxAICredits) } + if (result.EngineTimeout == nil) != (tt.expectedConfig.EngineTimeout == nil) { + t.Errorf("Expected EngineTimeout nil=%v, got nil=%v", tt.expectedConfig.EngineTimeout == nil, result.EngineTimeout == nil) + } else if result.EngineTimeout != nil && tt.expectedConfig.EngineTimeout != nil && *result.EngineTimeout != *tt.expectedConfig.EngineTimeout { + t.Errorf("Expected EngineTimeout %q, got %q", *tt.expectedConfig.EngineTimeout, *result.EngineTimeout) + } + if (result.MaxTurns == nil) != (tt.expectedConfig.MaxTurns == nil) { + t.Errorf("Expected MaxTurns nil=%v, got nil=%v", tt.expectedConfig.MaxTurns == nil, result.MaxTurns == nil) + } else if result.MaxTurns != nil && tt.expectedConfig.MaxTurns != nil && *result.MaxTurns != *tt.expectedConfig.MaxTurns { + t.Errorf("Expected MaxTurns %d, got %d", *tt.expectedConfig.MaxTurns, *result.MaxTurns) + } + if (result.Retries == nil) != (tt.expectedConfig.Retries == nil) { + t.Errorf("Expected Retries nil=%v, got nil=%v", tt.expectedConfig.Retries == nil, result.Retries == nil) + } else if result.Retries != nil && tt.expectedConfig.Retries != nil && *result.Retries != *tt.expectedConfig.Retries { + t.Errorf("Expected Retries %d, got %d", *tt.expectedConfig.Retries, *result.Retries) + } if (result.ContinueOnError == nil) != (tt.expectedConfig.ContinueOnError == nil) { t.Errorf("Expected ContinueOnError nil=%v, got nil=%v", tt.expectedConfig.ContinueOnError == nil, result.ContinueOnError == nil) @@ -342,6 +403,77 @@ func TestThreatDetectionExplicitDisable(t *testing.T) { } } +func TestThreatDetectionKillSwitchValidation(t *testing.T) { + tests := []struct { + name string + config string + expectError bool + }{ + { + name: "valid kill switch values", + config: `engine-timeout: 10m + max-turns: 100 + retries: 1`, + expectError: false, + }, + { + name: "engine-timeout zero is valid", + config: `engine-timeout: 0`, + expectError: false, + }, + { + name: "reject negative engine-timeout", + config: `engine-timeout: -1s`, + expectError: true, + }, + { + name: "reject negative max-turns", + config: `max-turns: -1`, + expectError: true, + }, + { + name: "reject negative retries", + config: `retries: -1`, + expectError: true, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + tmpDir := testutil.TempDir(t, "threat-detection-kill-switch-validation") + content := `--- +on: + workflow_dispatch: +permissions: + contents: read + issues: read + pull-requests: read +engine: copilot +safe-outputs: + create-issue: + max: 1 + threat-detection: + ` + tt.config + ` +--- + +# Threat Detection Kill Switch Validation +` + testFile := filepath.Join(tmpDir, "test-workflow.md") + if err := os.WriteFile(testFile, []byte(content), 0o644); err != nil { + t.Fatal(err) + } + + err := NewCompiler().CompileWorkflow(testFile) + if tt.expectError && err == nil { + t.Fatal("expected compilation error, got nil") + } + if !tt.expectError && err != nil { + t.Fatalf("expected successful compilation, got error: %v", err) + } + }) + } +} + func TestThreatDetectionCustomPrompt(t *testing.T) { // Test that custom prompt instructions are included in the inline detection steps compiler := NewCompiler() diff --git a/pkg/workflow/threat_detection_external.go b/pkg/workflow/threat_detection_external.go index 92ae9911536..39df40c24be 100644 --- a/pkg/workflow/threat_detection_external.go +++ b/pkg/workflow/threat_detection_external.go @@ -417,13 +417,7 @@ func (c *Compiler) buildExternalDetectorExecutionStep(data *WorkflowData) []stri // no longer writes any step-summary output (see // github/gh-aw-threat-detection#792), so the flag is intentionally omitted here. npmPathSetup := GetNpmBinPathSetup() - threatDetectCmd := fmt.Sprintf( - "%s && threat-detect --engine %s --output %s %s", - npmPathSetup, - engineID, - shellEscapeArg(constants.ThreatDetectionResultPath), - shellEscapeArg(constants.ThreatDetectionDir), - ) + threatDetectCmd := buildThreatDetectCommand(npmPathSetup, engineID, data.SafeOutputs.ThreatDetection) // Build the complete AWF command. BuildAWFCommand handles config file setup, // ARC/DinD probes, tool cache mount, and the log tee pattern. @@ -503,6 +497,32 @@ func (c *Compiler) buildExternalDetectorExecutionStep(data *WorkflowData) []stri return steps } +func buildThreatDetectCommand(npmPathSetup, engineID string, config *ThreatDetectionConfig) string { + args := []string{ + "threat-detect", + "--engine", shellEscapeArg(engineID), + } + + if config != nil { + if config.EngineTimeout != nil { + args = append(args, "--engine-timeout", shellEscapeArg(*config.EngineTimeout)) + } + if config.MaxTurns != nil { + args = append(args, "--max-turns", strconv.Itoa(*config.MaxTurns)) + } + if config.Retries != nil { + args = append(args, "--retries", strconv.Itoa(*config.Retries)) + } + } + + args = append(args, + "--output", shellEscapeArg(constants.ThreatDetectionResultPath), + shellEscapeArg(constants.ThreatDetectionDir), + ) + + return fmt.Sprintf("%s && %s", npmPathSetup, strings.Join(args, " ")) +} + // extractStepEnvLines copies the YAML env: block from a rendered engine execution step. // It intentionally stops when a comment line appears because comments in step templates // are section separators, and consuming past them may bleed into non-env content. diff --git a/pkg/workflow/threat_detection_external_detector_execution_test.go b/pkg/workflow/threat_detection_external_detector_execution_test.go index 66998cd3507..776e0c08552 100644 --- a/pkg/workflow/threat_detection_external_detector_execution_test.go +++ b/pkg/workflow/threat_detection_external_detector_execution_test.go @@ -319,6 +319,53 @@ func TestBuildExternalDetectorExecutionStepEmitsTimeoutMinutes(t *testing.T) { } } +func TestBuildThreatDetectCommandOmitsUnsetOptionalFlags(t *testing.T) { + cmd := buildThreatDetectCommand("setup-path", "copilot", &ThreatDetectionConfig{}) + + if strings.Contains(cmd, "--engine-timeout") { + t.Fatalf("expected --engine-timeout to be omitted when unset, got: %s", cmd) + } + if strings.Contains(cmd, "--max-turns") { + t.Fatalf("expected --max-turns to be omitted when unset, got: %s", cmd) + } + if strings.Contains(cmd, "--retries") { + t.Fatalf("expected --retries to be omitted when unset, got: %s", cmd) + } +} + +func TestBuildThreatDetectCommandEmitsConfiguredOptionalFlags(t *testing.T) { + cmd := buildThreatDetectCommand("setup-path", "copilot", &ThreatDetectionConfig{ + EngineTimeout: strPtr("10m"), + MaxTurns: func() *int { + v := 100 + return &v + }(), + Retries: func() *int { + v := 1 + return &v + }(), + }) + + for _, want := range []string{ + "--engine-timeout 10m", + "--max-turns 100", + "--retries 1", + "--output /tmp/gh-aw/threat-detection/detection_result.json /tmp/gh-aw/threat-detection", + } { + if !strings.Contains(cmd, want) { + t.Fatalf("expected command to contain %q, got: %s", want, cmd) + } + } +} + +func TestBuildThreatDetectCommandShellEscapesEngineID(t *testing.T) { + cmd := buildThreatDetectCommand("setup-path", "copilot next", &ThreatDetectionConfig{}) + + if !strings.Contains(cmd, "--engine 'copilot next'") { + t.Fatalf("expected engine argument to be shell-escaped as a single argument, got: %s", cmd) + } +} + // TestBuildInstallAWFForExternalDetectorStepUsesRootless verifies that the detection // job installs the AWF binary in the same mode used to invoke awf in that job. func TestBuildInstallAWFForExternalDetectorStepUsesRootless(t *testing.T) {