Update gh-aw-threat-detection to v0.3.0#47149
Conversation
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
Co-authored-by: davidslater <12449447+davidslater@users.noreply.github.com>
|
✅ Test Quality Sentinel completed test quality analysis. No test files were added or modified in this PR. Test Quality Sentinel analysis skipped. PR #47149 only updates gh-aw-threat-detection version constraints in lock.yml files and version constants. |
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅ |
|
✅ PR Code Quality Reviewer completed the code quality review. |
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. No ADR enforcement needed: PR #47149 does not have the 'implementation' label and has only 1 new line of code in business logic directories (threshold: 100). |
There was a problem hiding this comment.
Pull request overview
Updates the default gh-aw-threat-detection binary from v0.2.2 to v0.3.0 and propagates the pin through generated workflows. The v0.3.0 release and required assets exist.
Changes:
- Updates the single source version constant.
- Recompiles 89 threat-detection workflow lock files.
- Synchronizes a reusable workflow permission from
actions: writetoactions: read.
Show a summary per file
| File | Description |
|---|---|
pkg/constants/version_constants.go |
Pins threat detection to v0.3.0. |
.github/workflows/typist.lock.yml |
Propagates v0.3.0. |
.github/workflows/test-quality-sentinel.lock.yml |
Propagates v0.3.0. |
.github/workflows/smoke-call-workflow.lock.yml |
Synchronizes imported permissions. |
.github/workflows/prompt-clustering-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/github-remote-mcp-auth-test.lock.yml |
Propagates v0.3.0. |
.github/workflows/github-mcp-structural-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/example-workflow-analyzer.lock.yml |
Propagates v0.3.0. |
.github/workflows/duplicate-code-detector.lock.yml |
Propagates v0.3.0. |
.github/workflows/docs-noob-tester.lock.yml |
Propagates v0.3.0. |
.github/workflows/detection-analysis-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-token-consumption-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-testify-uber-super-expert.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-repo-chronicle.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-rendering-scripts-verifier.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-reliability-review.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-performance-summary.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-observability-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-news.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-multi-device-docs-tester.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-model-resolution.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-model-inventory.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-mcp-concurrency-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-max-ai-credits-test.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-issues-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-hippo-learn.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-geo-optimizer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-function-namer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-formal-spec-verifier.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-file-diet.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-fact.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-experiment-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-evals-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-elixir-credo-snippet-audit.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-doc-updater.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-doc-healer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-credit-limit-test.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-compiler-quality.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-community-attribution.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-code-metrics.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-cli-tools-tester.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-cli-performance.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-choice-test.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-caveman-optimizer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-cache-strategy-analyzer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-byok-ollama-test.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-aw-cross-repo-compile-check.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-assign-issue-to-user.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-architecture-diagram.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-ambient-context-optimizer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-agentrx-trace-optimizer.lock.yml |
Propagates v0.3.0. |
.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml |
Propagates v0.3.0. |
.github/workflows/craft.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-session-insights.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-pr-prompt-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-pr-nlp-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-pr-merged-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-opt.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-cli-deep-research.lock.yml |
Propagates v0.3.0. |
.github/workflows/copilot-agent-analysis.lock.yml |
Propagates v0.3.0. |
.github/workflows/contribution-check.lock.yml |
Propagates v0.3.0. |
.github/workflows/constraint-solving-potd.lock.yml |
Propagates v0.3.0. |
.github/workflows/commit-changes-analyzer.lock.yml |
Propagates v0.3.0. |
.github/workflows/code-scanning-fixer.lock.yml |
Propagates v0.3.0. |
.github/workflows/cloclo.lock.yml |
Propagates v0.3.0. |
.github/workflows/cli-version-checker.lock.yml |
Propagates v0.3.0. |
.github/workflows/cli-consistency-checker.lock.yml |
Propagates v0.3.0. |
.github/workflows/claude-code-user-docs-review.lock.yml |
Propagates v0.3.0. |
.github/workflows/ci-doctor.lock.yml |
Propagates v0.3.0. |
.github/workflows/ci-coach.lock.yml |
Propagates v0.3.0. |
.github/workflows/chaos-pr-bundle-fuzzer.lock.yml |
Propagates v0.3.0. |
.github/workflows/changeset.lock.yml |
Propagates v0.3.0. |
.github/workflows/breaking-change-checker.lock.yml |
Propagates v0.3.0. |
.github/workflows/brave.lock.yml |
Propagates v0.3.0. |
.github/workflows/blog-auditor.lock.yml |
Propagates v0.3.0. |
.github/workflows/aw-failure-investigator.lock.yml |
Propagates v0.3.0. |
.github/workflows/avenger.lock.yml |
Propagates v0.3.0. |
.github/workflows/auto-triage-issues.lock.yml |
Propagates v0.3.0. |
.github/workflows/audit-workflows.lock.yml |
Propagates v0.3.0. |
.github/workflows/artifacts-summary.lock.yml |
Propagates v0.3.0. |
.github/workflows/architecture-guardian.lock.yml |
Propagates v0.3.0. |
.github/workflows/archie.lock.yml |
Propagates v0.3.0. |
.github/workflows/approach-validator.lock.yml |
Propagates v0.3.0. |
.github/workflows/api-consumption-report.lock.yml |
Propagates v0.3.0. |
.github/workflows/agentic-token-trend-audit.lock.yml |
Propagates v0.3.0. |
.github/workflows/agent-persona-explorer.lock.yml |
Propagates v0.3.0. |
.github/workflows/agent-performance-analyzer.lock.yml |
Propagates v0.3.0. |
.github/workflows/ab-testing-advisor.lock.yml |
Propagates v0.3.0. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 91/91 changed files
- Comments generated: 0
- Review effort level: Medium
There was a problem hiding this comment.
Clean version bump from v0.2.2 to v0.3.0 for gh-aw-threat-detection. The single source constant in pkg/constants/version_constants.go is the right place for this pin, and the lock files are uniformly updated via make recompile. No issues found.
🧵 Reviewed using Impeccable skills by Impeccable Skills Reviewer · sonnet46 16.7 AIC · ⌖ 7.25 AIC · ⊞ 5K
There was a problem hiding this comment.
Skills-Based Review 🧠
Applied /codebase-design — this is a clean, mechanical version bump with no issues to flag.
📋 Review Summary
What was reviewed
pkg/constants/version_constants.go— single constant updatev0.2.2→v0.3.0- 89
.lock.ymlfiles — all mechanically recompiled; no hand-edits smoke-call-workflow.lock.yml— incidentalactions: write→actions: readcorrection
Positive Highlights
- ✅ Single source of truth: one constant drives all 89 lock file pins
- ✅ Recompile confirms no hand-edits; fully reproducible
- ✅ Pre-merge asset verification noted in PR description
- ✅
actions: write→actions: readis a least-privilege improvement - ✅ Isolation test dynamically reads the constant — no test edits needed
🧠 Reviewed using Matt Pocock's skills by Matt Pocock Skills Reviewer · sonnet46 19.9 AIC · ⌖ 4.51 AIC · ⊞ 6.7K
Comment /matt to run again
There was a problem hiding this comment.
No blocking issues
The version bump is mechanical and consistent: all 89 lock files updated to v0.3.0 via make recompile, and DefaultThreatDetectVersion is the single source of truth.
Incidental permissions fix in smoke-call-workflow
The actions: write → actions: read change in smoke-call-workflow.lock.yml is correct. It applies to the call-smoke-workflow-call job, which calls a reusable workflow that only requires actions: read (confirmed in smoke-workflow-call.lock.yml). The conclusion job that legitimately needs actions: write is unchanged. Since the source .md declares no explicit actions permission, make recompile will continue to derive actions: read from the called workflow — this fix will not regress.
🔎 Code quality review by PR Code Quality Reviewer · sonnet46 44.1 AIC · ⌖ 4.49 AIC · ⊞ 5.6K
Comment /review to run again
|
@copilot please run the Run: https://github.com/github/gh-aw/actions/runs/29873842709 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "pi.dev"See Network Configuration for more information.
|
Ran
Exact maintainer action: once that in-progress run finishes (or is confirmed non-required by branch protection), merge PR #47149. |
|
@copilot please run the Run: https://github.com/github/gh-aw/actions/runs/29877220652 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "pi.dev"See Network Configuration for more information.
|
Ran
Exact maintainer action to merge: after that in-progress run completes (or if branch protection confirms it is non-required), merge PR #47149. |
🤖 PR Triage
Rationale: Dependency version bump propagated to 91 lock files via
|
|
@copilot please run the Run: https://github.com/github/gh-aw/actions/runs/29881378283 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "pi.dev"See Network Configuration for more information.
|
Ran
Exact maintainer action to merge: once that in-progress check completes successfully (or is confirmed non-required by branch protection), merge PR #47149. |
|
@copilot please run the Run: https://github.com/github/gh-aw/actions/runs/29883079375 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "pi.dev"See Network Configuration for more information.
|
Ran
The remaining blocker is branch protection waiting on an active required check, not a stale check state: Exact maintainer action to merge: once that |
|
@copilot please run the Run: https://github.com/github/gh-aw/actions/runs/29889445104 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
network:
allowed:
- defaults
- "pi.dev"See Network Configuration for more information.
|
Ran
Exact next maintainer action: once that in-progress |
|
🎉 This pull request is included in a new release. Release: |
Bump the pinned
gh-aw-threat-detectionbinary fromv0.2.2tov0.3.0. The version is a single source constant that flows into all detection workflow lock files at compile time.Changes
pkg/constants/version_constants.go— updatedDefaultThreatDetectVersionfromv0.2.2tov0.3.0:Recompiled workflows —
make recompilepropagated the new pin (install_threat_detect_binary.sh v0.3.0) into 89.lock.ymlfiles. No lock files were hand-edited.Notes
v0.3.0release and its runtime assets (checksums.txt,threat-detect-linux-amd64,threat-detect-linux-arm64) exist ingithub/gh-aw-threat-detectionbefore pinning, since the install script fetches them from GitHub Releases at runtime.threat_detection_isolation_test.go) reads the constant dynamically, so it validates the new pin without edits.smoke-call-workflow.lock.ymlhad stale imported permissions (actions: write); recompile synchronized it toactions: readto match its source workflowsmoke-workflow-call.lock.yml.Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
pi.devSee Network Configuration for more information.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
pi.devSee Network Configuration for more information.
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
pi.devSee Network Configuration for more information.
Run: https://github.com/github/gh-aw/actions/runs/29883079375
Warning
Firewall blocked 1 domain
The following domain was blocked by the firewall during workflow execution:
pi.devSee Network Configuration for more information.