You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Daily Perf Improver workflow (Run #23581863015) is failing consistently in the detection job at the "Setup threat detection" step. This is a persistent, recurring failure observed on every scheduled run since at least 2026-03-02.
Failing Step: Setup threat detection (step 6 of 13)
Duration of Failure: Instantaneous (fails within the same second it starts)
Root Cause Analysis
The detection job fails at the "Setup threat detection" step, which executes:
const{ setupGlobals }=require('/opt/gh-aw/actions/setup_globals.cjs');setupGlobals(core,github,context,exec,io);const{ main }=require('/opt/gh-aw/actions/setup_threat_detection.cjs');awaitmain();
These scripts are provided by github/gh-aw/actions/setup@1b847e3d0c6d8ebc44cb538c55198da42baa8a78 (v0.47.1). The step fails instantly, causing all subsequent detection steps to be skipped (token validation, Copilot CLI install, threat detection execution).
Key observations:
The agent job succeeds — the Copilot CLI runs and produces a noop output (no performance improvements found)
Artifacts are produced and downloadable (agent-artifacts, agent-output, safe-output)
The failure is instantaneous, suggesting an exception thrown during script initialization or validation logic
The safe_outputs and push_repo_memory jobs are skipped because needs.detection.outputs.success != 'true'
Check release notes for versions v0.47.1 → v0.62.5 of github/gh-aw for any relevant fixes to threat detection setup
Regenerate the lock file by updating the github/gh-aw version to trigger a new compiled workflow that uses a patched version
AI Team Self-Improvement
Copy-paste these instructions into your instructions.md for AI coding agents:
When investigating CI failures in agentic workflows using github/gh-aw:
Check whether the failure is in a framework step (e.g., Setup threat detection, Setup Scripts) vs. user-authored code — framework failures often require updating the github/gh-aw package version rather than fixing repo code
When a detection or conclusion job fails at a gh-aw framework step, check if there's a pending Dependabot PR bumping github/gh-aw — merging it may resolve the issue
A failure in Setup threat detection that causes safe_outputs to be skipped means agent outputs are NOT being posted to GitHub, even if the main agent task succeeded
Historical Context
This is a recurring failure across 20+ scheduled runs. No existing open issue tracks this pattern. The [aw] No-Op Runs issue (#109) confirms the agent is successfully completing without finding work to do, which is separate from the detection framework failure.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Summary
The Daily Perf Improver workflow (Run #23581863015) is failing consistently in the
detectionjob at the "Setup threat detection" step. This is a persistent, recurring failure observed on every scheduled run since at least 2026-03-02.Failure Details
3fa0e5d105b8ebfa8802002edc5fb117ebb237bfschedule(daily)detectionSetup threat detection(step 6 of 13)Root Cause Analysis
The
detectionjob fails at the "Setup threat detection" step, which executes:These scripts are provided by
github/gh-aw/actions/setup@1b847e3d0c6d8ebc44cb538c55198da42baa8a78(v0.47.1). The step fails instantly, causing all subsequent detection steps to be skipped (token validation, Copilot CLI install, threat detection execution).Key observations:
agent-artifacts,agent-output,safe-output)safe_outputsandpush_repo_memoryjobs are skipped becauseneeds.detection.outputs.success != 'true'github/gh-awfrom 0.58.3 to 0.62.5, while the lock file pins v0.47.1Pattern: Recurrence History
This pattern is not new — the workflow has been failing at this exact step consistently.
Impact
safe_outputsto be skipped, preventing agent outputs from being posted to GitHubpush_repo_memoryis also skipped, so memory from agent runs is not persistedfailureeven though the main agent task completed successfullyRecommended Actions
setup_threat_detection.cjsscript ingithub/gh-aw@v0.47.1to understand why it failsgithub/gh-awfrom 0.58.3 to 0.62.5 may contain a fix for this issuegithub/gh-awfor any relevant fixes to threat detection setupgithub/gh-awversion to trigger a new compiled workflow that uses a patched versionAI Team Self-Improvement
When investigating CI failures in agentic workflows using
github/gh-aw:Setup threat detection,Setup Scripts) vs. user-authored code — framework failures often require updating thegithub/gh-awpackage version rather than fixing repo codedetectionorconclusionjob fails at a gh-aw framework step, check if there's a pending Dependabot PR bumpinggithub/gh-aw— merging it may resolve the issueSetup threat detectionthat causessafe_outputsto be skipped means agent outputs are NOT being posted to GitHub, even if the main agent task succeededHistorical Context
This is a recurring failure across 20+ scheduled runs. No existing open issue tracks this pattern. The
[aw] No-Op Runsissue (#109) confirms the agent is successfully completing without finding work to do, which is separate from the detection framework failure.All reactions