CI Failure DoctorCI Failure Investigation: Daily Test Improver - Persistent "Setup threat detection" Failure (30+ Days) #177
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
The Daily Test Improver workflow has been consistently failing at the "Setup threat detection" step in the
detectionjob since at least March 1, 2026 — over 29 consecutive daily failures. The same failure affects Daily Perf Improver (every run) and intermittently Daily QA (when the agent produces output).Failure Details
3fa0e5d105b8ebfa8802002edc5fb117ebb237bfschedule(daily)Root Cause Analysis
This is not a code issue in the rlm-rs codebase. The fastembed bump from 5.12.1 → 5.13.0 (PR #159) is not the cause — failures predate that commit by weeks.
The failure is in the gh-aw agentic workflow infrastructure, specifically the
setup_threat_detection.cjsscript shipped withgithub/gh-aw/actions v0.47.1(pinned at commit1b847e3d0c6d8ebc44cb538c55198da42baa8a78in all.lock.ymlfiles).Failure path:
activationjob → ✅ successagentjob → ✅ success (the AI agent actually runs correctly every time)detectionjob → ❌ failure at Step 6: Setup threat detection (fails within <1 second)safe_outputs→ ⏭ skipped (because detection failed)conclusion→ ✅ success (graceful degradation: "Handle Agent Failure")The
setup_threat_detection.cjsscript fails when invoked after the agent produces output (HAS_PATCH=true). This explains why:Failed Jobs and Errors
detectiondetectiondetectionsafe_outputsInvestigation Findings
Pattern timeline:
Version mismatch identified:
github/gh-aw/actions/setupatv0.47.1(commit1b847e3d0c6d8ebc44cb538c55198da42baa8a78)github/gh-aw from 0.58.3 to 0.62.5agentics-maintenance.ymlalready referencesv0.58.3— only the lock files are staleKey diagnostic fact: The agent runs successfully every time. The AI is doing its job (writing tests, making improvements). The issue is purely in the post-agent security validation pipeline. No agent output ever reaches
safe_outputsdue to the detection failure.Related issues:
Recommended Actions
github/gh-awfrom 0.58.3 to 0.62.5gh aw compilein the repository root — this regenerates all.lock.ymlfiles from their.mdsources using the latest gh-aw versionsetup_threat_detection.cjsversion bundled in the new gh-aw release is compatible with current agent output formatdetectionjobPrevention Strategies
detectionjob fails 3+ consecutive timesAI Team Self-Improvement
For AI coding agents working on this repository, add to
AGENTS.mdorinstructions.md:Historical Context
All reactions