fix(threat-detection): stop uploading detection.log for external gh-aw-detection path - #51233
Conversation
…w-detection path The external threat-detect engine's raw log (detection.log) can contain the full untrusted agent transcript passed to the detection engine, including any secrets the agent may have echoed. Uploading it as a downloadable workflow artifact created a secret-exfiltration path. The `detection` artifact now only contains detection_result.json (the structured verdict) and the step-summary on the external-detector path. Neither GitHub Actions jobs nor the CLI rely on detection.log contents: downstream jobs consume only needs.detection.outputs.*/result, and the CLI's `detection` artifact set is used purely for optional human diagnostics via `gh aw logs`/`audit`. Recompiled all 100 affected .lock.yml workflows using the gh-aw-detection feature. Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Prevents external threat-detection workflows from persisting potentially sensitive detection.log output while retaining structured verdict and summary artifacts.
Changes:
- Removes
detection.logfrom external-detector artifact uploads. - Adds regression coverage and updates artifact documentation.
- Recompiles 100 affected workflow lock files.
Show a summary per file
| File | Description |
|---|---|
pkg/workflow/threat_detection_external.go |
Excludes the raw detection log from external-detector artifacts. |
pkg/workflow/threat_detection_isolation_test.go |
Tests that external uploads omit the raw log. |
docs/src/content/docs/reference/artifacts.md |
Documents external-detector artifact contents. |
.github/workflows/typist.lock.yml |
Regenerated detection upload path. |
.github/workflows/test-quality-sentinel.lock.yml |
Regenerated detection upload path. |
.github/workflows/prompt-clustering-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/pr-sous-chef.lock.yml |
Regenerated detection upload path. |
.github/workflows/pr-description-caveman.lock.yml |
Regenerated detection upload path. |
.github/workflows/pr-code-quality-reviewer.lock.yml |
Regenerated detection upload path. |
.github/workflows/mattpocock-skills-reviewer.lock.yml |
Regenerated detection upload path. |
.github/workflows/issue-monster.lock.yml |
Regenerated detection upload path. |
.github/workflows/impeccable-skills-reviewer.lock.yml |
Regenerated detection upload path. |
.github/workflows/github-remote-mcp-auth-test.lock.yml |
Regenerated detection upload path. |
.github/workflows/github-mcp-structural-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/example-workflow-analyzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/duplicate-code-detector.lock.yml |
Regenerated detection upload path. |
.github/workflows/docs-noob-tester.lock.yml |
Regenerated detection upload path. |
.github/workflows/detection-analysis-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/design-decision-gate.lock.yml |
Regenerated detection upload path. |
.github/workflows/deployment-incident-monitor.lock.yml |
Regenerated detection upload path. |
.github/workflows/deep-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-token-consumption-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-testify-uber-super-expert.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-repo-chronicle.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-rendering-scripts-verifier.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-reliability-review.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-regulatory.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-performance-summary.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-observability-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-news.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-multi-device-docs-tester.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-model-resolution.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-model-inventory.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-mcp-concurrency-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-max-ai-credits-test.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-issues-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-hippo-learn.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-graft-intelligence.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-geo-optimizer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-function-namer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-formal-spec-verifier.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-file-diet.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-fact.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-experiment-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-evals-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-elixir-credo-snippet-audit.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-doc-updater.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-doc-healer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-credit-limit-test.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-compiler-threat-spec-optimizer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-compiler-quality.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-community-attribution.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-code-metrics.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-cli-tools-tester.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-cli-performance.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-choice-test.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-caveman-optimizer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-cache-strategy-analyzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-byok-ollama-test.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-aw-cross-repo-compile-check.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-astrostylelite-markdown-spellcheck.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-assign-issue-to-user.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-architecture-diagram.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-ambient-context-optimizer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-agentrx-trace-optimizer.lock.yml |
Regenerated detection upload path. |
.github/workflows/daily-agent-of-the-day-blog-writer.lock.yml |
Regenerated detection upload path. |
.github/workflows/craft.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-session-insights.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-pr-prompt-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-pr-nlp-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-pr-merged-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-opt.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-cli-deep-research.lock.yml |
Regenerated detection upload path. |
.github/workflows/copilot-agent-analysis.lock.yml |
Regenerated detection upload path. |
.github/workflows/contribution-check.lock.yml |
Regenerated detection upload path. |
.github/workflows/constraint-solving-potd.lock.yml |
Regenerated detection upload path. |
.github/workflows/commit-changes-analyzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/code-scanning-fixer.lock.yml |
Regenerated detection upload path. |
.github/workflows/cloclo.lock.yml |
Regenerated detection upload path. |
.github/workflows/cli-version-checker.lock.yml |
Regenerated detection upload path. |
.github/workflows/cli-consistency-checker.lock.yml |
Regenerated detection upload path. |
.github/workflows/claude-code-user-docs-review.lock.yml |
Regenerated detection upload path. |
.github/workflows/ci-doctor.lock.yml |
Regenerated detection upload path. |
.github/workflows/ci-coach.lock.yml |
Regenerated detection upload path. |
.github/workflows/chaos-pr-bundle-fuzzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/changeset.lock.yml |
Regenerated detection upload path. |
.github/workflows/breaking-change-checker.lock.yml |
Regenerated detection upload path. |
.github/workflows/blog-auditor.lock.yml |
Regenerated detection upload path. |
.github/workflows/aw-failure-investigator.lock.yml |
Regenerated detection upload path. |
.github/workflows/avenger.lock.yml |
Regenerated detection upload path. |
.github/workflows/auto-triage-issues.lock.yml |
Regenerated detection upload path. |
.github/workflows/audit-workflows.lock.yml |
Regenerated detection upload path. |
.github/workflows/artifacts-summary.lock.yml |
Regenerated detection upload path. |
.github/workflows/archivx-agentic-workflows-analyzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/architecture-guardian.lock.yml |
Regenerated detection upload path. |
.github/workflows/archie.lock.yml |
Regenerated detection upload path. |
.github/workflows/approach-validator.lock.yml |
Regenerated detection upload path. |
.github/workflows/api-consumption-report.lock.yml |
Regenerated detection upload path. |
.github/workflows/agentic-token-trend-audit.lock.yml |
Regenerated detection upload path. |
.github/workflows/agent-persona-explorer.lock.yml |
Regenerated detection upload path. |
.github/workflows/agent-performance-analyzer.lock.yml |
Regenerated detection upload path. |
.github/workflows/ab-testing-advisor.lock.yml |
Regenerated detection upload path. |
Review details
Tip
Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 103/103 changed files
- Comments generated: 1
- Review effort level: Balanced
…-detector path Address review feedback: the `detection` artifact table entry said "Single-file" unconditionally, which contradicted the exception noted in the same row (external gh-aw-detection engine omits detection.log but still uploads detection_result.json + step-summary, i.e. 2 files). Split the Type column by engine path and updated the flattening guidance below the naming-compatibility table to call out `detection` as multi-file when produced by the external gh-aw-detection engine. Also revert the .lock.yml regeneration from the previous commit per review feedback — keeping this PR scoped to the compiler/docs/test change; workflow lock files will be regenerated separately. Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
…rnal gh-aw-detection path The detection step-summary file (step-summary.md) can contain content derived from the untrusted agent transcript that was passed to the detection engine, the same secret-exfiltration concern that applied to detection.log. It was already being appended directly to the job's $GITHUB_STEP_SUMMARY by buildDetectionStepSummaryAppendStep, so uploading it separately as an artifact was redundant as well as risky. The external-detector `detection` artifact now contains only detection_result.json (the structured verdict). Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
|
@copilot Quick triage nudge for this PR. Please refresh the branch if needed, check for any unresolved reviewer feedback, run the Run: https://github.com/github/gh-aw/actions/runs/31227649983
|
…r external detector The upstream threat-detect binary removed the --step-summary flag entirely in v0.4.5 (github/gh-aw-threat-detection#792): it no longer writes any step-summary output. Our compiler was still: - passing --step-summary <path> to threat-detect (now a stale, unused arg) - resetting/touching ThreatDetectionStepSummaryPath before execution on the external-detector path (dead code — nothing writes to it anymore) - emitting an "Append detection step summary" host-side step to copy that file into $GITHUB_STEP_SUMMARY (always a no-op now, since the file is never populated) Removed all three. The step-summary reset/touch is now scoped to the inline detection path only, where the engine's own execution step still overrides GITHUB_STEP_SUMMARY to write there. Updated the isolation test to assert these are absent on the external-detector path, and updated docs. Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Addressed the remaining reviewer feedback in |
|
🎉 This pull request is included in a new release. Release: |
Problem
For the external
gh-aw-detectionengine path (features: gh-aw-detection: true), the "Upload threat detection artifact" step uploadeddetection.logalongsidedetection_result.json. That log can contain the full untrusted agent transcript/output fed into the detection engine — including any secrets the agent may have echoed — so persisting it as a downloadable workflow artifact was a secret-exfiltration path.Fix
buildUploadDetectionArtifactStep(external-detector path only) no longer includesconstants.ThreatDetectionLogPathin the artifact'spath:list. Thedetectionartifact on this path now only contains:detection_result.json(structured verdict)step-summary.mdThe inline detection path (
buildUploadDetectionLogStep, used by default without the feature flag) is unchanged — it still uploadsdetection.log, since that path doesn't have the same untrusted-transcript-in-log concern (out of scope for this change; not raised by the user).Validation that nothing else depends on
detection.logdetectionartifact — they only readneeds.detection.outputs.*andneeds.detection.result(job outputs/conclusion), which are set fromdetection_result.jsonvia the in-job conclude step, not from the uploaded artifact.actions/download-artifactfor thedetectionartifact.detectionartifact set is thegh aw logs/gh aw auditCLI (ArtifactSetDetection), used for optional human diagnostics — this remains functional, it will just no longer surface the raw log for this path.if-no-files-found: ignorethat omitting the path doesn't cause upload failures.Changes
pkg/workflow/threat_detection_external.go: removeddetection.logfrom the upload path list + updated doc comment.pkg/workflow/threat_detection_isolation_test.go: added assertion that the external-detector upload step does NOT includedetection.log.docs/src/content/docs/reference/artifacts.md: documented the exception for the external-detector path..lock.ymlworkflows that usefeatures: gh-aw-detection: true.Testing
go build ./...— passesgo test ./pkg/workflow/... ./pkg/cli/...— all passgh-aw compile --validate --verbose --purge— all 283 workflows compiled successfully