Repository navigation
CI Failure DoctorCI Failure Investigation: Daily Perf/Test Improver - setup_threat_detection Regression (22+ days) #160
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
The Daily Perf Improver and Daily Test Improver agentic workflows have been failing consistently for 22 consecutive days (since March 2, 2026). The failure occurs in the
detectionjob at the "Setup threat detection" step, which blocks all agent outputs from being published.This is not a Rust code issue — all Rust CI jobs (clippy, tests, doc, deny, msrv) pass normally.
Failure Details
448b4e6f8cfb28665b2697538d802f6dfee66cc5schedule(daily cron)Root Cause Analysis
The Trigger: SHA Change in
github/gh-aw/actions/setupPR #84 ("ci: bump github/gh-aw from 0.47.1 to 0.51.2", merged March 2, 2026) changed the pinned SHA for
github/gh-aw/actions/setupin all.lock.ymlworkflow files:c94abee3e98890c5ddf4e8f41a74ed3302c56cec# v0.47.15fa65dd15a71cec00f2d14c664467154d343d875# v0.47.1c2ce8fd41aa47d7471b14b1014c4c7560b7070f2# v0.47.10ce8adde9abb3d0841cfb16ede313b9f99301642# v0.47.11b847e3d0c6d8ebc44cb538c55198da42baa8a78# v0.47.1All SHAs carry the version comment
# v0.47.1, suggesting thev0.47.1tag on thegithub/gh-awrepo has been force-pushed multiple times. Each updated SHA introduced (or retained) the breaking change insetup_threat_detection.cjs.What Fails
The
setup_threat_detectionstep runs a JavaScript action:Historical Context
All reactions