apache / apache/cloudstack

[aw] Detection Runs

Ouverte
#13,879 19 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
agentic-workflows
Langage dominant
Java
Étoiles
3.1k
Forks
1.4k
Merge moyen
6 j 19 h
PR mergées (30 j)
32

Description

This issue tracks all runs where threat detection flagged problems in agentic workflows in this repository. Each workflow run that completes with a detection warning or failure posts a comment here.

What is a Detection Problem?

A detection problem occurs when the threat detection system either:
- **Detects potential security threats** (prompt injection, secret leak, malicious patch)
- **Fails to produce results** (agent failure, parse error)

When `continue-on-error: true` (the default), these problems produce warnings and safe outputs still proceed. When `continue-on-error: false`, they block safe outputs entirely.

How This Helps

This issue helps you:
- Track workflows where threat detection raised concerns
- Review patterns of detection warnings or failures
- Identify false positives or recurring issues with threat detection
- Monitor the health of the threat detection system

Resources

- [GitHub Agentic Workflows Documentation](https://github.com/github/gh-aw)

> [!TIP]
> To configure threat detection behavior, update the frontmatter:
> ```yaml
> safe-outputs:
> threat-detection:
> continue-on-error: true # Warnings only (default)
> # continue-on-error: false # Strict mode — block safe outputs
> ```

---

> This issue is automatically managed by GitHub Agentic Workflows. Do not close this issue manually.
>
> **No action to take** - Do not assign to an agent.

> - [x] expires on Sep 13, 2026, 2:00 PM UTC

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Il s’agit d’une issue de suivi gérée automatiquement pour les avertissements et les échecs de détection des menaces lors des exécutions de agentic workflow. Elle indique explicitement qu’aucune action n’est nécessaire et qu’elle ne doit pas être attribuée à un agent ; il n’y a donc ni point d’entrée d’implémentation ni test de complétion pour un contributeur.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
github-actions
Domaine
ci-cd, security
Type d'issue
Bug
Difficulté
5/5
Temps estimé
Plus d'une semaine
Activité
Active
Clarté
À clarifier
Accessibilité débutants
1/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.