github / github/gh-aw-threat-detection

[gh-aw-parity] gh-aw threat-detection changes to review - 2026-09-09

Open
#1,048 0 comments 0 reactions 0 assignees View on GitHub
automation gh-aw-parity
Dominant language
Go
Stars
13
Forks
7
Avg merge
9h 52m
Merged PRs (30d)
25

Description

Scanned 2 new gh-aw (pre)releases (v0.88.7, v0.88.8) since v0.88.6; found 1 threat-detection-related change.

## Releases
- v0.88.7 (release, 2026-09-08) — https://github.com/github/gh-aw/releases/tag/v0.88.7

## Threat-detection changes
- [#59314](https://github.com/github/gh-aw/pull/59314) — Provision Node.js for external Copilot threat detection — shipped in v0.88.7

## Why this matters
This repository ships the `threat-detect` binary consumed by `gh-aw`; changes to how `gh-aw` provisions or invokes the external Copilot threat detection path may require matching updates here to stay in parity.

Scanned: https://github.com/github/gh-aw-threat-detection/actions/runs/34309068396

> Generated by [gh-aw Parity Monitor](https://github.com/github/gh-aw-threat-detection/actions/runs/34309068396) · copilot · auto · 22.9 AIC · ⌖ 5.73 AIC · ⊞ 10K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fgh-aw-parity-monitor%22&type=issues)

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the gh-aw v0.88.7 release and linked PR #59314, then inspect how this repository’s threat-detect binary is consumed by gh-aw. Determine whether the Node.js provisioning or external Copilot threat-detection changes require a matching update here; done means parity has been assessed and any needed repository changes are identified and validated.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, node.js
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.