github / github/gh-aw-threat-detection
[gh-aw-parity] gh-aw threat-detection changes to review - 2026-09-10
- Dominant language
- Go
- Stars
- 13
- Forks
- 7
- Avg merge
- 9h 52m
- Merged PRs (30d)
- 25
Description
1 new gh-aw (pre)release scanned (v0.89.0), 1 threat-detection-related change found.
## Releases
- v0.89.0 (prerelease, 2026-09-09) — https://github.com/github/gh-aw/releases/tag/v0.89.0
## Threat-detection changes
- [#59636](https://github.com/github/gh-aw/pull/59636) — Fix threat detection reporting `config_error` for workflows using custom engines, so custom-engine workflows now get proper threat analysis instead of silently skipping it — shipped in v0.89.0
## Why this matters
This repository ships the `threat-detect` binary consumed by `gh-aw`; changes to how gh-aw invokes or gates on threat detection may require matching updates here to stay in parity.
Scanned: https://github.com/github/gh-aw-threat-detection/actions/runs/34435282931
> Generated by [gh-aw Parity Monitor](https://github.com/github/gh-aw-threat-detection/actions/runs/34435282931) · copilot · auto · 20.2 AIC · ⌖ 4.61 AIC · ⊞ 9K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw-threat-detection+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw-threat-detection%2Fgh-aw-parity-monitor%22&type=issues)
Contributor guide
Research direction
Start by reading gh-aw release v0.89.0 and upstream pull request #59636, then inspect how this repository's threat-detect binary is invoked and how custom engines affect threat analysis. Done means determining whether the upstream custom-engine change requires a matching update here and documenting or implementing the required parity work with appropriate validation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, go
- Domain
- security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 42/100