githubnext / githubnext/gh-aw-cao

[eu-cra-compliance:scope-classifier] github/gh-aw CRA scope evidence

Closed
#12,166 0 comments 0 reactions 0 assignees View on GitHub
eu-cra-compliance eu-cra-compliance:scope-classifier
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

github/gh-aw@b1c86bd47e35ad9a575318e54dcdebcdc0a33e40

Public `github/gh-aw` appears to be a software product used to create and run AI-powered GitHub Actions workflows, with active releases, installation scripts, and distribution via GitHub Releases and the GitHub CLI extension path. CRA scope is plausibly in play, but repository evidence is not sufficient to resolve economic-operator role, non-commercial FOSS treatment, EU-market placement, remote-processing dependence, or Annex classification without human review.

**Action:** GitHub legal/compliance and the `github/gh-aw` maintainers SHOULD review the open role, market-placement, hosted-service, and classification questions below; accept this record only if each `HUMAN_REVIEW_REQUIRED` row has an explicit owner and disposition.

### Snapshot
- Assessed repository: `github/gh-aw`
- Assessed checkout SHA: `b1c86bd47e35ad9a575318e54dcdebcdc0a33e40`
- Default branch: `main`
- Repository URL: https://github.com/github/gh-aw
- Verification date: 2026-09-16
- Overall status: `HUMAN_REVIEW_REQUIRED`

### Verified regulatory baseline
| Topic | Finding | Source | URL | Verified |
|---|---|---|---|---|
| CRA instrument | Regulation (EU) 2024/2847 is the binding baseline used for this record. | `source: { instrument: "Regulation (EU) 2024/2847", provision: "whole regulation baseline", authority: "binding" }` | https://eur-lex.europa.eu/eli/reg/2024/2847/oj | 2026-09-16 |
| Entry into force | 10 December 2024. | `source: { instrument: "Regulation (EU) 2024/2847", provision: "entry into force/date baseline", authority: "binding" }` | https://eur-lex.europa.eu/eli/reg/2024/2847/oj | 2026-09-16 |
| Article 14 reporting start | 11 September 2026. | `source: { instrument: "Regulation (EU) 2024/2847", provision: "Article 14 applicability date baseline", authority: "binding" }` | https://eur-lex.europa.eu/eli/reg/2024/2847/oj | 2026-09-16 |
| Full application | 11 December 2027. | `source: { instrument: "Regulation (EU) 2024/2847", provision: "general application date baseline", authority: "binding" }` | https://eur-lex.europa.eu/eli/reg/2024/2847/oj | 2026-09-16 |
| Commission guidance | Commission CRA policy page reflects guidance issued 27 July 2026; this guidance is non-binding. | `source: { instrument: "European Commission CRA guidance", provision: "policy guidance status/date", authority: "non-binding" }` | https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act | 2026-09-16 |

### Product and distribution evidence
| Topic | Evidence for scope | Evidence against / limit | Status |
|---|---|---|---|
| Product existence | README describes `gh-aw` as software that lets developers define AI-powered repository automation, compile workflows, and run AI agents through GitHub Actions. | None known. | `OBSERVED` |
| Software form | Checkout contains Go module, install scripts (`install-gh-aw.sh`, `install-gh-aw.ps1`), Dockerfile, actions, docs, and workflow compiler sources. | None known. | `OBSERVED` |
| Distribution channels | Public repo, homepage `(gh.io/redacted), GitHub Releases present; latest stable release observed `v0.88.7` and newer prereleases/tags exist. | No direct package-registry evidence observed from available GitHub package query. | `OBSERVED` |
| Security support signals | SECURITY.md states coordinated disclosure channel and says SBOMs are generated on every release and attached as assets. | Release assets/SBOM attachments not independently verified in this run. | `PARTIAL` |
| Remote/hosted dependence | README says workflows run through GitHub Actions and built-in AI engines include Copilot, Claude, OpenAI, Gemini, and Pi; this suggests remote-processing dependencies may be operationally material. | Repository evidence does not establish whether any hosted service is itself part of the product placed on the EU market versus an optional integration. | `HUMAN_REVIEW_REQUIRED` |

### Role, FOSS, scope, and classification records
| Topic | Evidence for | Evidence against / gaps | Status |
|---|---|---|---|
| CRA product with digital elements relevance | Repository represents executable software and supporting components, with releases and installation instructions. | No binding conclusion on whether all distributions are products with digital elements under the CRA without market-placement analysis. | `HUMAN_REVIEW_REQUIRED` |
| Manufacturer / other economic operator | Repository owner is `github`; copyright is GitHub, Inc.; homepage and release process indicate organized stewardship. | Repo evidence alone does not identify the legal entity placing a specific product on the EU market, nor importer/distributor relationships. | `HUMAN_REVIEW_REQUIRED` |
| Non-commercial free and open-source treatment | MIT license and public source availability support possible FOSS treatment. | GitHub-branded releases, homepage, active product docs, and associated services may indicate commercial activity or support linked to monetized offerings; repo evidence is insufficient to resolve the CRA non-commercial FOSS carve-out. | `HUMAN_REVIEW_REQUIRED` |
| Intended purpose / foreseeable use | README states purpose: define, compile, and run agentic GitHub workflows for tasks such as triage, review, docs, and analysis. | Support period, target users, and promised security-support window are not clearly stated in decisive repository evidence reviewed here. | `GAP_FOUND` |
| Substantial modification pathway | Project compiles workflows and supports extension/integration. | No assessed downstream product variant or modification record; cannot determine who becomes manufacturer after modifications. | `NOT_ASSESSED` |
| Default / important / critical classification | Repository automates software development and CI workflows; active integrations with GitHub Actions and AI services could matter for risk analysis. | No decisive evidence that the released product is an Annex III/IV important or critical product category, and no Official Journal harmonised-standard citation was verified for CRA classification or presumption of conformity. | `HUMAN_REVIEW_REQUIRED` |
| Harmonised standards / presumption | None verified. | No current Official Journal citation for Regulation (EU) 2024/2847 was verified in this run for any harmonised standard applicable to this repo; relevance alone MUST NOT be treated as presumption of conformity. | `GAP_FOUND` |

### Gaps and prioritized evidence requests
1. Confirm the legal entity and product SKU/version actually placed on the EU market, if any.
2. Confirm whether `gh-aw` is distributed only as non-commercial open-source software or as part of a commercial offering, support contract, managed service, or enterprise package.
3. Provide authoritative distribution inventory: release artifacts, package registries, container images, extension marketplaces, and download telemetry by region if available.
4. Confirm whether any hosted AI/model or GitHub-hosted processing is required for core intended use, optional, or bundled as product support.
5. Identify the intended support period, security update commitment, and substantial-modification governance.
6. Confirm whether internal classification analysis has considered Annex III/IV pathways and why they do or do not apply.

### Human review decisions
| Decision needed | Responsible reviewer | Why human review is required |
|---|---|---|
| Is a CRA-scoped product placed on the EU market? | GitHub legal/compliance | Requires market-placement and entity analysis beyond repo evidence. |
| Does the non-commercial FOSS treatment apply? | GitHub legal/compliance | MIT/public source is not enough to resolve commercial-activity questions. |
| What economic-operator role applies? | GitHub legal/compliance + product owner | Repo ownership does not prove manufacturer/importer/distributor status. |
| Any important/critical classification pathway? | Product security/compliance lead | Technical repo evidence is insufficient for final classification. |
| Are remote services part of the product boundary? | Product owner + architecture lead | Hosted dependencies and support relationship need authoritative scoping. |

### Human Acceptance
A non-bot reviewer SHOULD add a thumbs-up reaction only after reviewing the complete scope, role, FOSS-treatment, distribution, classification, provenance, gap, and human-decision record.

### Control Plane
- Correlation ID: `35111435260-322`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: https://github.com/githubnext/gh-aw-cao/actions/runs/35111435260

Evidence notes

- Repository metadata observed via `gh repo view`: public, not archived, MIT license, primary language Go, homepage `(gh.io/redacted), ~5.1k stars.
- Release evidence observed via `gh release list` and tags API: stable `v0.88.7` plus multiple newer prereleases/tags.
- Workflow inventory observed via GitHub API indicates many active workflows and automation capabilities.
- SECURITY.md says release SBOMs are generated and attached, but attachment presence was not independently checked.
- No GitHub Packages entries were returned from the bounded GraphQL package query.
- This record assists decision-makers and does not issue a legal conclusion.

> Generated by [:mag: EU CRA / Scope](https://github.com/githubnext/gh-aw-cao/actions/runs/35111973511) · pi · gpt54 · 24.5 AIC · ⊞ 10K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Feu-cra-compliance-scope-classifier%22&type=issues)
> - [x] expires on Oct 16, 2026, 3:03 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start with the issue's Snapshot and evidence tables, then review the referenced README, SECURITY.md, install scripts, Dockerfile, releases, and workflow inventory. Confirm the open role, market-placement, hosted-service, FOSS, and classification questions using repository evidence where possible. Done means every HUMAN_REVIEW_REQUIRED row has an explicit owner and disposition.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, github-actions, go
Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.