githubnext / githubnext/gh-aw-cao
[self-care:open-source-failures] Open source failures digest for 2026-09-06 snapshot
- Dominant language
- JavaScript
- Stars
- 3
- Forks
- 1
- Avg merge
- 49m
- Merged PRs (30d)
- 837
Description
Snapshot 2026-09-06T01:10:58Z covering the last 168 hours found 825 failed runs across 7 public projects. In the bounded evidence available to this worker, the highest-priority untracked risk is repeated live-mode target-authority denial across AW Doctor workflows in `githubnext/gh-aw-cao`; recurring safe-output processing and other failures appear already tracked. The snapshot was truncated to the newest 100 failed runs, so this digest covers only that bounded subset.
**Action:** CAO maintainers should confirm issue ownership for the existing safe-output and authority investigations, then prioritize the new AW Doctor authority remediation below; accept when one owner is assigned and a fresh AW Doctor rerun passes `Run CAO control precompute`.
Critical findings:
- Public projects scanned: 7
- Failed runs in snapshot: 825
- Available bounded evidence: newest 100 failed runs only (`truncated: true`)
- Cluster counts in bounded evidence: P0 1, P1 7, P2 24
- Existing coverage found for recurring safe-output processing, Dependabot authority, and GitHub App token failures.
- Prioritized new remediation: repeated AW Doctor live-mode target-authority denial in `githubnext/gh-aw-cao`.
Prioritized remediation list
1. `githubnext/gh-aw-cao` — repeated pre-activation denial at `Run CAO control precompute` for AW Doctor workflows with `Target authority missing: add .github/workflows/cao.json to the target default branch for live mode` (15 enriched runs across three workflows in the bounded snapshot).
2. `githubnext/gh-aw-cao` — repeated `Process Safe Outputs` failures in `SelfCare / Data Acquisition Audit` and `Dev Practices / Well-Architected` (10 enriched runs total); already tracked by open issues matching the same signature.
3. `githubnext/gh-aw-cao` — repeated conclusion-only failures corroborating the AW Doctor and Well-Architected clusters, but without stronger root-cause evidence in this bounded snapshot.
4. Remaining failures in `github/gh-aw`, `github/gh-aw-actions`, `github/gh-aw-firewall`, and `github/gh-aw-mcpg` are isolated or insufficiently evidenced within the newest-100-run window.
Cluster summary from bounded snapshot
- P0
- `githubnext/gh-aw-cao` — AW Doctor workflows fail pre-activation with `Target authority missing: add .github/workflows/cao.json to the target default branch for live mode` across `.github/workflows/aw-failures-investigator.lock.yml`, `.github/workflows/aw-maintenance-compiler-security.lock.yml`, and `.github/workflows/aw-maintenance-upgrade.lock.yml` (15 enriched runs).
- P1
- `githubnext/gh-aw-cao` — `.github/workflows/self-care-data-acquisition-audit.lock.yml` fails at `safe_outputs` / `Process Safe Outputs` (5 runs).
- `githubnext/gh-aw-cao` — `.github/workflows/software-development-practices-github-well-architected.lock.yml` fails at `safe_outputs` / `Process Safe Outputs` (5 runs).
- `githubnext/gh-aw-cao` — `.github/workflows/eu-cra-compliance-vulnerability-handling-auditor.lock.yml` fails at `activation` / `Check workflow lock file` (2 runs).
- `githubnext/gh-aw-cao` — conclusion-only corroborating failures on AW Doctor / Failures (11 runs), AW Doctor / Compiler Security (14 runs), AW Doctor / Upgrade (11 runs), and Dev Practices / Well-Architected (9 runs); timing is consistent with the stronger enriched clusters but bounded evidence does not prove identical causes for every run.
- P2
- 24 isolated or insufficient-evidence workflow failures across the allowed public projects, including single-run agent-step and activation-step failures.
Representative runs in this digest:
- AW Doctor authority denial: https://github.com/githubnext/gh-aw-cao/actions/runs/33999614331
- SelfCare safe outputs: https://github.com/githubnext/gh-aw-cao/actions/runs/33999619999
- Well-Architected safe outputs: https://github.com/githubnext/gh-aw-cao/actions/runs/33998706360
- EU CRA lock check: https://github.com/githubnext/gh-aw-cao/actions/runs/33994475063
Existing coverage match
Open issues already match these recurring clusters:
- Safe-output processing in `githubnext/gh-aw-cao`: issues #2716, #2668, #2578, #2702.
- Dependabot live-mode target authority: issues #2464, #2577.
- Shared live-mode target-authority coverage across AW Doctor and Dependabot: issues #2703, #2637, #2399.
- GitHub App token generation in AI Credit Savings: issue #2717 and related earlier issues.
This run treated repository + affected workflow(s) + normalized signature as the duplicate-avoidance key and filed only the highest-severity untracked AW Doctor-specific cluster.
### Control Plane
- Correlation ID: 34004130135-256
- Central repository: githubnext/gh-aw-cao
- Control-plane run: https://github.com/githubnext/gh-aw-cao/actions/runs/34004130135
> Generated by [SelfCare / Open Source Failures](https://github.com/githubnext/gh-aw-cao/actions/runs/34004301795) · pi · gpt54 · 30.8 AIC · ⌖ 8.65 AIC · ⊞ 8.3K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Fself-care-open-source-failures%22&type=issues)
> - [x] expires on Sep 20, 2026, 1:40 AM UTC
Contributor guide
Research direction
Start with the three affected workflow files: .github/workflows/aw-failures-investigator.lock.yml, aw-maintenance-compiler-security.lock.yml, and aw-maintenance-upgrade.lock.yml. Review the `Run CAO control precompute` failures and the linked authority investigations. Done means one owner is assigned and a fresh AW Doctor rerun passes that step.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, devops
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100