githubnext / githubnext/gh-aw-cao

[self-care:open-source-failures] Open source failures digest for 2026-09-06 snapshot

Closed
#3,057 0 comments 0 reactions 0 assignees View on GitHub
self-care self-care:open-source-failures
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

Snapshot 2026-09-06T01:10:58Z covering the last 168 hours found 825 failed runs across 7 public projects. In the bounded evidence available to this worker, the highest-priority untracked risk is repeated live-mode target-authority denial across AW Doctor workflows in `githubnext/gh-aw-cao`; recurring safe-output processing and other failures appear already tracked. The snapshot was truncated to the newest 100 failed runs, so this digest covers only that bounded subset.

**Action:** CAO maintainers should confirm issue ownership for the existing safe-output and authority investigations, then prioritize the new AW Doctor authority remediation below; accept when one owner is assigned and a fresh AW Doctor rerun passes `Run CAO control precompute`.

Critical findings:
- Public projects scanned: 7
- Failed runs in snapshot: 825
- Available bounded evidence: newest 100 failed runs only (`truncated: true`)
- Cluster counts in bounded evidence: P0 1, P1 7, P2 24
- Existing coverage found for recurring safe-output processing, Dependabot authority, and GitHub App token failures.
- Prioritized new remediation: repeated AW Doctor live-mode target-authority denial in `githubnext/gh-aw-cao`.

Prioritized remediation list

1. `githubnext/gh-aw-cao` — repeated pre-activation denial at `Run CAO control precompute` for AW Doctor workflows with `Target authority missing: add .github/workflows/cao.json to the target default branch for live mode` (15 enriched runs across three workflows in the bounded snapshot).
2. `githubnext/gh-aw-cao` — repeated `Process Safe Outputs` failures in `SelfCare / Data Acquisition Audit` and `Dev Practices / Well-Architected` (10 enriched runs total); already tracked by open issues matching the same signature.
3. `githubnext/gh-aw-cao` — repeated conclusion-only failures corroborating the AW Doctor and Well-Architected clusters, but without stronger root-cause evidence in this bounded snapshot.
4. Remaining failures in `github/gh-aw`, `github/gh-aw-actions`, `github/gh-aw-firewall`, and `github/gh-aw-mcpg` are isolated or insufficiently evidenced within the newest-100-run window.

Cluster summary from bounded snapshot

- P0
- `githubnext/gh-aw-cao` — AW Doctor workflows fail pre-activation with `Target authority missing: add .github/workflows/cao.json to the target default branch for live mode` across `.github/workflows/aw-failures-investigator.lock.yml`, `.github/workflows/aw-maintenance-compiler-security.lock.yml`, and `.github/workflows/aw-maintenance-upgrade.lock.yml` (15 enriched runs).
- P1
- `githubnext/gh-aw-cao` — `.github/workflows/self-care-data-acquisition-audit.lock.yml` fails at `safe_outputs` / `Process Safe Outputs` (5 runs).
- `githubnext/gh-aw-cao` — `.github/workflows/software-development-practices-github-well-architected.lock.yml` fails at `safe_outputs` / `Process Safe Outputs` (5 runs).
- `githubnext/gh-aw-cao` — `.github/workflows/eu-cra-compliance-vulnerability-handling-auditor.lock.yml` fails at `activation` / `Check workflow lock file` (2 runs).
- `githubnext/gh-aw-cao` — conclusion-only corroborating failures on AW Doctor / Failures (11 runs), AW Doctor / Compiler Security (14 runs), AW Doctor / Upgrade (11 runs), and Dev Practices / Well-Architected (9 runs); timing is consistent with the stronger enriched clusters but bounded evidence does not prove identical causes for every run.
- P2
- 24 isolated or insufficient-evidence workflow failures across the allowed public projects, including single-run agent-step and activation-step failures.

Representative runs in this digest:
- AW Doctor authority denial: https://github.com/githubnext/gh-aw-cao/actions/runs/33999614331
- SelfCare safe outputs: https://github.com/githubnext/gh-aw-cao/actions/runs/33999619999
- Well-Architected safe outputs: https://github.com/githubnext/gh-aw-cao/actions/runs/33998706360
- EU CRA lock check: https://github.com/githubnext/gh-aw-cao/actions/runs/33994475063

Existing coverage match

Open issues already match these recurring clusters:
- Safe-output processing in `githubnext/gh-aw-cao`: issues #2716, #2668, #2578, #2702.
- Dependabot live-mode target authority: issues #2464, #2577.
- Shared live-mode target-authority coverage across AW Doctor and Dependabot: issues #2703, #2637, #2399.
- GitHub App token generation in AI Credit Savings: issue #2717 and related earlier issues.

This run treated repository + affected workflow(s) + normalized signature as the duplicate-avoidance key and filed only the highest-severity untracked AW Doctor-specific cluster.

### Control Plane
- Correlation ID: 34004130135-256
- Central repository: githubnext/gh-aw-cao
- Control-plane run: https://github.com/githubnext/gh-aw-cao/actions/runs/34004130135

> Generated by [SelfCare / Open Source Failures](https://github.com/githubnext/gh-aw-cao/actions/runs/34004301795) · pi · gpt54 · 30.8 AIC · ⌖ 8.65 AIC · ⊞ 8.3K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Fself-care-open-source-failures%22&type=issues)
> - [x] expires on Sep 20, 2026, 1:40 AM UTC

Contributor guide

Open the contributing guide

Research direction

Start with the three affected workflow files: .github/workflows/aw-failures-investigator.lock.yml, aw-maintenance-compiler-security.lock.yml, and aw-maintenance-upgrade.lock.yml. Review the `Run CAO control precompute` failures and the linked authority investigations. Done means one owner is assigned and a fresh AW Doctor rerun passes that step.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, devops
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.