Repository navigation
Pattern miner: Add threat-detection and job-discriminator tips from upstream mining - #323
Draft
github-actions[bot] wants to merge 1 commit into
Conversation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Mined two small, evidence-backed refinements for existing curated archetypes. No new archetype was added this run — every recurring shape found that had two or more corroborating upstream examples was already represented in the library under a different tip, trigger, or safe-output recommendation.
Mining evidence
Sources mined:
/tmp/gh-aw/data/upstream/githubnext-agentics/files/workflows/*.md(58 workflow files)/tmp/gh-aw/data/upstream/github-gh-aw/files/.github/aw/*.md(gh-aw v0.87+ docs)1.
threat-detection: falsefor code-pattern scanners (security-scanner)githubnext-agentics/files/workflows/malicious-code-scan.md(the direct upstream equivalent of thesecurity-scannerarchetype) andai-moderator.mdboth explicitly setsafe-outputs.threat-detection: false..github/aw/workflow-patterns.md("Release Automation Pattern") and.github/aw/release-workflow.mdboth instruct disabling threat-detection whenever generated output legitimately contains code snippets, which is exactly what a malicious/suspicious-code scanner's findings do (they must quote the suspicious code to be actionable).security-scannerarchetype tips covered scope, reporting target,noop, and dedup, but nothing about threat-detection false positives on the scanner's own quoted-code output.patterns/archetypes/security-scanner.json.2.
concurrency.job-discriminatorfor schedule+workflow_dispatch archetypes (responsive-docs-tester)schedulewithworkflow_dispatch—multi-device-docs-tester.md(direct source for theresponsive-docs-testerarchetype),repo-assist.md, andvex-generator.md— all setconcurrency.job-discriminator: ${{ github.event_name == 'schedule' && 'scheduled' || github.run_id }}..github/aw/syntax-core.md) documentjob-discriminatoras an intentional feature specifically to prevent fan-out cancellations when "multiple workflow instances run concurrently with different inputs," listing the scheduled/dispatched-fallback expression as a named common usage.job-discriminator, andresponsive-docs-testercombinesschedulewith implicit manual re-runs for debugging a failing device/viewport, making it the best-matched existing archetype for this guidance.patterns/archetypes/responsive-docs-tester.json.What changed in
patterns/patterns/archetypes/security-scanner.json: added onetipsentry (no other field touched).patterns/archetypes/responsive-docs-tester.json: added onetipsentry (no other field touched).patterns/manifest.json,patterns/workflow-generation.json: untouched (no new archetype).Validation
npm test: 329 tests passed across 19 test files (19/19 files green).npm run build: succeeded,dist/produced cleanly including the two updated archetype JSON files.Candidates considered and deliberately left out
agentic-wiki-coder.md,agentic-wiki-writer.md): only one upstream repo pair, no corroborating docs recommendinggollumas a standalone archetype trigger. Below the two-workflow-or-docs bar.lock-for-agent,skip-roles,skip-bots,hide-comment,forks:moderation bundle (ai-moderator.md): all appear in a single upstream workflow;skip-roles/skip-botsare documented generically insyntax-core.mdbut not tied to a moderation-specific recommendation with a second corroborating example, so this stayed below the evidence bar for a refinement.group: trueoncreate-issuefor batched findings: three upstream workflows use it (discussion-task-miner.md,duplicate-code-detector.md,issue-arborist.md), but this exact tip ("use create-issue's group: true so they land as linked sub-issues") is already present verbatim inpatterns/archetypes/issue-hierarchy-manager.json.discussion-task-miner.md): a real recurring shape, but its core techniques (cache-memory history tracking,group: true,expires, bounded-window discussion scanning) are already spread acrosscode-health-auditor,backlog-drip, andissue-hierarchy-managertips; adding a new archetype would duplicate rather than add value within this run's "at most one archetype" budget.vex-statement-generator,agent-cost-tracker,issue-hierarchy-manager).