Skip to content

Pattern miner: Add threat-detection and job-discriminator tips from upstream mining - #323

Draft
github-actions[bot] wants to merge 1 commit into
mainfrom
pattern-mining/threat-detection-job-discriminator-tips-a4a64638057ee390
Draft

github-actions[bot] wants to merge 1 commit into
mainfrom
pattern-mining/threat-detection-job-discriminator-tips-a4a64638057ee390

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Summary

Mined two small, evidence-backed refinements for existing curated archetypes. No new archetype was added this run — every recurring shape found that had two or more corroborating upstream examples was already represented in the library under a different tip, trigger, or safe-output recommendation.

Mining evidence

Sources mined:

  • /tmp/gh-aw/data/upstream/githubnext-agentics/files/workflows/*.md (58 workflow files)
  • /tmp/gh-aw/data/upstream/github-gh-aw/files/.github/aw/*.md (gh-aw v0.87+ docs)

1. threat-detection: false for code-pattern scanners (security-scanner)

  • Upstream evidence: githubnext-agentics/files/workflows/malicious-code-scan.md (the direct upstream equivalent of the security-scanner archetype) and ai-moderator.md both explicitly set safe-outputs.threat-detection: false.
  • Upstream docs corroborate this as a deliberate, recommended pattern rather than a one-off: .github/aw/workflow-patterns.md ("Release Automation Pattern") and .github/aw/release-workflow.md both instruct disabling threat-detection whenever generated output legitimately contains code snippets, which is exactly what a malicious/suspicious-code scanner's findings do (they must quote the suspicious code to be actionable).
  • Gap: the library's security-scanner archetype tips covered scope, reporting target, noop, and dedup, but nothing about threat-detection false positives on the scanner's own quoted-code output.
  • Change: appended one tip to patterns/archetypes/security-scanner.json.

2. concurrency.job-discriminator for schedule+workflow_dispatch archetypes (responsive-docs-tester)

  • Upstream evidence: three workflows combining schedule with workflow_dispatch — multi-device-docs-tester.md (direct source for the responsive-docs-tester archetype), repo-assist.md, and vex-generator.md — all set concurrency.job-discriminator: ${{ github.event_name == 'schedule' && 'scheduled' || github.run_id }}.
  • Upstream docs (.github/aw/syntax-core.md) document job-discriminator as an intentional feature specifically to prevent fan-out cancellations when "multiple workflow instances run concurrently with different inputs," listing the scheduled/dispatched-fallback expression as a named common usage.
  • Gap: the library had no tip anywhere about job-discriminator, and responsive-docs-tester combines schedule with implicit manual re-runs for debugging a failing device/viewport, making it the best-matched existing archetype for this guidance.
  • Change: appended one tip to patterns/archetypes/responsive-docs-tester.json.

What changed in patterns/

  • patterns/archetypes/security-scanner.json: added one tips entry (no other field touched).
  • patterns/archetypes/responsive-docs-tester.json: added one tips entry (no other field touched).
  • patterns/manifest.json, patterns/workflow-generation.json: untouched (no new archetype).

Validation

  • npm test: 329 tests passed across 19 test files (19/19 files green).
  • npm run build: succeeded, dist/ produced cleanly including the two updated archetype JSON files.

Candidates considered and deliberately left out

  • New archetype for wiki-to-code / wiki-driven workflows (agentic-wiki-coder.md, agentic-wiki-writer.md): only one upstream repo pair, no corroborating docs recommending gollum as a standalone archetype trigger. Below the two-workflow-or-docs bar.
  • lock-for-agent, skip-roles, skip-bots, hide-comment, forks: moderation bundle (ai-moderator.md): all appear in a single upstream workflow; skip-roles/skip-bots are documented generically in syntax-core.md but not tied to a moderation-specific recommendation with a second corroborating example, so this stayed below the evidence bar for a refinement.
  • group: true on create-issue for batched findings: three upstream workflows use it (discussion-task-miner.md, duplicate-code-detector.md, issue-arborist.md), but this exact tip ("use create-issue's group: true so they land as linked sub-issues") is already present verbatim in patterns/archetypes/issue-hierarchy-manager.json.
  • Discussion-mining into issues (discussion-task-miner.md): a real recurring shape, but its core techniques (cache-memory history tracking, group: true, expires, bounded-window discussion scanning) are already spread across code-health-auditor, backlog-drip, and issue-hierarchy-manager tips; adding a new archetype would duplicate rather than add value within this run's "at most one archetype" budget.
  • VEX/cost-tracker/sub-issue-closer style single-purpose workflows: each already has a matching curated archetype (vex-statement-generator, agent-cost-tracker, issue-hierarchy-manager).

Generated by Pattern Miner · copilot · auto · 395 AIC · ⌖ 10.3 AIC · ⊞ 8.3K · ◷

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants