refactor(detect): remove step summary output from the detection job - #792
Conversation
The detector no longer writes to GITHUB_STEP_SUMMARY. Drop the artifact inventory table, the rendered-prompt block, and the conclude verdict block along with the --step-summary flags on both commands. Observability now lives solely in the JSONL run log and the conclude job-log diagnostics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Removes GitHub Actions step-summary output while retaining JSONL observability and job-log diagnostics.
Changes:
- Removes step-summary flags, writers, markers, and tests.
- Preserves run-log inventory and conclusion diagnostics.
- Updates specifications and documentation.
Show a summary per file
| File | Description |
|---|---|
specs/usage-spec.md |
Documents JSONL-only inventory. |
specs/threat-detection-spec.md |
Revises summary-output requirements. |
README.md |
Removes step-summary usage. |
DEVGUIDE.md |
Updates inventory guidance. |
CLAUDE.md |
Updates repository guidance. |
cmd/threat-detect/main.go |
Removes detection summary output. |
cmd/threat-detect/main_test.go |
Removes summary tests. |
cmd/threat-detect/logfile_test.go |
Removes summary assertions. |
cmd/threat-detect/conclude.go |
Removes verdict-summary output. |
cmd/threat-detect/conclude_test.go |
Updates conclusion tests. |
pkg/detector/reason.go |
Removes summary markers. |
pkg/detector/reason_test.go |
Removes marker tests. |
pkg/detector/summary.go |
Deletes summary rendering. |
pkg/detector/summary_test.go |
Deletes renderer tests. |
pkg/stepsummary/stepsummary.go |
Deletes inventory summary writer. |
pkg/stepsummary/stepsummary_test.go |
Deletes writer tests. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 16/16 changed files
- Comments generated: 1
- Review effort level: Balanced
| artifact inventory defined by TD-17b, the rendered prompt, and the conclusion | ||
| verdict are surfaced through the run log (TD-20a) and the `conclude` | ||
| diagnostics (TD-20d) only. |
The rendered prompt is no longer surfaced anywhere; the run log records only prompt metadata. Say so explicitly instead of implying the full prompt is available via the run log or conclude diagnostics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
Good catch — fixed in e50029e. TD-20c now reads:
|
main removed all step-summary output from the detector (#792), so the preflight block written to GITHUB_STEP_SUMMARY is dropped along with engine.FormatPreflightSummary and its test. Preflight now surfaces solely through stderr and the engine_preflight run-log event, matching TD-20c; TD-20j and the README/CLAUDE.md notes are reworded accordingly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
…r external detector The upstream threat-detect binary removed the --step-summary flag entirely in v0.4.5 (github/gh-aw-threat-detection#792): it no longer writes any step-summary output. Our compiler was still: - passing --step-summary <path> to threat-detect (now a stale, unused arg) - resetting/touching ThreatDetectionStepSummaryPath before execution on the external-detector path (dead code — nothing writes to it anymore) - emitting an "Append detection step summary" host-side step to copy that file into $GITHUB_STEP_SUMMARY (always a no-op now, since the file is never populated) Removed all three. The step-summary reset/touch is now scoped to the inline detection path only, where the engine's own execution step still overrides GITHUB_STEP_SUMMARY to write there. Updated the isolation test to assert these are absent on the external-detector path, and updated docs. Co-authored-by: David Slater <12449447+davidslater@users.noreply.github.com>
What
The detection job no longer writes anything to the GitHub Actions step summary.
Removed:
pkg/stepsummary— the artifact inventory Markdown tablepkg/detector/summary.go— the rendered-prompt block (FormatPromptSummary) and the verdict block (FormatVerdictSummary,AppendStepSummary)--step-summaryflag (and itsGITHUB_STEP_SUMMARYdefault) on boththreat-detectandthreat-detect conclude, plus the related path-collision checksThreatMarkerand the<!-- gh-aw-threat-* -->marker constants, which were only ever rendered into the verdict summaryKept
--log-file) still records the full recursive artifact inventory, prompt metadata, and verdict.concludestill writes its self-contained job-log diagnostics, including theThreatHeadlinethat distinguishes a tooling failure (agent_failure/parse_error) from a real security finding.$GITHUB_OUTPUT/$GITHUB_ENVcollision rejection inconclude, and--log-filevs--outputcollision rejection in the detection run.Docs & spec
specs/threat-detection-spec.md: TD-20c rewritten to state the detector MUST NOT write to the step summary; TD-20g and TD-20h removed; TD-20i reduced to the job-log headline contract.specs/usage-spec.md(U-09),README.md,DEVGUIDE.md,CLAUDE.mdupdated accordingly.Verification
make fmt lint build testpasses.gosecfindings are unchanged from the pre-existing baseline (only reduced by the deleted files).