Historical evidence defect
On PR #70 predecessor exact head b35e97c08b37a2e6f21cbc5e0403277c99f7931e, Manifest V3 Compatibility run 32401838435, job 96531623967, checked out that exact head and completed successfully while the external step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 initialization path logged a timeout and invalid authorization header format while fetching custom detection rules. That run therefore remained valid browser-fixture evidence but was not valid proof that custom detection rules were active.
Fresh exact-head recheck
PR #70 has since advanced non-destructively to exact head d1f0dfc611c07b847477bfe4671eba0a4d83d065 on unchanged prerequisite #65 head 6bb9474840db538b37299541f6031a0aee8393b7.
The exact-head Manifest V3 run 32436889661, job 96639798522, checks out d1f0dfc611c07b847477bfe4671eba0a4d83d065 and is successful. Its harden-runner/agent logs now show:
- global feature flag
EnableCustomDetectionRules:true;
Fetching custom detection rules;
Custom detection rules evaluator initialized;
Custom detection rules enabled; and
- final harden-runner status
Initialized.
The predecessor timeout/invalid-authorization messages do not recur in this exact-head run. No OriginWeave product or workflow mutation was used to manufacture that recovery.
Disposition
The observed external-integration failure is no longer reproducible on the current exact PR head, so this issue is closed as a recovered transient evidence condition rather than left as a false current blocker. The predecessor run remains historical evidence only and is not promoted to current proof.
If a future exact-head run again shows custom-detection initialization failure while remaining green, reopen or create the current owner incident with that exact run/job/checkout evidence. Protected-main AGENTS.md still forbids the scheduled OriginWeave writer from altering workflows, credentials, or security gates.
Historical evidence defect
On PR #70 predecessor exact head
b35e97c08b37a2e6f21cbc5e0403277c99f7931e, Manifest V3 Compatibility run32401838435, job96531623967, checked out that exact head and completed successfully while the externalstep-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920initialization path logged a timeout andinvalid authorization header formatwhile fetching custom detection rules. That run therefore remained valid browser-fixture evidence but was not valid proof that custom detection rules were active.Fresh exact-head recheck
PR #70 has since advanced non-destructively to exact head
d1f0dfc611c07b847477bfe4671eba0a4d83d065on unchanged prerequisite #65 head6bb9474840db538b37299541f6031a0aee8393b7.The exact-head Manifest V3 run
32436889661, job96639798522, checks outd1f0dfc611c07b847477bfe4671eba0a4d83d065and is successful. Its harden-runner/agent logs now show:EnableCustomDetectionRules:true;Fetching custom detection rules;Custom detection rules evaluator initialized;Custom detection rules enabled; andInitialized.The predecessor timeout/invalid-authorization messages do not recur in this exact-head run. No OriginWeave product or workflow mutation was used to manufacture that recovery.
Disposition
The observed external-integration failure is no longer reproducible on the current exact PR head, so this issue is closed as a recovered transient evidence condition rather than left as a false current blocker. The predecessor run remains historical evidence only and is not promoted to current proof.
If a future exact-head run again shows custom-detection initialization failure while remaining green, reopen or create the current owner incident with that exact run/job/checkout evidence. Protected-main
AGENTS.mdstill forbids the scheduled OriginWeave writer from altering workflows, credentials, or security gates.