Skip to content

[Evidence Gap] Harden-runner custom detection initialization fails while MV3 gate stays green #206

Description

@seonghobae

Historical evidence defect

On PR #70 predecessor exact head b35e97c08b37a2e6f21cbc5e0403277c99f7931e, Manifest V3 Compatibility run 32401838435, job 96531623967, checked out that exact head and completed successfully while the external step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 initialization path logged a timeout and invalid authorization header format while fetching custom detection rules. That run therefore remained valid browser-fixture evidence but was not valid proof that custom detection rules were active.

Fresh exact-head recheck

PR #70 has since advanced non-destructively to exact head d1f0dfc611c07b847477bfe4671eba0a4d83d065 on unchanged prerequisite #65 head 6bb9474840db538b37299541f6031a0aee8393b7.

The exact-head Manifest V3 run 32436889661, job 96639798522, checks out d1f0dfc611c07b847477bfe4671eba0a4d83d065 and is successful. Its harden-runner/agent logs now show:

  • global feature flag EnableCustomDetectionRules:true;
  • Fetching custom detection rules;
  • Custom detection rules evaluator initialized;
  • Custom detection rules enabled; and
  • final harden-runner status Initialized.

The predecessor timeout/invalid-authorization messages do not recur in this exact-head run. No OriginWeave product or workflow mutation was used to manufacture that recovery.

Disposition

The observed external-integration failure is no longer reproducible on the current exact PR head, so this issue is closed as a recovered transient evidence condition rather than left as a false current blocker. The predecessor run remains historical evidence only and is not promoted to current proof.

If a future exact-head run again shows custom-detection initialization failure while remaining green, reopen or create the current owner incident with that exact run/job/checkout evidence. Protected-main AGENTS.md still forbids the scheduled OriginWeave writer from altering workflows, credentials, or security gates.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions