Threat-detection Setup Node.js ignores `runtimes.node.version`
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 84/100
Hướng nghiên cứu
Bắt đầu tại pkg/workflow/nodejs.go ở GenerateNodeJsSetupStep(), sau đó theo dõi cách phiên bản runtime Node đã được phân giải được chuyển đến agent job. Chạy gh aw compile với runtimes.node.version được đặt thành 24.21.0; kết quả đúng là các bước Setup Node.js của detection và evals sử dụng phiên bản đó, khớp với agent job.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
With runtimes.node.version set, the agent job's Setup Node.js step uses that version. The threat-detection job's Setup Node.js step still emits node-version: '24' (constants.DefaultNodeVersion).
Related history:
- #64498 (for #64466) made the detection and evals steps honor
runtimes.node.action-repoandaction-version. Its description says it does not changeruntimes.node.version. - Adding our own
Setup Node.jsundersafe-outputs.threat-detection.stepsfails to compile with "duplicate step 'Setup Node.js' found in job 'detection'".
Version
gh-aw v0.89.21; v0.90.3 behaves the same.
Reproduction
-
Add to any workflow with threat detection enabled:
runtimes: node: version: "24.21.0" -
Run
gh aw compile.
Observed
The agent job emits node-version: '24.21.0'. The detection job emits:
- name: Setup Node.js
uses: actions/setup-node@<sha> # v7.0.0
with:
node-version: '24'
Expected
The detection and evals Setup Node.js steps use runtimes.node.version when it is set, matching the agent job, so a repository that pins an exact runtime sees one version across every generated job.
Suggested change
Pass the resolved Node runtime version into GenerateNodeJsSetupStep() (pkg/workflow/nodejs.go), as #64498 did for the action reference.
- Ngôn ngữ chính
- Go
- Star
- 5.4k
- Fork
- 576
- Merge trung bình
- 8 giờ 46 phút
- Pull request đã merge (30 ngày)
- 753
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/gh-aw
-
automation models
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
automation code-quality cookie deep-report documentation improvement quick-win task-mining
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 85/100
github/gh-aw#66660 · 10 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agentic-workflows maintenance
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 77/100
github/gh-aw#66635 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
automation code-quality cookie improvement quick-win task-mining
Độ khó 2/5 Dưới một giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
automation documentation enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
Maintainer thường phản hồi trong vòng 1 ngày
Issue tương tự
-
bug from-studio
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 63/100
esengine/DeepSeek-Reasonix#12355 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 1 ngày
-
needs-triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
gke-labs/kube-agents#2612 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 66/100
bluesky-social/indigo#1496 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Gentleman-Programming/gentle-ai#5371 ·
Maintainer thường phản hồi trong vòng 1 ngày