Summary
With gh-aw v0.91.0, gh aw add applies the Markdown security scanner to a JavaScript file declared under resources: in an aw.yml package. Legitimate <form> and <script> markup inside a JavaScript template literal produces [html-abuse] errors and prevents package installation or reapplication.
Reproduction
In a fresh git repository, using gh-aw v0.91.0:
gh aw add githubnext/gh-aw-cao@5592db45cdcaa91e8c6e6ca7daefa43668922539 --force
This fails on .github/workflows/shared/setup-github-apps.mjs. Installing with --no-security-scanner succeeds; reapplying the same immutable package revision with the command above fails again.
Observed output:
Adding 58 workflow(s)...
Adding workflow 6/58: setup-github-apps
Security scan failed for workflow
Security scan found 2 issue(s) in workflow markdown:
.github/workflows/shared/setup-github-apps.mjs:285:1: error: [html-abuse] <script> tag can execute arbitrary JavaScript
.github/workflows/shared/setup-github-apps.mjs:285:1: error: [html-abuse] <form> tag can submit data to external servers
failed to add workflow 'githubnext/gh-aw-cao/.github/workflows/shared/setup-github-apps.mjs@5592db45cdcaa91e8c6e6ca7daefa43668922539'
workflow '.github/workflows/shared/setup-github-apps.mjs' failed security scan: 2 issue(s) detected
Expected behavior
Use file-aware/resource-aware security validation rather than interpreting arbitrary JavaScript source as workflow Markdown. This declared .mjs resource should not be rejected solely for an HTML template used by its GitHub App manifest registration page. Preserve applicable security checks for resources and normal Markdown scanning for workflow/prompt content; this is not a request to disable all resource scanning.
Verified source evidence
Workaround and impact
gh aw add githubnext/gh-aw-cao@5592db45cdcaa91e8c6e6ca7daefa43668922539 --force --no-security-scanner
The package's existing public installer documents and uses this workaround. It disables scanning for the whole package, including actual workflow Markdown, just to install one legitimate JavaScript resource. A regression test covering a declared .mjs resource with an HTML template alongside scanned Markdown content would help keep the fix appropriately scoped.
Summary
With gh-aw v0.91.0,
gh aw addapplies the Markdown security scanner to a JavaScript file declared underresources:in anaw.ymlpackage. Legitimate<form>and<script>markup inside a JavaScript template literal produces[html-abuse]errors and prevents package installation or reapplication.Reproduction
In a fresh git repository, using gh-aw v0.91.0:
This fails on
.github/workflows/shared/setup-github-apps.mjs. Installing with--no-security-scannersucceeds; reapplying the same immutable package revision with the command above fails again.Observed output:
Expected behavior
Use file-aware/resource-aware security validation rather than interpreting arbitrary JavaScript source as workflow Markdown. This declared
.mjsresource should not be rejected solely for an HTML template used by its GitHub App manifest registration page. Preserve applicable security checks for resources and normal Markdown scanning for workflow/prompt content; this is not a request to disable all resource scanning.Verified source evidence
registrationPage()returns the HTML template. The form posts the GitHub App manifest and the script submits that form; these are intentional runtime HTML, not rendered workflow Markdown.af1e2fd1ef1e34c3aa23207519116ac208d9393c),addWorkflowWithTracking()calls security validation before dispatching non-workflow resources.validateWorkflowSecurity()unconditionally passes the resolved content toScanMarkdownSecurityunless scanning is disabled, despite the availableIsPackageResourceFilemetadata.Workaround and impact
The package's existing public installer documents and uses this workaround. It disables scanning for the whole package, including actual workflow Markdown, just to install one legitimate JavaScript resource. A regression test covering a declared
.mjsresource with an HTML template alongside scanned Markdown content would help keep the fix appropriately scoped.