published Aug 28, 2026, 10:41 PM · updated Aug 30, 2026, 2:38 AM
Summary
The package detail routes omit standalone package-maintainer workflows from their package topology and reporting, even though the published inventory and registered workflow set include them. Affected routes: /cao/packages/uk-ai-advisory.html and /cao/packages/eu-cra-compliance.html (and likely any package detail page with standalone package workflows). Severity: medium. Finding fingerprint: package-detail-omits-standalone-package-members|routes:packages/eu-cra-compliance.html,packages/uk-ai-advisory.html
Evidence
The trusted expected inventory lists standalone package members for both packages:
advisory-package-maintainerbelongs to packageadvisory/aw.yml(UK AI Advisory / Package Maintainer).eu-cra-compliance-package-maintainerbelongs to packageeu-cra-compliance/aw.yml(EU CRA Advisor / Package Maintainer).
The current Actions workflow registry also shows both workflows as active:
UK AI Advisory / Package Maintainer→.github/workflows/advisory-package-maintainer.lock.ymlEU CRA Advisor / Package Maintainer→.github/workflows/eu-cra-compliance-package-maintainer.lock.yml
Rendered package detail pages omit them entirely:
https://githubnext.github.io/central-agentic-ops/cao/packages/uk-ai-advisory.htmlshows only the orchestrator plusUK AI Advisory / Operational Resilienceunder “Workflow topology”.https://githubnext.github.io/central-agentic-ops/cao/packages/eu-cra-compliance.htmlshows the orchestrator plus six workers, but notEU CRA Advisor / Package Maintainer.
By contrast, the global workflows inventory at https://githubnext.github.io/central-agentic-ops/cao/workflows/ does list both package-maintainer workflows with their package membership metadata, so the omission is route-specific rather than source-data absence.
Viewport check: reproduced at both desktop (1440px) and mobile (390px) widths.
Trusted comparison sources:
- deployment:
https://githubnext.github.io/central-agentic-ops/cao/ - expected inventory:
/tmp/gh-aw/agent/cao-dashboard-review/expected-inventory.json - Actions evidence:
https://github.com/githubnext/central-agentic-ops/actions/runs/33217017641
Impact
Operators using a package detail page to audit package scope can incorrectly conclude that a package has no package-maintainer workflow. That hides real coverage, distorts package topology, and can mislead review of package-level responsibility and run activity.
Acceptance criteria
- Package detail routes include every workflow whose trusted inventory associates it with that package, not only orchestrators and workers.
- Standalone package workflows such as package maintainers appear consistently in package topology and any related package reports/insights sections.
- The package detail views for
UK AI AdvisoryandEU CRA Advisorvisibly include their respectivePackage Maintainerworkflows at both desktop and mobile widths.
References
- https://githubnext.github.io/central-agentic-ops/cao/packages/uk-ai-advisory.html
- https://githubnext.github.io/central-agentic-ops/cao/packages/eu-cra-compliance.html
- https://githubnext.github.io/central-agentic-ops/cao/workflows/
Generated by CAO Dashboard Review · pi · gpt54 · 36.4 AIC · ⌖ 5.81 AIC · ⊞ 3.9K · ◷
- expires on Sep 11, 2026, 10:41 PM UTC