Skip to content

Daily Org Oversight Report — 2026-05-19 (UTC) #3311

@fro-bot

Description

@fro-bot

Scope: all repositories in the fro-bot GitHub organization. Data pulled via gh at run start. Links only; no content duplication.

Previous report: #3304 (no action taken since — backlog items below are largely carryover).

Summary metrics

Metric Count Δ vs yesterday
Repositories scanned 5 (.github, agent, fro-bot.github.io, systematic, tokentoilet archived)
New issues (last 24h, org-wide) 6 (2 op logs, 1 autohealing, 1 oversight, 2 duplicate collaborator-grant alerts) +3
Open PRs (org-wide) 9 +1
Aging PRs (>7d no activity) 1 0
Stale PRs (>14d no activity) 1 0
Stale issues (>30d no activity) 2 0
Operational-log issues >14d (deletion candidates) 20+
Failing main-branch workflows (latest run) 1 (agentAuto Release, still red since 2026-03-22) 0
Open code-scanning alerts 8 (.github=3, agent=5) 0
Open Dependabot alerts 0 0
Unassigned bugs 0 (no bug label exists in org) 0

Critical items

Repo Item Link Recommended action
fro-bot/.github Duplicate unsolicited-collaborator-grant alerts from bfra-me — 4 repos: bfra-me/.github, bfra-me/ha-addon-repository, bfra-me/renovate-action, +1. Two identical issues opened within 0s of each other (reconciler emitted twice). #3307, #3308 Close one as duplicate, decide accept/decline on the grants. Also: the rollup emitter has a deduplication bug — investigate why it fired twice at 08:54:50Z.
fro-bot/agent Auto Release workflow still failing on main since 2026-03-22 (now ~58d red). Same call as yesterday — Prepare Release PR is doing the actual work. run 23399265449 Delete the workflow or fix it. Carryover from #3304.
fro-bot/.github Scorecard: Branch-Protection, CII-Best-Practices, Fuzzing code scanning Policy debt. Carryover.
fro-bot/agent Scorecard: SAST, Fuzzing, CII-Best-Practices, Code-Review, Branch-Protection code scanning Policy debt. Carryover.

No new Dependabot alerts. No broken release pipelines blocking shipping.

Aging PRs (>7d no activity)

Repo PR Age Author
fro-bot/systematic #2 feat(deps): configure Renovate 23d app/fro-bot

All other 8 open PRs were updated within the last 24h (Renovate batch on agent and .github, plus the active docs PR on .github). The backlog is not growing.

Stale issues (>30d no activity)

Repo Issue Age Recommended next step
fro-bot/systematic #1 Enable code scanning (CodeQL / Scorecard) for coverage parity 71d Schedule CodeQL enablement or close as won't-fix. Carryover.
fro-bot/fro-bot.github.io #1 Enable code scanning (CodeQL / Scorecard) for coverage parity 71d Static site — likely close as not-applicable. Carryover.

Op-log entropy increasing: 20+ "Fro Bot operational log" issues are now >14d old in fro-bot/.github, oldest being #3166 at 26d. Yesterday's recommended auto-close (14d retention) is unimplemented; the noise floor is climbing daily.

Unassigned bugs or high-signal issues

No bug-labeled issues exist org-wide. Carryover: the label taxonomy needs a baseline. The two reconcile:pending-review issues (#3307, #3308) are the closest thing to a high-signal unassigned item today — they're security-adjacent (collaborator access) and have no assignee.

Repo hotspots

  1. fro-bot/.github — 49 open issues (40 operational logs + 2 duplicate collaborator-grant alerts + noise), 3 open PRs. Issue volume jumped +5 in 24h; ~80% is bot-authored process artifact.
  2. fro-bot/agent — 5 open PRs (all Renovate or release), 2 open issues. Active churn, healthy.
  3. fro-bot/systematic — Stalest PR in org (fix: add @fro-bot as a collaborator to prevent it from being "removed" #2, 23d), 70d-cold issue (feat: set default settings #1). Same call as yesterday: decide if this repo is alive.

Recommended actions (checklist)

  • New (P0): Triage the bfra-me collaborator grants in #3307 / #3308. Close one as duplicate. Accept or decline the four repos. This is org-perimeter security work.
  • New: Fix the reconciler's double-emission bug (two identical rollups at 08:54:50Z). The dedup gate failed.
  • Carryover: Implement 14d auto-close for "Fro Bot operational log" + "Daily Autohealing Report" patterns. Op-log queue is now 40 issues deep and growing ~2/day.
  • Carryover: Decide fro-bot/agentAuto Release (delete or fix). 58 days red.
  • Carryover: Resolve fro-bot/systematic#2 (Renovate config) — merge or close at 23d.
  • Carryover: Resolve fro-bot/systematic#1 and fro-bot/fro-bot.github.io#1 — both 71d cold on the same CodeQL question.
  • Carryover: Triage the 8 Scorecard alerts as policy debt or enforce Branch-Protection baseline.
  • Carryover: Establish a bug label baseline on .github and agent.

Run Summary

  • Event: schedule
  • Repo: fro-bot/.github
  • Ref: refs/heads/main
  • Run ID: 26075384343
  • Cache: hit
  • Sessions used: ses_1c6ba9e0dffe7oK9VLD2oWDr9c (prior thread)
  • Logical Thread: schedule-898cd73a
  • Mode: branch-pr (single summary issue)
  • Repos scanned: 5
  • Data sources: gh issue list, gh pr list, gh api actions/workflows, gh api code-scanning/alerts, gh api dependabot/alerts

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions