You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This cycle's recent-changes scan (7-day lookback, 2026-09-18 to 2026-09-25) covered 117 commits (51 flagged for auth/token/secret/permission/firewall/sandbox keywords), 62 open security-labelled issues, 275 open code-scanning alerts, and 0 open secret-scanning alerts. Two of the three planned sub-agents (asset-tier-classifier, control-verifier) failed twice with a backend model-access error (model not accessible via the chat endpoint); this report proceeds with partial confidence, built from direct gh/git/jq evidence in place of sub-agent synthesis. No ai-risk-scorer dispatch was attempted given the prior two failures — scoring below is derived manually from the same dimensions.
The repository shows no new secret leaks and a healthy volume of CI/dependency hygiene commits, but recent changes touched 10 Go compiler/CLI source files that already carry (or newly surface) high-severity CodeQL findings (go/allocation-size-overflow, go/bad-redirect-check, workflow-go-graphql-injection-sprintf), plus a systemic, well-tracked npm-install non-determinism gap spanning roughly 80 compiled workflow lockfiles (issue #61636). Ownership control is weak: repository-root CODEOWNERS exists but has no path-scoped rules — it names four global owners only, with no entries for pkg/workflow/, pkg/cli/, Dockerfile, or scripts/, matching the already-open gap in issue #61637. Recovery posture is mixed: dependency updates flow through Dependabot weekly across nine ecosystems (good), but a recurring pattern of "untracked/stale code-scanning alert" issues (the uk-ai-resilience label series) shows remediation velocity lagging alert creation — several Tier B/C findings from prior cycles remain open.
Recommendation: prioritize closing the CODEOWNERS gap (unblocks ownership-confidence scoring repo-wide) and land two new, specific untracked-alert issues for the highest-severity, most recently-touched files (experiments_command.go, mcp_github_config.go) rather than opening broader duplicate tracking of the already-covered systemic npm-install and Dockerfile gaps.
Asset graph summary (recent-change scoped)
Recently-changed assets with security-relevant alerts (top 15)
CI trigger tokens, step-output tokens, sandbox runtime removal
no open alert; process/behavior change
n/a
B (needs SDLC follow-up)
Ownership note: CODEOWNERS lists only four global owners repo-wide, with zero path-scoped rules — every asset above currently maps to the same generic ownership signal, which is itself the Tier B finding in #61637.
Tier classification table
Tier assignments
Tier
Definition
Assets in this cycle
A - Open Safe
No material gap
none identified this cycle
B - Open With Conditions
Tracked gap, remediation path known, needs SLA
items 3, 5, 6, 7, 11, 12, 14, 15
C - Restricted Pending Review
Untracked or recurring/stale gap, needs active review
SDLC controls: Could not verify branch-protection API (403 - insufficient token scope for this read-only run). Weekly Dependabot cadence exists across nine ecosystems (github-actions, gomod, npm x3, pip, docker x2) per .github/dependabot.yml - a positive SDLC/dependency signal.
Rationale: the two untracked findings (experiments_command.go, mcp_github_config.go) score highest priority for new issue creation because they combine high CodeQL severity, recent code churn, and zero existing tracking - unlike the other Tier B/C items which already have open issues and only need SLA/ownership follow-through.
Reconcile closed tracking issues vs. still-open CodeQL alerts
medium
Exception register
No new exceptions requested this cycle. Existing uk-ai-resilience Tier B/C tracking issues remain the governance record; none require temporary hidden-repo or bypass exceptions.
Operational metrics baseline
MTTR proxy: Not independently measurable this cycle (branch-protection/issue-timeline API reads were rate/permission limited); qualitative signal is "improving but lagging" per alert-dismissal hygiene issues.
Ownership coverage: 0 percent of security-sensitive compiler/CLI paths have path-scoped CODEOWNERS (four global owners only).
Unsupported dependency ratio: Not directly measurable this cycle; Dependabot covers nine ecosystems weekly, suggesting low unsupported-dependency risk overall.
Exception aging: 0 active exceptions.
Exposure without recovery capability: 244/275 (89 percent) of open alerts are the single systemic npm-install non-determinism class - high exposure concentration but a known, tracked remediation path (Tier B, not Tier D).
Limitation disclosure: asset-tier-classifier and control-verifier sub-agents failed twice on a backend model-access error and were not retried a third time per guardrails; ai-risk-scorer was not dispatched given the pattern. All findings above were reconstructed via direct gh/git/jq reads and should be treated as partial-confidence pending a successful sub-agent run in a future cycle.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Executive summary
This cycle's recent-changes scan (7-day lookback, 2026-09-18 to 2026-09-25) covered 117 commits (51 flagged for auth/token/secret/permission/firewall/sandbox keywords), 62 open security-labelled issues, 275 open code-scanning alerts, and 0 open secret-scanning alerts. Two of the three planned sub-agents (
asset-tier-classifier,control-verifier) failed twice with a backend model-access error (model not accessible via the chat endpoint); this report proceeds with partial confidence, built from directgh/git/jqevidence in place of sub-agent synthesis. Noai-risk-scorerdispatch was attempted given the prior two failures — scoring below is derived manually from the same dimensions.The repository shows no new secret leaks and a healthy volume of CI/dependency hygiene commits, but recent changes touched 10 Go compiler/CLI source files that already carry (or newly surface) high-severity CodeQL findings (
go/allocation-size-overflow,go/bad-redirect-check,workflow-go-graphql-injection-sprintf), plus a systemic, well-tracked npm-install non-determinism gap spanning roughly 80 compiled workflow lockfiles (issue #61636). Ownership control is weak: repository-rootCODEOWNERSexists but has no path-scoped rules — it names four global owners only, with no entries forpkg/workflow/,pkg/cli/,Dockerfile, orscripts/, matching the already-open gap in issue #61637. Recovery posture is mixed: dependency updates flow through Dependabot weekly across nine ecosystems (good), but a recurring pattern of "untracked/stale code-scanning alert" issues (theuk-ai-resiliencelabel series) shows remediation velocity lagging alert creation — several Tier B/C findings from prior cycles remain open.Recommendation: prioritize closing the CODEOWNERS gap (unblocks ownership-confidence scoring repo-wide) and land two new, specific untracked-alert issues for the highest-severity, most recently-touched files (
experiments_command.go,mcp_github_config.go) rather than opening broader duplicate tracking of the already-covered systemic npm-install and Dockerfile gaps.Asset graph summary (recent-change scoped)
Recently-changed assets with security-relevant alerts (top 15)
Ownership note: CODEOWNERS lists only four global owners repo-wide, with zero path-scoped rules — every asset above currently maps to the same generic ownership signal, which is itself the Tier B finding in #61637.
Tier classification table
Tier assignments
Control verification gaps
CODEOWNERSexists at repo root but has no path-scoped entries forpkg/workflow/,pkg/cli/,Dockerfile, orscripts/- confirmed by direct file read. This matches open issue [uk-ai-resilience] Missing .github/CODEOWNERS for security-sensitive compiler/CLI paths (Tier B) #61637 and is the single largest ownership-confidence gap found..github/dependabot.yml- a positive SDLC/dependency signal.github-token-for-extra-empty-commit: noneto keep GH_AW_CI_TRIGGER_TOKEN out of compiled workflows #62416, push-to-PR-branch token retry push_to_pull_request_branch: retry transient workflows-scope timeout on the primary push path #62668) - good remediation-in-progress signal, no new gap found.uk-ai-resiliencetracking issues ([uk-ai-resilience] Alert-dismissal hygiene gap persists across CodeQL tracking issues (Tier C) #59490, [uk-ai-resilience] Alert-dismissal hygiene gap: 3 CodeQL alerts remain open despite closed/remediated tracking issues (Tier C) #57982) explicitly flag alert-dismissal hygiene gaps - CodeQL alerts remaining open despite remediated or closed tracking issues - indicating remediation closure lags remediation action.Risk-scoring table and rationale
Manual risk scoring (sub-agent unavailable - partial confidence)
Rationale: the two untracked findings (
experiments_command.go,mcp_github_config.go) score highest priority for new issue creation because they combine high CodeQL severity, recent code churn, and zero existing tracking - unlike the other Tier B/C items which already have open issues and only need SLA/ownership follow-through.Remediation queue with SLAs
Exception register
No new exceptions requested this cycle. Existing
uk-ai-resilienceTier B/C tracking issues remain the governance record; none require temporary hidden-repo or bypass exceptions.Operational metrics baseline
Limitation disclosure:
asset-tier-classifierandcontrol-verifiersub-agents failed twice on a backend model-access error and were not retried a third time per guardrails;ai-risk-scorerwas not dispatched given the pattern. All findings above were reconstructed via directgh/git/jqreads and should be treated as partial-confidence pending a successful sub-agent run in a future cycle.All reactions