Repository navigation
[uk ai resilience] [uk-ai-resilience] UK AI open code risk report - 2026-10-06 #66213
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by UK AI Operational Resilience. A newer discussion is available at Discussion #66613. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive summary
Lookback 7 days (since 2026-09-29): 281 commits (155 Copilot, 50 human, 43 bot, 24 dependabot), 114 security-signal commits, 42 open security issues, 279 open code-scanning alerts (0 secret-scanning). No Tier D candidates. Most risk is supply-chain determinism (non-pinned installs in compiled workflows) and unowned changes to security-sensitive paths. Sub-agents were not dispatched; analysis was performed directly from the pre-computed data (limitation: lower confidence on ownership signals).
Asset graph summary (recent-change scoped)
Asset graph
.github/workflows/*.lock.yml.github/scripts/*.cjs,scripts/*.mjsjs/insecure-temporary-filealerts (new 2026-10-05)pkg/workflow,pkg/cli(Go)go/bad-redirect-check, 2 GraphQL sprintf alerts (project_command.go:269,272)Dockerfilealpine:3.24not SHA-pinned (alert #940)Ownership: no
.github/CODEOWNERSpresent (see #61637).Tier classification
Tiers
Control verification gaps
Risk scoring
Scores (1 low – 5 high risk)
Remediation queue
Human-review trigger: any change to release/token-minting workflows or low ownership confidence.
Exception register
None. No hidden-repo exceptions recommended.
Operational metrics baseline
All reactions