Skip to content

[Alert] Smart Alerts β€” 2026-03-18 06:36 UTC (Run 23232290898)Β #340

@github-actions

Description

@github-actions

Scan time: 2026-03-18T06:36 UTC | Previous alert: #337 (2026-03-18 00:55 UTC, ~5.7h ago)


πŸ”΄ CRITICAL β€” Security (DAY 5+, ESCALATING β€” ZERO RESPONSE, 18+ ALERT CYCLES)

subcog: AWS Access Key Still Publicly Exposed (~100 hours)

Field Value
Repo subcog (public)
Issue subcog#153
File src/security/mod.rs @ commit ad6f61a6
First detected 2026-03-14T02:27 UTC
Age ~100 hours (+6h since last alert)
Response ❌ Zero β€” 0 comments, issue still open, no commits, no remediations across 18+ alert cycles

This is now Day 5+ of an active public credential exposure. No remediation has occurred across 18+ automated alert cycles.

Immediate actions required (in order):

  1. Revoke the AWS Access Key at console.aws.amazon.com β€” do this first, takes 30 seconds
  2. Remove the key from src/security/mod.rs and push a fix commit
  3. Purge from git history: git filter-repo --path src/security/mod.rs --invert-paths or BFG Repo Cleaner
  4. Rotate all services depending on those credentials
  5. Close subcog#153 with a remediation note

πŸ”΄ Critical β€” CI Failures (6 workflows, 5 repos) β€” ONGOING, UNCHANGED

All 6 CI failures from #337 remain unresolved. A new CI Health Report (#339) generated at ~05:24 UTC today confirms all failures are still active. github-project-manager PR #4 still open β€” not merged.

Repo Workflow Age Root Cause Action
vscode-git-adr CI ~20d ⚠️ actions/upload-artifact v6β†’v7 breaking change Update workflow to v7 API
sdlc-quality CI ~17d Broken since chore: update dependabot configuration (2026-03-01) Investigate config change
atlatl-spec Validate Specification ~17d Invalid <br/> in Mermaid sequence diagram Fix diagram syntax
atlatl CI Checks ~13d Clippy 1.94 strict lints + broken doc links Fix lints manually
atlatl Pipeline ~12d ONNX Runtime prebuilt targets dropped Review CI matrix
github-project-manager Agentic Maintenance ~7d github/gh-aw bump Merge PR #4 (gh-aw 0.58.3, ready now)

⚑ Quick win (5 min): Merge github-project-manager PR #4 β€” clears one CI failure immediately.


βœ… Checks Within Threshold

Check Status
Issue spike (>5 new in 6h window) βœ… 2 automated issues only (CI health report + prior smart alert) β€” below threshold
Review backlog (>10/reviewer) βœ… Open PRs well within threshold
Stale critical/high labeled items βœ… No new labeled critical/high items (security tracked above)
New CI failures (default branch) βœ… None new this cycle

Summary

Severity Count Delta from #337
πŸ”΄ Critical (security) 1 +6h exposure β€” now ~100h total, Day 5+, 18+ alert cycles with ZERO response
πŸ”΄ Critical (CI β€” ongoing) 6 workflows / 5 repos No change β€” PR #4 still unmerged, CI Health Report #339 confirms
🟑 Open PRs β‰₯4 awaiting review No change
βœ… Healthy 15 repos β€”

Top priorities:

  1. 🚨 Revoke subcog AWS credentials IMMEDIATELY β€” Day 5+, zero response across 18+ alert cycles
  2. βœ… Merge github-project-manager PR #4 (5 minutes, clears one CI failure)
  3. πŸ”§ Fix vscode-git-adr CI (oldest at ~20d β€” upload-artifact v6β†’v7 API update)
  4. πŸ”§ Fix sdlc-quality CI (~17d β€” investigate dependabot config from 2026-03-01)

gh-aw-workflow-id: smart-alerts

Generated by Smart Alerts Β· β—·

Generated by Smart Alerts Β· β—·

Metadata

Metadata

Assignees

No one assigned

    Labels

    gpm/alertGPM automated alert

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions