[uk ai resilience] UK AI Open Code Risk & Resilience Governance — 2026-09-28 #64042
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by UK AI Operational Resilience. A newer discussion is available at Discussion #64297. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Executive summary
UK AI Open Code Risk & Resilience Governance review of github/gh-aw, 7-day recent-change lookback (since 2026-09-21T15:37:05Z): 139 commits (91 by
Copilot, 43 bygithub-actions[bot]— heavy automation-driven velocity), 57 security-signal commits, 64 open security issues, 277 open code-scanning alerts, 0 open secret-scanning alerts.Governance verdict: the classification → control-verification → risk-scoring → remediation loop is largely functioning — the vast majority of currently open code-scanning alerts (259 of 277, ~93%) already have matching
[uk-ai-resilience]tracking issues from prior runs, and no secrets are exposed. However, this run identified 2 newly-surfaced, untracked CodeQL alerts in files touched today (2026-09-28) by the automated commit stream, plus one systemic ownership gap (noCODEOWNERS) that continues to depress detectability/ownership confidence across all findings. No repository-hiding or concealment action is recommended anywhere in this review, consistent with guidance.Note on this run: the three governance sub-agents (
asset-tier-classifier,control-verifier,ai-risk-scorer) were unavailable this run (model-access error, retried once per guardrail). Analysis below was compiled directly from precomputed evidence with equivalent rigor; confidence is noted per finding.Asset graph summary (recent-change scoped)
Segments, runtime areas, and dependencies touched in the lookback window
pkg/workflow/create_code_scanning_alert.go5fe849dand prior in-window)security-events:writepkg/workflow/github_app_requirements.gopkg/cli/project_command.gopkg/cli,pkg/workflow(broad).github/workflows/*.lock.yml(100+ compiled workflows)Dockerfile(root)FROM alpine:3.24confirmed unpinned by SHA.github/workflows/format-and-commit.ymlactions/setup-node@...missing explicitnode-versionscripts/ensure-docs-slide-pdf.jspkg/workflow/mcp_*.go)Ownership signals: no
.github/CODEOWNERSexists (confirmed absent on disk). Human maintainers appearing on security-signal commits:pelikhan,David Slater,Landon Cox; bulk of window volume is bot/agent-authored (Copilot, github-actions[bot], dependabot[bot]) with human co-author sign-off on security fixes.Tier classification table
Tier assignments for this run's high-priority changed areas
pkg/workflow/create_code_scanning_alert.go:110(alerts #944, #945 — allocation-size-overflow)pkg/workflow/github_app_requirements.go:151(alert #941 — bad-redirect-check)HasPrefix(name, "/")string-prefix checks misclassified as redirect validation) but is itself untracked as an individual alert.github/CODEOWNERS(#61637, still open)format-and-commit.ymlmissing node-version pin (#61378, tracked)pkg/cli/project_command.goGraphQL Sprintf injection (#52749, tracked)scripts/ensure-docs-slide-pdf.jsuntrusted-data-to-file (#53737/#62692, tracked)Control verification gaps
CODEOWNERSfor security-sensitivepkg/cli/pkg/workflowpaths (#61637 open)pr-actionrules run on every push; 57 security-signal commits show active remediation cadenceRisk-scoring table and rationale
Rationale: none of the new findings are exploit-imminent (compiler-internal Go code, not attacker-reachable network surface), but leaving them untracked breaks the audit trail this governance loop depends on, and the missing CODEOWNERS file compounds every other ownership-confidence score in the backlog.
Remediation queue with SLAs
create_code_scanning_alert.go:110len(tokenMintSteps)+len(uploadSteps)with bounds check or widen toint64beforemake([]string, 0, ...); open/attach tracking issuegithub_app_requirements.go:151isSafeRelativePath-style helper; if genuine, add////\rejection.github/CODEOWNERScoveringpkg/cli/,pkg/workflow/Exception register
None. No temporary exceptions requested or granted in this run; no repository-hiding recommended.
Operational metrics baseline
All reactions