github / github/gh-aw

[uk-ai-resilience] Alert-dismissal hygiene gap: 3 CodeQL alerts remain open despite closed/remediated tracking issues (Tier C)

Open
#57,982 5 comments 0 reactions 0 assignees View on GitHub
ai-generated cookie high-priority security uk-ai-resilience
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 46m
Merged PRs (30d)
760

Description

### Tier: C — Restricted Pending Review (process gap, not live code risk)

**Finding:** Three open CodeQL alerts (#669/#668 in `pkg/workflow/graders_config.go`, #667 in `pkg/cli/add_package_manifest_includes.go`, #653 actionlint `workflow-out-of-context`) each have a pre-existing tracking issue (#57472, #54037, #57728 respectively) asserting the underlying finding is a false positive or already remediated in code — yet all three alerts remain **open/undismissed** in code scanning. This is a recurring alert-lifecycle hygiene gap distinct from the individual code findings themselves: it inflates the open-alert count, obscures true remediation status in dashboards, and increases MTTR-proxy metrics without reflecting live risk.

### Risk-scoring breakdown (aggregate across the 3 alerts)
| Dimension | Rating |
|---|---|
| Exposure amplification | Low |
| Patchability | High (fix already believed complete per linked issues) |
| Detectability | High (alerts are visible; the gap is in closure, not detection) |
| Operational fragility | Low |
| Ownership confidence | Low — no `CODEOWNERS` file to route alert-dismissal responsibility |

### Remediation action
For each of #57472, #54037, #57728: verify the referenced fix is merged and live, then dismiss the corresponding CodeQL alert(s) with an explicit, documented reason (e.g., "false positive" or "fixed"). Do not leave alerts open once root-cause issues are closed. Consider adding a lightweight periodic check (or workflow) that flags alerts whose linked tracking issue is closed but the alert itself remains open, to prevent recurrence.

**SLA urgency:** high (7 days) — this is a low-effort, high-value fix to remediation velocity and dashboard accuracy.

### Discussion report
See the full UK AI Governance: Recent-Changes Risk & Resilience Review (2026-09-02) discussion for the complete asset graph, control verification, and risk-scoring context, including the operational metrics baseline (MTTR proxy, ownership coverage).

> Generated by [UK AI Operational Resilience](https://github.com/github/gh-aw/actions/runs/33649272244) · copilot · auto · 43.2 AIC · ⌖ 6.81 AIC · ⊞ 8.1K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fuk-ai-operational-resilience%22&type=issues)

Contributor guide

Open the contributing guide

Research direction

Review tracking issues #57472, #54037, and #57728, along with the referenced locations in pkg/workflow/graders_config.go and pkg/cli/add_package_manifest_includes.go. Verify each fix is merged and live, then dismiss alerts #669, #668, #667, and #653 with documented reasons. Done means the relevant alerts are no longer open; consider a periodic check for this mismatch if the scope includes recurrence prevention.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions, go
Domain
ci-cd, devops, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.