github / github/gh-aw

[uk-ai-resilience] Alert-dismissal hygiene gap persists across CodeQL tracking issues (Tier C)

Open
#59,490 0 comments 0 reactions 0 assignees View on GitHub
ai-generated cookie high-priority security
Dominant language
Go
Stars
5.1k
Forks
541
Avg merge
5h 48m
Merged PRs (30d)
773

Description

### Summary

The UK AI Open Code Risk & Resilience Governance workflow (recent-changes scope, 7-day lookback since 2026-09-01) confirms the dismissal-hygiene gap first raised in #57982: several CodeQL code-scanning alerts remain **open** in this run's alert set despite prior tracking issues claiming remediation/closure.

### Tier & risk-scoring

- **Tier: C — Restricted Pending Review**
- Exposure amplification: Medium
- Patchability: High (process fix, no code change required)
- Detectability: Low (staleness is silent — no automated re-check that a "remediated" issue's alert actually closed)
- Operational fragility: High
- Ownership confidence: Medium

### Remediation action

- Audit the 3 CodeQL alerts referenced in #57982 and confirm current state (open vs. dismissed) directly against the code-scanning API.
- For any alert still open despite a closed "remediated" tracking issue, either (a) reopen the tracking issue and re-triage, or (b) explicitly dismiss the alert with a documented reason if it is confirmed fixed/false-positive.
- Add an automated dismissal-hygiene check to the alert-tracking workflow (e.g. a step that verifies code-scanning alert state matches tracking-issue state before allowing issue closure) to prevent recurrence.

### SLA urgency

**High** — this is a process control gap affecting the reliability of the entire alert-remediation loop, not an isolated code defect.

### Related

- Prior report: #57982
- Full governance report: see linked discussion for this run.

> Generated by [UK AI Operational Resilience](https://github.com/github/gh-aw/actions/runs/34245243100) · copilot · auto · 55.1 AIC · ⌖ 12.6 AIC · ⊞ 8.1K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fuk-ai-operational-resilience%22&type=issues)

Contributor guide

Open the contributing guide

Research direction

Start with prior report #57982 and the linked governance discussion, then inspect the three referenced alerts through the code-scanning API and locate the alert-tracking workflow. Done means each alert's state is reconciled with its tracking issue, and the workflow checks this state before allowing closure.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.