[uk-ai-resilience] Alert-dismissal hygiene gap persists across CodeQL tracking issues (Tier C)
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Summary
The UK AI Open Code Risk & Resilience Governance workflow (recent-changes scope, 7-day lookback since 2026-09-01) confirms the dismissal-hygiene gap first raised in #57982: several CodeQL code-scanning alerts remain **open** in this run's alert set despite prior tracking issues claiming remediation/closure.
### Tier & risk-scoring
- **Tier: C — Restricted Pending Review**
- Exposure amplification: Medium
- Patchability: High (process fix, no code change required)
- Detectability: Low (staleness is silent — no automated re-check that a "remediated" issue's alert actually closed)
- Operational fragility: High
- Ownership confidence: Medium
### Remediation action
- Audit the 3 CodeQL alerts referenced in #57982 and confirm current state (open vs. dismissed) directly against the code-scanning API.
- For any alert still open despite a closed "remediated" tracking issue, either (a) reopen the tracking issue and re-triage, or (b) explicitly dismiss the alert with a documented reason if it is confirmed fixed/false-positive.
- Add an automated dismissal-hygiene check to the alert-tracking workflow (e.g. a step that verifies code-scanning alert state matches tracking-issue state before allowing issue closure) to prevent recurrence.
### SLA urgency
**High** — this is a process control gap affecting the reliability of the entire alert-remediation loop, not an isolated code defect.
### Related
- Prior report: #57982
- Full governance report: see linked discussion for this run.
> Generated by [UK AI Operational Resilience](https://github.com/github/gh-aw/actions/runs/34245243100) · copilot · auto · 55.1 AIC · ⌖ 12.6 AIC · ⊞ 8.1K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fuk-ai-operational-resilience%22&type=issues)
Contributor guide
Research direction
Start with prior report #57982 and the linked governance discussion, then inspect the three referenced alerts through the code-scanning API and locate the alert-tracking workflow. Done means each alert's state is reconciled with its tracking issue, and the workflow checks this state before allowing closure.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100