[uk-ai-resilience] Untracked code-scanning alert #657 in README.md — smoke-test alert-numbering drift from #564 (Tier B)
- Dominant language
- Go
- Stars
- 5.1k
- Forks
- 541
- Avg merge
- 5h 48m
- Merged PRs (30d)
- 773
Description
### Summary
CodeQL alert `#657` (`workflow-security-finding-1`, severity: warning) in `README.md` has **no open tracking issue**. This is a distinct finding from the previously-tracked `#564` (issue #57981, still open) — the alert number has drifted, which itself is evidence of the alert-numbering/tracking-issue reconciliation gap already flagged in #57982/#59490.
- **Alert**: [#657](https://github.com/github/gh-aw/security/code-scanning/657) — `workflow-security-finding-1`, tool "Smoke Claude", message "Smoke test dummy warning — Run 34294409797"
- **Location**: `README.md` (line 1)
### Tier & risk-scoring
- **Tier: B — Open With Conditions**
- Exposure amplification: Low (appears to be a deliberate smoke-test/dummy warning generated by the "Smoke Claude" workflow's SARIF upload step, not a real content finding)
- Patchability: High
- Detectability: Low (untracked, so it isn't visible in remediation queues; also not linked to the prior #564 tracking issue, so backlog audits may assume it's already covered)
- Operational fragility: Low
- Ownership confidence: Low — no verified CODEOWNERS entry for `README.md` or the smoke-test workflow this run
### Remediation action
- Confirm alert #657 is indeed a smoke-test dummy artifact from `.github/workflows/smoke-claude.lock.yml`'s `upload_code_scanning_sarif` step (not a genuine finding), and dismiss it with a documented reason (e.g., "test/won't fix — smoke test artifact").
- If the smoke-test workflow is expected to keep generating a fresh dummy alert on every run, consider excluding its SARIF category from the standard open-alert governance count, or auto-dismissing smoke-test alerts on upload, to prevent this class from recurring as an untracked/backlog-visible item each cycle.
- Update or close #57981 to avoid confusion between the old (#564) and current (#657) alert numbers for the same rule.
### SLA urgency
**Medium** (14 days) — low real risk, but leaving it untracked degrades confidence in the alert-classification step of the governance loop.
### Discussion report
See the "UK AI Governance: recent-change risk review (2026-09-02 to 2026-09-09)" discussion created by this run for full asset graph, control verification, and risk-scoring context.
> Generated by [UK AI Operational Resilience](https://github.com/github/gh-aw/actions/runs/34370632630) · copilot · auto · 80.5 AIC · ⌖ 6.82 AIC · ⊞ 8.1K · [◷](https://github.com/search?q=repo%3Agithub%2Fgh-aw+is%3Aissue+%22gh-aw-workflow-call-id%3A+github%2Fgh-aw%2Fuk-ai-operational-resilience%22&type=issues)
Contributor guide
Research direction
Start by inspecting .github/workflows/smoke-claude.lock.yml and its upload_code_scanning_sarif step, then compare alert #657 with the previously tracked #564 in issue #57981. Verify whether the README.md finding is a smoke-test artifact. Done means the alert has a documented disposition and the tracking status in #57981 is reconciled; any recurring-alert policy should be addressed separately.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100