[uk ai resilience] UK AI Open Code Risk & Resilience Governance — Weekly Report 2026-07-24 #47820
Closed
Replies: 1 comment
|
This discussion has been marked as outdated by UK AI Operational Resilience. A newer discussion is available at Discussion #48404. |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
UK AI Open Code Risk & Resilience Governance
Repository: github/gh-aw | Period: 2026-07-17 → 2026-07-24 | Run: §30107107922
Executive Summary
The repository is operating at high velocity (354 commits in 7 days, ~50/day) driven largely by Copilot SWE agent. Governance posture is Tier B — Open With Conditions. Two actionable code-scanning findings remain open (GraphQL injection in CLI, JS network-to-file write). The firewall agent container image (
agent:0.27.41) carries a critical Go stdlib vulnerability (GO-2026-4337) and a severe Go runtime version lag, requiring urgent upgrade. No secrets were exposed. Dependency license noncompliance persists in container images.Asset Graph Summary (Recent-Change Scoped)
pkg/cli/project_command.gofmt.Sprintf(alerts #651, #652)ghcr.io/github/gh-aw-firewall/agent:0.27.41ghcr.io/github/gh-aw-firewall/api-proxy:0.27.41@opentelemetry/core); 34 denied licensesscripts/ensure-docs-slide-pdf.js.github/workflows/(lock.yml fleet)pkg/linters/pkg/actionpins/Tier Classification Table
Control Verification
.envleaks detectedRisk-Scoring Table
project_command.goensure-docs-slide-pdf.js@opentelemetry/coreCVEScores 1–5 (5 = worst). Overall tier = worst-case dimension result.
Remediation Queue with SLAs
project_command.go)fmt.Sprintf+escapeGraphQLString()with parameterised GraphQL variables@opentelemetry/coreGHSA-8988-4f7v-96qf (fixable)@opentelemetry/coreto ≥2.8.0 in firewall npm depsensure-docs-slide-pdf.js)Exception Register
No formal exceptions exist at this time. The following items require expedited triage:
ownerinputOperational Metrics Baseline
Positive Signals This Week
no-child-process-interpolated-commandfor shell injection prevention (eslint-factory: addno-child-process-interpolated-commandto catch shell-injection command strings #47555)docker/build-push-actionpinned to commit SHA (Pin docker/build-push-action to commit SHA (CodeQL alert #625) #47334)References:
All reactions