Skip to content

[uk-ai-resilience] Alert-dismissal hygiene gap: 3 CodeQL alerts remain open despite closed/remediated tracking issues (Tier C) #57982

Description

@github-actions

Tier: C — Restricted Pending Review (process gap, not live code risk)

Finding: Three open CodeQL alerts (#669/#668 in pkg/workflow/graders_config.go, #667 in pkg/cli/add_package_manifest_includes.go, #653 actionlint workflow-out-of-context) each have a pre-existing tracking issue (#57472, #54037, #57728 respectively) asserting the underlying finding is a false positive or already remediated in code — yet all three alerts remain open/undismissed in code scanning. This is a recurring alert-lifecycle hygiene gap distinct from the individual code findings themselves: it inflates the open-alert count, obscures true remediation status in dashboards, and increases MTTR-proxy metrics without reflecting live risk.

Risk-scoring breakdown (aggregate across the 3 alerts)

Dimension Rating
Exposure amplification Low
Patchability High (fix already believed complete per linked issues)
Detectability High (alerts are visible; the gap is in closure, not detection)
Operational fragility Low
Ownership confidence Low — no CODEOWNERS file to route alert-dismissal responsibility

Remediation action

For each of #57472, #54037, #57728: verify the referenced fix is merged and live, then dismiss the corresponding CodeQL alert(s) with an explicit, documented reason (e.g., "false positive" or "fixed"). Do not leave alerts open once root-cause issues are closed. Consider adding a lightweight periodic check (or workflow) that flags alerts whose linked tracking issue is closed but the alert itself remains open, to prevent recurrence.

SLA urgency: high (7 days) — this is a low-effort, high-value fix to remediation velocity and dashboard accuracy.

Discussion report

See the full UK AI Governance: Recent-Changes Risk & Resilience Review (2026-09-02) discussion for the complete asset graph, control verification, and risk-scoring context, including the operational metrics baseline (MTTR proxy, ownership coverage).

Generated by UK AI Operational Resilience · copilot · auto · 43.2 AIC · ⌖ 6.81 AIC · ⊞ 8.1K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions