Tier: C — Restricted Pending Review (process gap, not live code risk)
Finding: Three open CodeQL alerts (#669/#668 in pkg/workflow/graders_config.go, #667 in pkg/cli/add_package_manifest_includes.go, #653 actionlint workflow-out-of-context) each have a pre-existing tracking issue (#57472, #54037, #57728 respectively) asserting the underlying finding is a false positive or already remediated in code — yet all three alerts remain open/undismissed in code scanning. This is a recurring alert-lifecycle hygiene gap distinct from the individual code findings themselves: it inflates the open-alert count, obscures true remediation status in dashboards, and increases MTTR-proxy metrics without reflecting live risk.
Risk-scoring breakdown (aggregate across the 3 alerts)
| Dimension |
Rating |
| Exposure amplification |
Low |
| Patchability |
High (fix already believed complete per linked issues) |
| Detectability |
High (alerts are visible; the gap is in closure, not detection) |
| Operational fragility |
Low |
| Ownership confidence |
Low — no CODEOWNERS file to route alert-dismissal responsibility |
Remediation action
For each of #57472, #54037, #57728: verify the referenced fix is merged and live, then dismiss the corresponding CodeQL alert(s) with an explicit, documented reason (e.g., "false positive" or "fixed"). Do not leave alerts open once root-cause issues are closed. Consider adding a lightweight periodic check (or workflow) that flags alerts whose linked tracking issue is closed but the alert itself remains open, to prevent recurrence.
SLA urgency: high (7 days) — this is a low-effort, high-value fix to remediation velocity and dashboard accuracy.
Discussion report
See the full UK AI Governance: Recent-Changes Risk & Resilience Review (2026-09-02) discussion for the complete asset graph, control verification, and risk-scoring context, including the operational metrics baseline (MTTR proxy, ownership coverage).
Generated by UK AI Operational Resilience · copilot · auto · 43.2 AIC · ⌖ 6.81 AIC · ⊞ 8.1K · ◷
Tier: C — Restricted Pending Review (process gap, not live code risk)
Finding: Three open CodeQL alerts (#669/#668 in
pkg/workflow/graders_config.go, #667 inpkg/cli/add_package_manifest_includes.go, #653 actionlintworkflow-out-of-context) each have a pre-existing tracking issue (#57472, #54037, #57728 respectively) asserting the underlying finding is a false positive or already remediated in code — yet all three alerts remain open/undismissed in code scanning. This is a recurring alert-lifecycle hygiene gap distinct from the individual code findings themselves: it inflates the open-alert count, obscures true remediation status in dashboards, and increases MTTR-proxy metrics without reflecting live risk.Risk-scoring breakdown (aggregate across the 3 alerts)
CODEOWNERSfile to route alert-dismissal responsibilityRemediation action
For each of #57472, #54037, #57728: verify the referenced fix is merged and live, then dismiss the corresponding CodeQL alert(s) with an explicit, documented reason (e.g., "false positive" or "fixed"). Do not leave alerts open once root-cause issues are closed. Consider adding a lightweight periodic check (or workflow) that flags alerts whose linked tracking issue is closed but the alert itself remains open, to prevent recurrence.
SLA urgency: high (7 days) — this is a low-effort, high-value fix to remediation velocity and dashboard accuracy.
Discussion report
See the full UK AI Governance: Recent-Changes Risk & Resilience Review (2026-09-02) discussion for the complete asset graph, control verification, and risk-scoring context, including the operational metrics baseline (MTTR proxy, ownership coverage).