You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk-ai-resilience] Untracked recurrence of code-scanning alert #663 in ensure-docs-slide-pdf.js (Tier C) #62692
Code-scanning alert #663 (js/http-to-file-access, severity: warning, created 2026-08-28) at scripts/ensure-docs-slide-pdf.js:197 is a recurrence of a previously tracked and closed finding: the same rule at the same file was previously alert #654, tracked by issue #53737, and #654 has since been dismissed/closed. Alert #663 resurfaced at the same location with no matching open tracking issue — the remediation applied for #654 either lacked durable validation or was reverted/bypassed, breaking the classification → control-verification → remediation loop for this recent-changes-scoped review (7-day lookback since 2026-09-15).
Tier and risk-scoring breakdown
Tier: C — Restricted Pending Review
Dimension
Rating
Exposure amplification
Low (docs build script only, not user-facing runtime)
Patchability
High (validate content-type/size/checksum before writing network response to disk)
Detectability
Low — no regression test/lint currently prevents this pattern from reappearing; only re-caught by code scanning after the fact
Operational fragility
Medium (recurrence itself is evidence of a control-verification gap in the SDLC loop)
Ownership confidence
Medium
Finding
CodeQL flags that network response data is written to the file system in scripts/ensure-docs-slide-pdf.js without further validation, which "allows arbitrary file upload and might indicate a backdoor" per the rule description (js/http-to-file-access). This is the same finding class as the prior alert #654 (tracked/closed via #53737), now recurring as alert #663 at the same file/line class.
Remediation action
Re-apply or extend content validation in scripts/ensure-docs-slide-pdf.js: verify content-type, enforce an expected size limit, and/or checksum the expected artifact before trusting the raw HTTP response body written to disk.
Add a regression test or static-analysis guard so this specific pattern cannot silently reappear after remediation, closing the SDLC verification gap that allowed [Custom Engine Test] Test Issue Created by Custom Engine #654's fix to not prevent recurrence.
SLA urgency: High
Governance report
Full asset graph, control-verification findings, and risk-scoring context are in the linked governance discussion report: "UK AI Open Code Risk & Resilience Governance — Weekly Review (2026-09-22)".
Summary
Code-scanning alert #663 (
js/http-to-file-access, severity: warning, created 2026-08-28) atscripts/ensure-docs-slide-pdf.js:197is a recurrence of a previously tracked and closed finding: the same rule at the same file was previously alert #654, tracked by issue #53737, and #654 has since been dismissed/closed. Alert #663 resurfaced at the same location with no matching open tracking issue — the remediation applied for #654 either lacked durable validation or was reverted/bypassed, breaking the classification → control-verification → remediation loop for this recent-changes-scoped review (7-day lookback since 2026-09-15).Tier and risk-scoring breakdown
Finding
CodeQL flags that network response data is written to the file system in
scripts/ensure-docs-slide-pdf.jswithout further validation, which "allows arbitrary file upload and might indicate a backdoor" per the rule description (js/http-to-file-access). This is the same finding class as the prior alert #654 (tracked/closed via #53737), now recurring as alert #663 at the same file/line class.Remediation action
scripts/ensure-docs-slide-pdf.js: verify content-type, enforce an expected size limit, and/or checksum the expected artifact before trusting the raw HTTP response body written to disk.SLA urgency: High
Governance report
Full asset graph, control-verification findings, and risk-scoring context are in the linked governance discussion report: "UK AI Open Code Risk & Resilience Governance — Weekly Review (2026-09-22)".