Skip to content

[uk-ai-resilience] Untracked recurrence of code-scanning alert #663 in ensure-docs-slide-pdf.js (Tier C) #62692

Description

@github-actions

Summary

Code-scanning alert #663 (js/http-to-file-access, severity: warning, created 2026-08-28) at scripts/ensure-docs-slide-pdf.js:197 is a recurrence of a previously tracked and closed finding: the same rule at the same file was previously alert #654, tracked by issue #53737, and #654 has since been dismissed/closed. Alert #663 resurfaced at the same location with no matching open tracking issue — the remediation applied for #654 either lacked durable validation or was reverted/bypassed, breaking the classification → control-verification → remediation loop for this recent-changes-scoped review (7-day lookback since 2026-09-15).

Tier and risk-scoring breakdown

  • Tier: C — Restricted Pending Review
Dimension Rating
Exposure amplification Low (docs build script only, not user-facing runtime)
Patchability High (validate content-type/size/checksum before writing network response to disk)
Detectability Low — no regression test/lint currently prevents this pattern from reappearing; only re-caught by code scanning after the fact
Operational fragility Medium (recurrence itself is evidence of a control-verification gap in the SDLC loop)
Ownership confidence Medium

Finding

CodeQL flags that network response data is written to the file system in scripts/ensure-docs-slide-pdf.js without further validation, which "allows arbitrary file upload and might indicate a backdoor" per the rule description (js/http-to-file-access). This is the same finding class as the prior alert #654 (tracked/closed via #53737), now recurring as alert #663 at the same file/line class.

Remediation action

  • Re-apply or extend content validation in scripts/ensure-docs-slide-pdf.js: verify content-type, enforce an expected size limit, and/or checksum the expected artifact before trusting the raw HTTP response body written to disk.
  • Add a regression test or static-analysis guard so this specific pattern cannot silently reappear after remediation, closing the SDLC verification gap that allowed [Custom Engine Test] Test Issue Created by Custom Engine #654's fix to not prevent recurrence.

SLA urgency: High

Governance report

Full asset graph, control-verification findings, and risk-scoring context are in the linked governance discussion report: "UK AI Open Code Risk & Resilience Governance — Weekly Review (2026-09-22)".

Generated by UK AI Operational Resilience · copilot · auto · 81.6 AIC · ⌖ 7.77 AIC · ⊞ 7.9K · ◷

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions