You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk ai resilience] UK AI Open Code Risk & Resilience Report - 2026-10-09
#67226
Lookback: 7 days (since 2026-10-02). 349 commits (171 Copilot, 99 maintainer, 45 bot, 24 dependabot), 47 open security issues, 253 open code-scanning alerts, 0 secret-scanning alerts. Dominant risk is supply-chain reproducibility in compiled workflows (218 of the 253 alerts are non-deterministic npm installs). Most other findings already have open [uk-ai-resilience] issues. One new cluster (work-queue scripts, filed 2026-10-09) lacks tracking; a new issue is raised for it. No secret exposure.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Executive summary
Lookback: 7 days (since 2026-10-02). 349 commits (171 Copilot, 99 maintainer, 45 bot, 24 dependabot), 47 open security issues, 253 open code-scanning alerts, 0 secret-scanning alerts. Dominant risk is supply-chain reproducibility in compiled workflows (218 of the 253 alerts are non-deterministic npm installs). Most other findings already have open
[uk-ai-resilience]issues. One new cluster (work-queue scripts, filed 2026-10-09) lacks tracking; a new issue is raised for it. No secret exposure.Asset graph summary (recent-change scoped)
Asset graph
.github/workflows/*.lock.ymlpkg/workflow,pkg/cli(Go compiler)go/unsafe-quoting(maintenance_workflow_yaml_jobs.go:587,620); 5go/bad-redirect-check; 2 GraphQL Sprintf.github/scripts,specs/work-queue,specs/eslint-factoryjs/file-system-race, 1js/incomplete-sanitization(new 2026-10-09); 5 insecure-temp-filescripts/ensure-docs-slide-pdf.jsjs/http-to-file-access(#663)Tier classification
Tier table
No Tier C/D areas identified.
Control verification gaps
.github/CODEOWNERSmissing (still open, [uk-ai-resilience] Missing .github/CODEOWNERS for security-sensitive compiler/CLI paths (Tier B) #61637).curl | sudo sh([setup-security] Unpinnedcurl | sudo shroot install in sudo_docker_sbx_install.sh (supply-chain risk) #62521).Risk scoring
Scores (1 low risk – 5 high risk; ownership confidence 5 = high)
Rationale: high detectability everywhere (scanners work); the weak points are ownership and install determinism.
Remediation queue
Human-review trigger: any change to compiler template output or release token minting.
Exception register
None.
Operational metrics baseline
All reactions