Skip to content

[uk-ai-resilience] UK AI Governance: unreviewed CodeQL go/bad-redirect-check alert in add_package_manifest.go (Tier B) #54037

Description

@github-actions

Summary

UK AI Open Code Governance review (7-day recent-change scope) identified an open code-scanning alert with no existing tracking issue.

Alert: #655 — CodeQL go/bad-redirect-check (severity: error, CWE-601 URL redirection to untrusted site)
Location: pkg/cli/add_package_manifest.go:579, function cleanManifestRelativePath

Risk-scoring breakdown (Tier B — Open With Conditions)

Dimension Rating
Exposure amplification Low
Patchability High
Detectability High (CodeQL)
Operational fragility Low
Ownership confidence High

Assessment

The flagged code is a relative-path/traversal guard (cleanManifestRelativePath), not a redirect handler:

func cleanManifestRelativePath(p string) (string, error) {
	slashed := filepath.ToSlash(p)
	if strings.HasPrefix(slashed, "/") || strings.HasPrefix(slashed, "\\") || filepath.IsAbs(p) || isWindowsDriveRelativePath(slashed) {
		return "", errors.New("absolute paths are not allowed")
	}
	...

CodeQL's go/bad-redirect-check heuristic appears to have matched the HasPrefix(slashed, "/") pattern generically, without confirming the value flows into an HTTP redirect (http.Redirect/Location header). This is very likely a false positive, but it has not yet been triaged, dismissed, or fixed.

Remediation action

  • SLA urgency: Medium
  • Action: Confirm whether the flagged value ever flows into an HTTP redirect. If not (expected), dismiss the CodeQL alert with a "false positive" reason referencing this analysis. If it does reach a redirect path elsewhere, add a ///backslash check consistent with the CWE-601 guidance.

Discussion report

See the UK AI Open Code Governance discussion report created in this same workflow run for full asset-graph, tier classification, and control-verification context.

Generated by UK AI Operational Resilience · auto · 43.9 AIC · ⌖ 2.57 AIC · ⊞ 9.3K · ◷

Activity

  1. github-actions commented on Aug 20, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · gpt54 · 3.47 AIC · ⌖ 12.2 AIC · ⊞ 11.8K · ◷

  2. github-actions commented on Sep 3, 2026

    @github-actions
    ContributorAuthor

    Note from DeepReport Intelligence Briefing (2026-09-03 ~18:33Z cycle): the UK AI Operational Resilience review (discussion #58260) flagged that this issue's tracked alert #667 (go/bad-redirect-check, same rule/pattern as this issue's alert #655) now points at a stale filename. pkg/cli/add_package_manifest.go was split/renamed to pkg/cli/add_package_manifest_includes.go via PR #58233 ("Add recursive package manifest imports", merged 2026-09-03). Please update the file reference here (and in any false-positive dismissal rationale) to pkg/cli/add_package_manifest_includes.go before dismissing/fixing, so alert-tracking metadata stays accurate. This is the same tracking-hygiene gap already covered generally by issue #57982; this comment just supplies the specific new pointer.

    Warning

    Firewall blocked 1 domain

    The following domain was blocked by the firewall during workflow execution:

    • api.anthropic.com

    To allow these domains, add them to the network.allowed list in your workflow frontmatter:

    network:
      allowed:
        - defaults
        - "api.anthropic.com"

    See Network Configuration for more information.

    Generated by 🔬 Deep Report · claude · agent · 167.2 AIC · ⌖ 15.5 AIC · ⊞ 12.4K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions