You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk-ai-resilience] Alert-dismissal hygiene gap persists across CodeQL tracking issues (Tier C) #59490
The UK AI Open Code Risk & Resilience Governance workflow (recent-changes scope, 7-day lookback since 2026-09-01) confirms the dismissal-hygiene gap first raised in #57982: several CodeQL code-scanning alerts remain open in this run's alert set despite prior tracking issues claiming remediation/closure.
Tier & risk-scoring
Tier: C — Restricted Pending Review
Exposure amplification: Medium
Patchability: High (process fix, no code change required)
Detectability: Low (staleness is silent — no automated re-check that a "remediated" issue's alert actually closed)
For any alert still open despite a closed "remediated" tracking issue, either (a) reopen the tracking issue and re-triage, or (b) explicitly dismiss the alert with a documented reason if it is confirmed fixed/false-positive.
Add an automated dismissal-hygiene check to the alert-tracking workflow (e.g. a step that verifies code-scanning alert state matches tracking-issue state before allowing issue closure) to prevent recurrence.
SLA urgency
High — this is a process control gap affecting the reliability of the entire alert-remediation loop, not an isolated code defect.
Summary
The UK AI Open Code Risk & Resilience Governance workflow (recent-changes scope, 7-day lookback since 2026-09-01) confirms the dismissal-hygiene gap first raised in #57982: several CodeQL code-scanning alerts remain open in this run's alert set despite prior tracking issues claiming remediation/closure.
Tier & risk-scoring
Remediation action
SLA urgency
High — this is a process control gap affecting the reliability of the entire alert-remediation loop, not an isolated code defect.
Related