Summary
Four new/recurring go/bad-redirect-check CodeQL alerts in actively-changed CLI/workflow-compiler files have no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-01):
This is the same alert class flagged as a recurring false positive in #57472 (path-traversal/redirect guards), and the same class previously tracked individually for add_package_manifest.go in #54037.
Tier & risk-scoring
- Tier: B — Open With Conditions
- Exposure amplification: Low–Medium
- Patchability: High
- Detectability: Medium (alert exists in code scanning, but untracked in issue backlog)
- Operational fragility: Medium
- Ownership confidence: Medium
Remediation action
SLA urgency
High — untracked alerts in actively-changed files reduce confidence in the classification step of the operational governance loop; low individual exploit likelihood keeps this at High rather than Critical.
Related
Generated by UK AI Operational Resilience · copilot · auto · 55.1 AIC · ⌖ 12.6 AIC · ⊞ 8.1K · ◷
Summary
Four new/recurring
go/bad-redirect-checkCodeQL alerts in actively-changed CLI/workflow-compiler files have no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-01):pkg/cli/add_package_manifest_imports.gopkg/workflow/graders_config.gopkg/workflow/graders_config.gopkg/cli/add_package_manifest_includes.goThis is the same alert class flagged as a recurring false positive in #57472 (path-traversal/redirect guards), and the same class previously tracked individually for
add_package_manifest.goin #54037.Tier & risk-scoring
Remediation action
isSafeRelativePathutility checked for//and/\prefixes) acrosspkg/cliandpkg/workflowto eliminate the recurring finding class, then dismiss the alerts with that rationale.add_package_manifest_imports.go,add_package_manifest_includes.go, andgraders_config.goto also reject//and/\prefixed inputs.SLA urgency
High — untracked alerts in actively-changed files reduce confidence in the classification step of the operational governance loop; low individual exploit likelihood keeps this at High rather than Critical.
Related