Skip to content

[uk-ai-resilience] Untracked code-scanning alert #657 in README.md — smoke-test alert-numbering drift from #564 (Tier B) #59774

Description

@github-actions

Summary

CodeQL alert #657 (workflow-security-finding-1, severity: warning) in README.md has no open tracking issue. This is a distinct finding from the previously-tracked #564 (issue #57981, still open) — the alert number has drifted, which itself is evidence of the alert-numbering/tracking-issue reconciliation gap already flagged in #57982/#59490.

  • Alert: #657 — workflow-security-finding-1, tool "Smoke Claude", message "Smoke test dummy warning — Run 34294409797"
  • Location: README.md (line 1)

Tier & risk-scoring

  • Tier: B — Open With Conditions
  • Exposure amplification: Low (appears to be a deliberate smoke-test/dummy warning generated by the "Smoke Claude" workflow's SARIF upload step, not a real content finding)
  • Patchability: High
  • Detectability: Low (untracked, so it isn't visible in remediation queues; also not linked to the prior [Custom Engine Test] Test Issue Created by Custom Engine #564 tracking issue, so backlog audits may assume it's already covered)
  • Operational fragility: Low
  • Ownership confidence: Low — no verified CODEOWNERS entry for README.md or the smoke-test workflow this run

Remediation action

  • Confirm alert #657 is indeed a smoke-test dummy artifact from .github/workflows/smoke-claude.lock.yml's upload_code_scanning_sarif step (not a genuine finding), and dismiss it with a documented reason (e.g., "test/won't fix — smoke test artifact").
  • If the smoke-test workflow is expected to keep generating a fresh dummy alert on every run, consider excluding its SARIF category from the standard open-alert governance count, or auto-dismissing smoke-test alerts on upload, to prevent this class from recurring as an untracked/backlog-visible item each cycle.
  • Update or close [uk-ai-resilience] Untracked code-scanning alert #564 in README.md (Tier B) #57981 to avoid confusion between the old ([Custom Engine Test] Test Issue Created by Custom Engine #564) and current (#657) alert numbers for the same rule.

SLA urgency

Medium (14 days) — low real risk, but leaving it untracked degrades confidence in the alert-classification step of the governance loop.

Discussion report

See the "UK AI Governance: recent-change risk review (2026-09-02 to 2026-09-09)" discussion created by this run for full asset graph, control verification, and risk-scoring context.

Generated by UK AI Operational Resilience · copilot · auto · 80.5 AIC · ⌖ 6.82 AIC · ⊞ 8.1K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions