You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk-ai-resilience] Untracked code-scanning alert #657 in README.md — smoke-test alert-numbering drift from #564 (Tier B) #59774
CodeQL alert #657 (workflow-security-finding-1, severity: warning) in README.md has no open tracking issue. This is a distinct finding from the previously-tracked #564 (issue #57981, still open) — the alert number has drifted, which itself is evidence of the alert-numbering/tracking-issue reconciliation gap already flagged in #57982/#59490.
Alert: #657 — workflow-security-finding-1, tool "Smoke Claude", message "Smoke test dummy warning — Run 34294409797"
Location: README.md (line 1)
Tier & risk-scoring
Tier: B — Open With Conditions
Exposure amplification: Low (appears to be a deliberate smoke-test/dummy warning generated by the "Smoke Claude" workflow's SARIF upload step, not a real content finding)
Ownership confidence: Low — no verified CODEOWNERS entry for README.md or the smoke-test workflow this run
Remediation action
Confirm alert #657 is indeed a smoke-test dummy artifact from .github/workflows/smoke-claude.lock.yml's upload_code_scanning_sarif step (not a genuine finding), and dismiss it with a documented reason (e.g., "test/won't fix — smoke test artifact").
If the smoke-test workflow is expected to keep generating a fresh dummy alert on every run, consider excluding its SARIF category from the standard open-alert governance count, or auto-dismissing smoke-test alerts on upload, to prevent this class from recurring as an untracked/backlog-visible item each cycle.
Medium (14 days) — low real risk, but leaving it untracked degrades confidence in the alert-classification step of the governance loop.
Discussion report
See the "UK AI Governance: recent-change risk review (2026-09-02 to 2026-09-09)" discussion created by this run for full asset graph, control verification, and risk-scoring context.
Summary
CodeQL alert
#657(workflow-security-finding-1, severity: warning) inREADME.mdhas no open tracking issue. This is a distinct finding from the previously-tracked#564(issue #57981, still open) — the alert number has drifted, which itself is evidence of the alert-numbering/tracking-issue reconciliation gap already flagged in #57982/#59490.workflow-security-finding-1, tool "Smoke Claude", message "Smoke test dummy warning — Run 34294409797"README.md(line 1)Tier & risk-scoring
README.mdor the smoke-test workflow this runRemediation action
.github/workflows/smoke-claude.lock.yml'supload_code_scanning_sarifstep (not a genuine finding), and dismiss it with a documented reason (e.g., "test/won't fix — smoke test artifact").SLA urgency
Medium (14 days) — low real risk, but leaving it untracked degrades confidence in the alert-classification step of the governance loop.
Discussion report
See the "UK AI Governance: recent-change risk review (2026-09-02 to 2026-09-09)" discussion created by this run for full asset graph, control verification, and risk-scoring context.