Summary
CodeQL alert #681 (go/allocation-size-overflow, CWE-190, severity: high) in actively-changed workflow-YAML codegen has no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-07).
- Alert: #681 —
pkg/workflow/compiler_yaml_ai_execution.go:92
- Created 2026-09-12; still open at time of this review.
Tier & risk-scoring
- Tier: C — Restricted Pending Review
- Exposure amplification: Low–Medium (this file generates GitHub Actions workflow YAML for AI execution steps; an overflow-triggered panic or undersized allocation at codegen time could affect all generated workflows using this code path)
- Patchability: High (bounds-check or widen the intermediate type to
uint64/int64 before slice-length conversion)
- Detectability: Medium (CodeQL catches it, but it isn't yet visible in the tracking-issue backlog)
- Operational fragility: Medium
- Ownership confidence: Low-Medium (repository CODEOWNERS is a single flat global rule —
* @dsyme @eaftan @pelikhan @krzysztof-cieslak — with no path-specific reviewer for pkg/workflow/)
Remediation action
- Guard the size computation with a bounds check before use in the allocation at
compiler_yaml_ai_execution.go:92, or widen the intermediate type (e.g., accumulate as uint64/int64 before converting to a slice length).
- Add a regression test exercising a large/edge-case input to confirm no panic or wraparound occurs.
- After fixing, verify the alert actually transitions to
fixed/dismissed in code scanning before closing this issue.
SLA urgency
Critical — untracked, security-severity-"high" alert in actively-changed, workflow-generation-critical code; low individual exploit likelihood but broad blast radius if triggered.
Discussion report
See the "UK AI Governance: recent-change risk review (2026-09-07 to 2026-09-14)" discussion created by this run for full asset graph, control verification, and risk-scoring context.
Generated by UK AI Operational Resilience · copilot · auto · 82.3 AIC · ⌖ 8.97 AIC · ⊞ 8.2K · ◷
Summary
CodeQL alert
#681(go/allocation-size-overflow, CWE-190, severity: high) in actively-changed workflow-YAML codegen has no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-07).pkg/workflow/compiler_yaml_ai_execution.go:92Tier & risk-scoring
uint64/int64before slice-length conversion)* @dsyme @eaftan @pelikhan @krzysztof-cieslak— with no path-specific reviewer forpkg/workflow/)Remediation action
compiler_yaml_ai_execution.go:92, or widen the intermediate type (e.g., accumulate asuint64/int64before converting to a slice length).fixed/dismissedin code scanning before closing this issue.SLA urgency
Critical — untracked, security-severity-"high" alert in actively-changed, workflow-generation-critical code; low individual exploit likelihood but broad blast radius if triggered.
Discussion report
See the "UK AI Governance: recent-change risk review (2026-09-07 to 2026-09-14)" discussion created by this run for full asset graph, control verification, and risk-scoring context.