Skip to content

[uk-ai-resilience] Untracked missing node-version pin in format-and-commit.yml (alert #831, Tier B) #61378

Description

@github-actions

Summary

CodeQL alert #831 (pr-action.rules.github-actions.javascript-lockfile-install.github-actions-setup-node-missing-version, severity: error) flags .github/workflows/format-and-commit.yml:29, where actions/setup-node is used without an explicit node-version (or node-version-file) input:

- name: Set up Node.js
  uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v6
  with:
    cache: npm
    cache-dependency-path: pkg/workflow/js/package-lock.json

This alert was introduced/surfaced by PR #61359 ("Fix stale docker action pins in wasm golden fixture", merged 2026-09-16), which touched this workflow while re-pinning stale Docker action SHAs. It has no matching open tracking issue, breaking the classification → control-verification loop for this run's recent-changes scope (7-day lookback since 2026-09-09T15:31:12Z).

Tier & risk-scoring

  • Tier: B — Open With Conditions
  • Exposure amplification: Low–Medium — without a pinned Node version, the workflow silently picks up whatever default/latest Node version the action resolves to, which can drift across runs and diverge from the version used locally/in other CI jobs.
  • Patchability: High — trivial fix, add an explicit node-version (or node-version-file: .nvmrc/package.json engines) input.
  • Detectability: Medium — only surfaces as flaky/inconsistent behavior if a Node version bump changes tool behavior; no active monitoring for version drift today.
  • Operational fragility: Medium.
  • Ownership confidence: High — single workflow file, clear scope, no cross-cutting change needed.

Remediation action

  • Add an explicit node-version (or node-version-file) input to the actions/setup-node step in .github/workflows/format-and-commit.yml:29, matching the Node version used elsewhere in the repo's CI/build tooling.
  • SLA urgency: Medium

Reference

Full governance analysis: see the linked discussion report #aw_ukgov0916.

Generated by UK AI Operational Resilience · copilot · auto · 94.4 AIC · ⌖ 7.9 AIC · ⊞ 8.2K · ◷

Activity

  1. github-actions commented on Sep 16, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · pi · gpt54 · 10.9 AIC · ⊞ 12.8K · ◷

  2. github-actions commented on Sep 28, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I’ve identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · pi · gpt54 · 10.5 AIC · ⌖ 10.3 AIC · ⊞ 13.2K · ◷

  3. github-actions commented on Sep 30, 2026

    @github-actions
    ContributorAuthor

    🍪 Issue Monster selected this for Copilot

    I've identified this issue as a good candidate for automated resolution and requested assignment to the Copilot coding agent.

    If assignment succeeds, the Copilot coding agent will analyze the issue and create a pull request with the fix.

    Om nom nom! 🍪

    🍪 Om nom nom by Issue Monster · pi · gpt54 · 6.81 AIC · ⌖ 10.4 AIC · ⊞ 14.1K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions