You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk-ai-resilience] Untracked go/allocation-size-overflow alerts #675/#676 in mcp_github_config.go (Tier C) #63466
CodeQL flags two open, untrackedgo/allocation-size-overflow alerts in pkg/workflow/mcp_github_config.go, a file that was actively modified within the last 7-day lookback window and generates MCP GitHub server configuration used by the agentic workflow runtime.
Tier and risk-scoring breakdown
Tier: C - Restricted Pending Review (untracked, recently-changed, high severity)
Exposure amplification: Medium-High (feeds MCP server config consumed by the agent runtime, wider blast radius than a pure CLI-local file)
Patchability: High (bounds checks on slice pre-allocation are straightforward)
Detectability: High (CodeQL already flags it)
Operational fragility: Medium (config-generation path, multiple call sites)
Location: pkg/workflow/mcp_github_config.go, multiple make([]string, 0, n) call sites (approx. lines 85, 211, 422, 638, 646) where n is derived from combined slice lengths (e.g. len(enclave.Dynamic.AllowedRepositories)+len(enclave.Dynamic.AllowedOwners))
Remediation action
Validate/bound the computed capacity values before calling make() at each flagged call site, so combined or attacker-influenced slice lengths cannot trigger an allocation-size overflow during MCP config generation. SLA urgency: high.
Discussion report
Full governance analysis, asset graph, and control-verification context: see the "UK AI Open Code Risk & Resilience Review — 2026-09-25 (recent-changes cycle)" discussion report created in this same run.
Summary
CodeQL flags two open, untracked
go/allocation-size-overflowalerts inpkg/workflow/mcp_github_config.go, a file that was actively modified within the last 7-day lookback window and generates MCP GitHub server configuration used by the agentic workflow runtime.Tier and risk-scoring breakdown
CODEOWNERSentry exists forpkg/workflow/(see companion Tier B finding in [uk-ai-resilience] Missing .github/CODEOWNERS for security-sensitive compiler/CLI paths (Tier B) #61637)Alert details
go/allocation-size-overflowpkg/workflow/mcp_github_config.go, multiplemake([]string, 0, n)call sites (approx. lines 85, 211, 422, 638, 646) wherenis derived from combined slice lengths (e.g.len(enclave.Dynamic.AllowedRepositories)+len(enclave.Dynamic.AllowedOwners))Remediation action
Validate/bound the computed capacity values before calling
make()at each flagged call site, so combined or attacker-influenced slice lengths cannot trigger an allocation-size overflow during MCP config generation. SLA urgency: high.Discussion report
Full governance analysis, asset graph, and control-verification context: see the "UK AI Open Code Risk & Resilience Review — 2026-09-25 (recent-changes cycle)" discussion report created in this same run.