You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
[uk-ai-resilience] Untracked go/allocation-size-overflow alerts #944/#945 in create_code_scanning_alert.go (Tier C) #64043
UK AI Open Code Governance review (7-day recent-change scope, since 2026-09-21) identified two open CodeQL alerts with no matching tracking issue, in a file modified the same day (2026-09-28) by the automated commit stream:
Medium (caught by CodeQL, but untracked in the issue backlog)
Operational fragility
Low
Ownership confidence
Medium (no CODEOWNERS assigns an explicit owner — see #61637)
Assessment
len(tokenMintSteps)+len(uploadSteps) is used as the capacity argument to make([]string, 0, ...) when assembling the steps for the code-scanning SARIF upload job. Both slice lengths are compiler-internal and currently bounded by a small, fixed set of generated steps, so the practical overflow risk today is low. However this code path is part of the security-events upload/token-minting job itself (mints a fresh GitHub App token for security-events:write), so any future change that allows either slice to grow unboundedly (e.g. per-workflow step generation driven by user-controlled config) could reintroduce the CWE-190 overflow/wraparound risk CodeQL is flagging.
This is the same alert class (go/allocation-size-overflow) already tracked individually in #59773, #60875, #60876, #63465, #63466 for other files in pkg/workflow/pkg/cli — this pair in create_code_scanning_alert.go is the only untracked occurrence found in this run.
Remediation action
Guard the arithmetic with a bounds check before use in the allocation, or widen the intermediate type (e.g. accumulate as int64/uint64 before converting to slice capacity).
Add a regression test exercising a large/edge-case input if the guard is implemented.
SLA urgency: high — target remediation or documented risk acceptance within 14 days.
Report
See the full UK AI Open Code Risk & Resilience Governance discussion report generated in this run for asset graph, control verification, and full remediation queue.
Summary
UK AI Open Code Governance review (7-day recent-change scope, since 2026-09-21) identified two open CodeQL alerts with no matching tracking issue, in a file modified the same day (2026-09-28) by the automated commit stream:
#944— CodeQLgo/allocation-size-overflow(severity: warning, CWE-190)#945— CodeQLgo/allocation-size-overflow(severity: warning, CWE-190)Location:
pkg/workflow/create_code_scanning_alert.go:110Tier: C — Restricted Pending Review
Assessment
len(tokenMintSteps)+len(uploadSteps)is used as the capacity argument tomake([]string, 0, ...)when assembling the steps for the code-scanning SARIF upload job. Both slice lengths are compiler-internal and currently bounded by a small, fixed set of generated steps, so the practical overflow risk today is low. However this code path is part of the security-events upload/token-minting job itself (mints a fresh GitHub App token forsecurity-events:write), so any future change that allows either slice to grow unboundedly (e.g. per-workflow step generation driven by user-controlled config) could reintroduce the CWE-190 overflow/wraparound risk CodeQL is flagging.This is the same alert class (
go/allocation-size-overflow) already tracked individually in #59773, #60875, #60876, #63465, #63466 for other files inpkg/workflow/pkg/cli— this pair increate_code_scanning_alert.gois the only untracked occurrence found in this run.Remediation action
int64/uint64before converting to slice capacity).SLA urgency: high — target remediation or documented risk acceptance within 14 days.
Report
See the full UK AI Open Code Risk & Resilience Governance discussion report generated in this run for asset graph, control verification, and full remediation queue.