Skip to content

[uk-ai-resilience] Untracked go/allocation-size-overflow alerts #944/#945 in create_code_scanning_alert.go (Tier C) #64043

Description

@github-actions

Summary

UK AI Open Code Governance review (7-day recent-change scope, since 2026-09-21) identified two open CodeQL alerts with no matching tracking issue, in a file modified the same day (2026-09-28) by the automated commit stream:

  • Alert #944 — CodeQL go/allocation-size-overflow (severity: warning, CWE-190)
  • Alert #945 — CodeQL go/allocation-size-overflow (severity: warning, CWE-190)

Location: pkg/workflow/create_code_scanning_alert.go:110

steps := make([]string, 0, len(tokenMintSteps)+len(uploadSteps))

Tier: C — Restricted Pending Review

Dimension Rating
Exposure amplification Low–Medium
Patchability High
Detectability Medium (caught by CodeQL, but untracked in the issue backlog)
Operational fragility Low
Ownership confidence Medium (no CODEOWNERS assigns an explicit owner — see #61637)

Assessment

len(tokenMintSteps)+len(uploadSteps) is used as the capacity argument to make([]string, 0, ...) when assembling the steps for the code-scanning SARIF upload job. Both slice lengths are compiler-internal and currently bounded by a small, fixed set of generated steps, so the practical overflow risk today is low. However this code path is part of the security-events upload/token-minting job itself (mints a fresh GitHub App token for security-events:write), so any future change that allows either slice to grow unboundedly (e.g. per-workflow step generation driven by user-controlled config) could reintroduce the CWE-190 overflow/wraparound risk CodeQL is flagging.

This is the same alert class (go/allocation-size-overflow) already tracked individually in #59773, #60875, #60876, #63465, #63466 for other files in pkg/workflow/pkg/cli — this pair in create_code_scanning_alert.go is the only untracked occurrence found in this run.

Remediation action

  • Guard the arithmetic with a bounds check before use in the allocation, or widen the intermediate type (e.g. accumulate as int64/uint64 before converting to slice capacity).
  • Alternatively, since both lengths are derived from small, statically-bounded slices in current usage, add a brief code comment documenting the invariant and consider whether CodeQL dismissal with that rationale is appropriate — consistent with how the sibling false-positive class is being triaged in [uk-ai-resilience] UK AI Governance: recurring go/bad-redirect-check false positive across path-traversal guards (Tier B) #57472.
  • Add a regression test exercising a large/edge-case input if the guard is implemented.

SLA urgency: high — target remediation or documented risk acceptance within 14 days.

Report

See the full UK AI Open Code Risk & Resilience Governance discussion report generated in this run for asset graph, control verification, and full remediation queue.

Generated by UK AI Operational Resilience · copilot · auto · 75.7 AIC · ⌖ 8.88 AIC · ⊞ 7.8K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions