Skip to content

[uk-ai-resilience] Non-deterministic installs in compiled workflows (259 alerts, Tier B) #65894

Description

@github-actions

Summary

Code scanning reports 259 open high-severity alerts for non-deterministic dependency installs in generated .github/workflows/*.lock.yml (249 javascript-lockfile-install npm, 10 uv-pip-install). 196 were opened 2026-09-15 and 54 on 2026-10-04, so the oldest are about 20 days old.

Tier and risk scoring

  • Tier B — Open With Conditions
  • Exposure 3/5, Patchability 4/5, Detectability 5/5, Fragility 2/5, Ownership confidence 3/5

Remediation action

Update the compiler (pkg/workflow) to emit lockfile-based installs (npm ci, hash-pinned uv pip install) and pin the one remaining non-SHA Dockerfile image, then recompile. Triage the alerts in bulk by rule.

SLA urgency

High. Human review is required for any change that alters install commands in all lock files.

Discussion report

See the "[uk-ai-resilience] Weekly Review - 2026-10-05" discussion (created in this run).

Generated by UK AI Operational Resilience · copilot · auto · 27.6 AIC · ⌖ 7.86 AIC · ⊞ 7.9K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions