Summary
Code scanning reports 259 open high-severity alerts for non-deterministic dependency installs in generated .github/workflows/*.lock.yml (249 javascript-lockfile-install npm, 10 uv-pip-install). 196 were opened 2026-09-15 and 54 on 2026-10-04, so the oldest are about 20 days old.
Tier and risk scoring
- Tier B — Open With Conditions
- Exposure 3/5, Patchability 4/5, Detectability 5/5, Fragility 2/5, Ownership confidence 3/5
Remediation action
Update the compiler (pkg/workflow) to emit lockfile-based installs (npm ci, hash-pinned uv pip install) and pin the one remaining non-SHA Dockerfile image, then recompile. Triage the alerts in bulk by rule.
SLA urgency
High. Human review is required for any change that alters install commands in all lock files.
Discussion report
See the "[uk-ai-resilience] Weekly Review - 2026-10-05" discussion (created in this run).
Generated by UK AI Operational Resilience · copilot · auto · 27.6 AIC · ⌖ 7.86 AIC · ⊞ 7.9K · ◷
Summary
Code scanning reports 259 open high-severity alerts for non-deterministic dependency installs in generated
.github/workflows/*.lock.yml(249javascript-lockfile-installnpm, 10uv-pip-install). 196 were opened 2026-09-15 and 54 on 2026-10-04, so the oldest are about 20 days old.Tier and risk scoring
Remediation action
Update the compiler (
pkg/workflow) to emit lockfile-based installs (npm ci, hash-pinneduv pip install) and pin the one remaining non-SHA Dockerfile image, then recompile. Triage the alerts in bulk by rule.SLA urgency
High. Human review is required for any change that alters install commands in all lock files.
Discussion report
See the "[uk-ai-resilience] Weekly Review - 2026-10-05" discussion (created in this run).