Skip to content

[uk-ai-resilience] Insecure temp-file handling in new automation scripts (Tier B) #65895

Description

@github-actions

Summary

On 2026-10-05, code scanning raised 6 alerts for insecure temporary files or file-system races in newly added scripts:

  • .github/scripts/aw_issue_clustering.cjs (lines 111, 115, 132)
  • .github/scripts/safe_output_health_cadence.cjs (line 38)
  • scripts/pr-sous-chef.mjs (line 462)
  • .github/scripts/aw_issue_clustering_publish.cjs (line 538, file-system-race)

Tier and risk scoring

  • Tier B — Open With Conditions
  • Exposure 2/5, Patchability 5/5, Detectability 5/5, Fragility 2/5, Ownership confidence 3/5

Remediation action

Use fs.mkdtempSync with a private directory, create files with exclusive flags and 0600 mode, and avoid check-then-use patterns. Add a check that blocks merging when new CodeQL alerts appear on a PR.

SLA urgency

Medium

Discussion report

See the "[uk-ai-resilience] Weekly Review - 2026-10-05" discussion (created in this run).

Generated by UK AI Operational Resilience · copilot · auto · 27.6 AIC · ⌖ 7.86 AIC · ⊞ 7.9K · ◷

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions