You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Every third-party uses: SHA-pinned with a version comment. Strip-only TS clean. Every workflow declares permissions:.
Code Quality
✅
bootstrap / check-types / lint / test pass at b8f7ff0: 80 files, 3701 tests.
Oversight
⚠️
49 PRs stale >14d (44 Fro-Bot-authored); 7 repos red on default branch (+2 since yesterday). ❔ sub-source: Dependabot alerts HTTP 403 on 28 of 34 repos.
Cross-Project Intelligence
⚠️
Coverage partial: 29 of 34 ledger entries. Same 2 failed surveys (2026-09-12), now 11 days unretried.
Progressive Improvement
⚠️
Compounding still stalled: 10 open learning-proposal issues, last authoring commit 2026-09-07 (16 days). No unmanaged tool drift.
Errored PRs
None. The remediation pass ran in branch-pr mode ahead of this job and opened 0 PRs, pushed 0 branches, and made 0 commits. Its findings are in this comment on #3913.
#3901 (fro-bot): every check run passes. The combined legacy status is success (only Security: Private Leak Scan). Mergeable. It has sat idle since 2026-09-20, so the fix is done and only waiting on a merge.
The four dependency PRs listed yesterday (#3882, #3904, #3911, #3912) have been merged or closed since.
Security
Advisory data was available for this repo.
Dependabot: 1 open alert. GHSA-p498-v437-472g, @humanfs/node@0.16.7, medium, development scope, pulled in transitively through eslint@10.11.0, fixed in 0.16.8. Below the critical/high bar, so it stays with Renovate.
Code scanning: 4 Scorecard posture alerts, none of them code defects: VulnerabilitiesID (high, which restates the alert above), BranchProtectionID (high), FuzzingID (medium), CIIBestPracticesID (low).
Secret scanning: 0 open.
Control-Plane Integrity
Clean, per the remediation pass.
SHA pinning: every non-local uses: is pinned @<40-char sha> # vX. The only unpinned refs are local (./.github/actions/setup, ./.github/actions/sync-wiki, ./.github/workflows/fro-bot.yaml).
Strip-only TS: no enum, namespace, import x =, or parameter properties in scripts/*.ts.
Least privilege: every workflow declares permissions:. The only broad grant is read-all in scorecard.yaml (the upstream OSSF template), narrowed per job.
Guards: wiki-authority, private-leak, and mutation-guard checks are present and green. None were changed.
One new thing this pass found (report-only, see Cross-Project Intelligence): 24 create-github-app-token steps use the deprecated app-id input.
Code Quality
pnpm bootstrap, pnpm check-types, pnpm lint, pnpm test all pass on main @ b8f7ff0: 80 test files, 3701 passing, 3 todo. The tree was clean afterwards, so there were no autofixes.
Outside that gate, workflow health has one failure: Merge Data Branch. It last succeeded on 2026-09-06 and failed on 2026-09-13 and 2026-09-20 (run 35545734311). See Needs Human Attention 1.
Oversight
Scope. Paginated user/repos (affiliation=owner,collaborator,organization_member) returned 38 repos, 34 of them non-archived, all public. user/orgs returned empty, so bfra-me/* is reachable through collaborator access, not org membership.
❔ Unavailable source. Dependabot alerts returned 403 on 28 of 34 repos. Only the 6 fro-bot/* repos are readable: fro-bot/.github has 1 medium, the other five have none. Security posture across the other 28 repos is unmeasured, which is not the same as clean.
Stale PRs (>14d without an update): 49, of which 44 are Fro-Bot-authored. Down from 57 yesterday.
Next step: use the existing #3652 for triage, starting with the two bfra-me/* security queues. Close #1383 or rebase it; after 195 days it's no longer a live proposal.
Failing default-branch checks (7 repos, 2 new since yesterday):
New:bfra-me/github-actionmain@1faf65b1, Update Repo Settings. The job fails with Failed to apply branches settings: Branch not found (404): the settings config protects a branch that doesn't exist. Next step: drop or correct that branch entry in the repo's .github/settings.yml.
Next step: four repos have a red Renovate context. Check whether they share one cause, likely a common config or preset change, before triaging them one at a time.
New issues (last 24h): 17 total, 11 of them Fro-Bot-authored. Human-filed:
Top three hotspots (count of stale issues + stale PRs + unassigned bugs + red default branch):
marcusrbrown/gpt: 34. 19 stale issues and 15 stale PRs. #2165 and the #2162 HeroUI tree account for most of it. Next step: decide whether the migration goes ahead or gets closed.
marcusrbrown/vbs: 23. 15 stale issues and 8 stale Fro-Bot PRs, 4 of them fix(security). Next step: merge or close the security four.
marcusrbrown/marcusrbrown.com: 12. 3 stale issues, 6 stale PRs, 2 unassigned a11y bugs, and a red Fro Bot context. Next step: fix the agent job first, because nothing in this repo self-heals while it's red.
Gateway rollout tracker (category 8, awareness only; no tracker writes and no Project edits).#3512 still has every drift reported yesterday. Its body text hasn't changed.
marcusrbrown/infra#1412 (gateway deploy parked at the required-reviewer gate) is still open, so the running gateway still predates infra#1405. The tracker has no concept of a deploy waiting on a reviewer.
Cross-Project Intelligence
Coverage: partial, 29 of 34 metadata/repos.yaml entries (read from origin/data, the authoritative copy).
Bucket
Count
Detail
Scanned (survey succeeded)
29
Last survey failed
2
marcusrbrown/containers, marcusrbrown/dev-like, both dated 2026-09-12 and not retried in the 11 days since
Never surveyed
3
pending, private by classification. Counted only, not named.
lost-access
1
marcusrbrown/copiloting (archived)
The ledger gap from yesterday is still there: bfra-me/github-action, bfra-me/github-app, and bfra-me/renovate-config are writable but not in the ledger, and they hold 8 of the 49 stale PRs.
Adoptable findings (report-only):
create-github-app-tokenapp-id deprecation, from bfra-me/.github#2770. This repo passes app-id: ${{ secrets.APPLICATION_ID }}24 times across 14 workflows, all pinned at bcd2ba49… # v3.2.0. Every run logs the deprecation warning. The upstream issue's key point: client-id takes the App's Client ID (Iv…), not the numeric App ID, so renaming the key alone would break every App-token step the moment it's minted. The fix order is: provision the Client ID as a variable, then edit the workflows. Nothing is red today; it breaks on the major release that removes the input. Persisted to the wiki this run.
Carried over from yesterday, still unadopted: capability-split agent jobs (the marcusrbrown/infrafro-bot.yaml shape) and out-of-band liveness monitoring. See #3913 for the full write-up.
Progressive Improvement
Compounding pipeline: stalled. 10 open learning-proposal issues: #3887–#3891 (9 days) and #3905–#3909 (2 days). The last authoring commit was #3868 on 2026-09-07, 16 days ago. docs/solutions/ still holds 59 entries. The first batch crosses the 14-day threshold on 2026-09-28. As instructed, the healthy reading on #3674 doesn't count as evidence here.
Tool-version drift: none unmanaged. Latest versions come from the latest dist-tag on registry.npmjs.org, and major drift was included:
Minor skew: @vitest/coverage-v8@4.1.4 vs vitest@4.1.11.
Stale TODO/FIXME: none. The one hit is this prompt's own text in .github/workflows/fro-bot.yaml:382.
Convention drift: none detected.
Needs Human Attention
1. Merge Data Branch is blocked by the privacy gate. The gate is working correctly; do not weaken it. The data branch's lead over main (origin/main..origin/data) is now 78 commits (72 yesterday). Publish Wiki last ran on 2026-09-06, so the public wiki is 17 days stale while every workflow shows green. The full agent note is in #3913 → Needs Human Attention 1, and nothing about it has changed. The fix requires a local operator run of check-wiki-private-presence.ts --operator-report followed by a one-field data-branch repair. No CI agent can do this.
2. Two surveys failed and nothing retried them.marcusrbrown/containers and marcusrbrown/dev-like (2026-09-12). Re-dispatch both with gh workflow run survey-repo.yaml -f node_id=<node_id from metadata/repos.yaml on data> and read the logs before touching any cadence logic. Verify: both show last_survey_status: success.
Files:.github/workflows/{manage-cache,capture-learnings,dispatch-renovate,status-truth,update-metadata,reset-survey-status,manage-issues,…}.yaml. List them all with grep -rn 'app-id:' .github/workflows.
Prerequisite (human): provision the fro-bot App's Client ID (Iv…) as a repo or org variable. APPLICATION_ID holds the numeric App ID and won't work as a client-id value.
Smallest safe fix after that: replace app-id: ${{ secrets.APPLICATION_ID }} with client-id: ${{ vars.<NAME> }} in a single PR, and nothing else in it.
Do not rename the key while still passing secrets.APPLICATION_ID. That produces a green lint and a failed token mint.
Verify: the deprecation warning is gone from a Dispatch Renovate / Update Metadata run log, and the token step succeeds.
Not urgent: this only breaks on the action's next major.
4. Scorecard BranchProtectionID (high). Leave it alone. Branch protection is out of scope, and on a single-operator repo requiring two reviewers would deadlock data → main promotion.
5. The learning-authoring loop has no owner and no alarm. Same as yesterday's item 5. The smallest useful fix is a visible count-and-age of open learning-proposal issues. Do not auto-author the proposals.
Persisted to the wiki this run: a new section in knowledge/wiki/topics/github-actions-ci.md (A Deprecated Input Whose Replacement Takes a Different Value), with knowledge/index.md and knowledge/log.md updated. No metadata/** file was written.
Daily Fro Bot Report — 2026-09-23 (UTC)
Run Summary
uses:SHA-pinned with a version comment. Strip-only TS clean. Every workflow declarespermissions:.bootstrap/check-types/lint/testpass atb8f7ff0: 80 files, 3701 tests.learning-proposalissues, last authoring commit 2026-09-07 (16 days). No unmanaged tool drift.Errored PRs
None. The remediation pass ran in
branch-prmode ahead of this job and opened 0 PRs, pushed 0 branches, and made 0 commits. Its findings are in this comment on #3913.fro-bot): every check run passes. The combined legacy status issuccess(onlySecurity: Private Leak Scan). Mergeable. It has sat idle since 2026-09-20, so the fix is done and only waiting on a merge.The four dependency PRs listed yesterday (#3882, #3904, #3911, #3912) have been merged or closed since.
Security
Advisory data was available for this repo.
GHSA-p498-v437-472g,@humanfs/node@0.16.7, medium, development scope, pulled in transitively througheslint@10.11.0, fixed in0.16.8. Below the critical/high bar, so it stays with Renovate.VulnerabilitiesID(high, which restates the alert above),BranchProtectionID(high),FuzzingID(medium),CIIBestPracticesID(low).Control-Plane Integrity
Clean, per the remediation pass.
uses:is pinned@<40-char sha> # vX. The only unpinned refs are local (./.github/actions/setup,./.github/actions/sync-wiki,./.github/workflows/fro-bot.yaml).enum,namespace,import x =, or parameter properties inscripts/*.ts.permissions:. The only broad grant isread-allinscorecard.yaml(the upstream OSSF template), narrowed per job.One new thing this pass found (report-only, see Cross-Project Intelligence): 24
create-github-app-tokensteps use the deprecatedapp-idinput.Code Quality
pnpm bootstrap,pnpm check-types,pnpm lint,pnpm testall pass onmain@b8f7ff0: 80 test files, 3701 passing, 3 todo. The tree was clean afterwards, so there were no autofixes.Outside that gate, workflow health has one failure:
Merge Data Branch. It last succeeded on 2026-09-06 and failed on 2026-09-13 and 2026-09-20 (run 35545734311). See Needs Human Attention 1.Oversight
Scope. Paginated
user/repos(affiliation=owner,collaborator,organization_member) returned 38 repos, 34 of them non-archived, all public.user/orgsreturned empty, sobfra-me/*is reachable through collaborator access, not org membership.❔ Unavailable source. Dependabot alerts returned 403 on 28 of 34 repos. Only the 6
fro-bot/*repos are readable:fro-bot/.githubhas 1 medium, the other five have none. Security posture across the other 28 repos is unmeasured, which is not the same as clean.Stale PRs (>14d without an update): 49, of which 44 are Fro-Bot-authored. Down from 57 yesterday.
Oldest:
bfra-me/renovate-config#1383(195d, Copilot agent),marcusrbrown/gpt#2165(178d, the HeroUI v3 migration), andbfra-me/github-app#840/bfra-me/github-action#1463(99d, bothfix(security)).Next step: use the existing #3652 for triage, starting with the two
bfra-me/*security queues. Close #1383 or rebase it; after 195 days it's no longer a live proposal.Aging PRs (>7d since creation): 74 of 91 open.
Stale issues (>30d without an update): 74, concentrated in marcusrbrown/gpt (19) and marcusrbrown/vbs (15).
Failing default-branch checks (7 repos, 2 new since yesterday):
main@1faf65b1,Update Repo Settings. The job fails withFailed to apply branches settings: Branch not found (404): the settings config protects a branch that doesn't exist. Next step: drop or correct that branch entry in the repo's.github/settings.yml.main@2398ab2f,Renovate / Renovate.Renovate), marcusrbrown/containers (Renovate), marcusrbrown/cortexkit_anthropic-auth (Fro Bot), marcusrbrown/extend-vscode (Pre-Release Validation (vulnerabilities)), marcusrbrown/marcusrbrown.com (Fro Bot, now at1fd9c349, so it failed again on a new commit).Renovatecontext. Check whether they share one cause, likely a common config or preset change, before triaging them one at a time.New issues (last 24h): 17 total, 11 of them Fro-Bot-authored. Human-filed:
fro-bot/agent#1645,#1652,#1655: gateway rate-limit and lease-takeover correctness.bfra-me/.github#2767:_extendsreplaces the labels array. This is the upstream root cause behind this repo's interim fix in #3916.bfra-me/.github#2770:app-id→client-iddeprecation. It applies here too, see below.marcusrbrown/systematic#1020: external listing request.Unassigned bugs (6):
bfra-me/.github#2767(0d),marcusrbrown/systematic#1005(4d),bfra-me/ha-addon-repository#569(22d),marcusrbrown/marcusrbrown.com#517(44d),marcusrbrown/systematic#740(51d),marcusrbrown/marcusrbrown.com#465(76d). Next step: #569 and the new github-action 404 are bothUpdate Repo Settingsfailures, so check them together.Top three hotspots (count of stale issues + stale PRs + unassigned bugs + red default branch):
fix(security). Next step: merge or close the security four.Fro Botcontext. Next step: fix the agent job first, because nothing in this repo self-heals while it's red.Gateway rollout tracker (category 8, awareness only; no tracker writes and no Project edits). #3512 still has every drift reported yesterday. Its body text hasn't changed.
Todov0.85.0"fro-bot/agentlatest release:v0.114.1(2026-09-22)v0.83.0"marcusrbrown/infraapps/gateway/upstream.json:v0.113.2v0.85.0but not yet deployed"v0.85.0, so this premise no longer holdsdashboard#179,dashboard#125,#3525,infra#711listed as openv1.6.0dashboard.fro.bot/operator/health→{"ok":true,"contractVersion":"1.6.0"}marcusrbrown/infra#1412(gateway deploy parked at the required-reviewer gate) is still open, so the running gateway still predatesinfra#1405. The tracker has no concept of a deploy waiting on a reviewer.Cross-Project Intelligence
Coverage: partial, 29 of 34
metadata/repos.yamlentries (read fromorigin/data, the authoritative copy).marcusrbrown/containers,marcusrbrown/dev-like, both dated 2026-09-12 and not retried in the 11 days sincepending, private by classification. Counted only, not named.lost-accessmarcusrbrown/copiloting(archived)The ledger gap from yesterday is still there:
bfra-me/github-action,bfra-me/github-app, andbfra-me/renovate-configare writable but not in the ledger, and they hold 8 of the 49 stale PRs.Adoptable findings (report-only):
create-github-app-tokenapp-iddeprecation, frombfra-me/.github#2770. This repo passesapp-id: ${{ secrets.APPLICATION_ID }}24 times across 14 workflows, all pinned atbcd2ba49… # v3.2.0. Every run logs the deprecation warning. The upstream issue's key point:client-idtakes the App's Client ID (Iv…), not the numeric App ID, so renaming the key alone would break every App-token step the moment it's minted. The fix order is: provision the Client ID as a variable, then edit the workflows. Nothing is red today; it breaks on the major release that removes the input. Persisted to the wiki this run.bfra-me/.github#2767is the root cause that #3916 patched locally, by duplicating the 48 base labels plus a drift guard. Once chore(dev): update dependency @bfra.me/eslint-config to v0.17.0 #2767 lands, fix(labels): restore the shared label taxonomy and declare control-plane labels #3916's duplication can be reverted. Keepscripts/settings-label-union.test.tsuntil then.marcusrbrown/infrafro-bot.yamlshape) and out-of-band liveness monitoring. See #3913 for the full write-up.Progressive Improvement
Compounding pipeline: stalled. 10 open
learning-proposalissues: #3887–#3891 (9 days) and #3905–#3909 (2 days). The last authoring commit was #3868 on 2026-09-07, 16 days ago.docs/solutions/still holds 59 entries. The first batch crosses the 14-day threshold on 2026-09-28. As instructed, thehealthyreading on #3674 doesn't count as evidence here.Tool-version drift: none unmanaged. Latest versions come from the
latestdist-tag onregistry.npmjs.org, and major drift was included:latesttypescript.github/renovate.json5allowedVersions: '<6.1.0'(typescript-eslint peer ceiling)vitesteslintprettierMinor skew:
@vitest/coverage-v8@4.1.4vsvitest@4.1.11.Stale TODO/FIXME: none. The one hit is this prompt's own text in
.github/workflows/fro-bot.yaml:382.Convention drift: none detected.
Needs Human Attention
1.
Merge Data Branchis blocked by the privacy gate. The gate is working correctly; do not weaken it. The data branch's lead over main (origin/main..origin/data) is now 78 commits (72 yesterday).Publish Wikilast ran on 2026-09-06, so the public wiki is 17 days stale while every workflow shows green. The full agent note is in #3913 → Needs Human Attention 1, and nothing about it has changed. The fix requires a local operator run ofcheck-wiki-private-presence.ts --operator-reportfollowed by a one-fielddata-branch repair. No CI agent can do this.2. Two surveys failed and nothing retried them.
marcusrbrown/containersandmarcusrbrown/dev-like(2026-09-12). Re-dispatch both withgh workflow run survey-repo.yaml -f node_id=<node_id from metadata/repos.yaml on data>and read the logs before touching any cadence logic. Verify: both showlast_survey_status: success.3.
create-github-app-tokenapp-id→client-idmigration (24 steps, 14 workflows)..github/workflows/{manage-cache,capture-learnings,dispatch-renovate,status-truth,update-metadata,reset-survey-status,manage-issues,…}.yaml. List them all withgrep -rn 'app-id:' .github/workflows.Iv…) as a repo or org variable.APPLICATION_IDholds the numeric App ID and won't work as aclient-idvalue.app-id: ${{ secrets.APPLICATION_ID }}withclient-id: ${{ vars.<NAME> }}in a single PR, and nothing else in it.secrets.APPLICATION_ID. That produces a green lint and a failed token mint.Dispatch Renovate/Update Metadatarun log, and the token step succeeds.4. Scorecard
BranchProtectionID(high). Leave it alone. Branch protection is out of scope, and on a single-operator repo requiring two reviewers would deadlockdata → mainpromotion.5. The learning-authoring loop has no owner and no alarm. Same as yesterday's item 5. The smallest useful fix is a visible count-and-age of open
learning-proposalissues. Do not auto-author the proposals.Persisted to the wiki this run: a new section in
knowledge/wiki/topics/github-actions-ci.md(A Deprecated Input Whose Replacement Takes a Different Value), withknowledge/index.mdandknowledge/log.mdupdated. Nometadata/**file was written.