Skip to content

Daily Fro Bot Report — 2026-09-23 (UTC) #3917

Description

@fro-bot

Daily Fro Bot Report — 2026-09-23 (UTC)

Run Summary

Category Status Notes
Errored PRs ✅ Remediation pass checked the only open PR (#3901) against check runs and legacy statuses. Green. 0 repairs.
Security ⚠️ 1 open medium dev-scope transitive advisory (Renovate's lane) + 4 Scorecard posture alerts (2 high). 0 remediation PRs, correctly. Secret scanning: 0.
Control-Plane Integrity ✅ Every third-party uses: SHA-pinned with a version comment. Strip-only TS clean. Every workflow declares permissions:.
Code Quality ✅ bootstrap / check-types / lint / test pass at b8f7ff0: 80 files, 3701 tests.
Oversight ⚠️ 49 PRs stale >14d (44 Fro-Bot-authored); 7 repos red on default branch (+2 since yesterday). ❔ sub-source: Dependabot alerts HTTP 403 on 28 of 34 repos.
Cross-Project Intelligence ⚠️ Coverage partial: 29 of 34 ledger entries. Same 2 failed surveys (2026-09-12), now 11 days unretried.
Progressive Improvement ⚠️ Compounding still stalled: 10 open learning-proposal issues, last authoring commit 2026-09-07 (16 days). No unmanaged tool drift.

Errored PRs

None. The remediation pass ran in branch-pr mode ahead of this job and opened 0 PRs, pushed 0 branches, and made 0 commits. Its findings are in this comment on #3913.

  • #3901 (fro-bot): every check run passes. The combined legacy status is success (only Security: Private Leak Scan). Mergeable. It has sat idle since 2026-09-20, so the fix is done and only waiting on a merge.

The four dependency PRs listed yesterday (#3882, #3904, #3911, #3912) have been merged or closed since.

Security

Advisory data was available for this repo.

  • Dependabot: 1 open alert. GHSA-p498-v437-472g, @humanfs/node@0.16.7, medium, development scope, pulled in transitively through eslint@10.11.0, fixed in 0.16.8. Below the critical/high bar, so it stays with Renovate.
  • Code scanning: 4 Scorecard posture alerts, none of them code defects: VulnerabilitiesID (high, which restates the alert above), BranchProtectionID (high), FuzzingID (medium), CIIBestPracticesID (low).
  • Secret scanning: 0 open.

Control-Plane Integrity

Clean, per the remediation pass.

  • SHA pinning: every non-local uses: is pinned @<40-char sha> # vX. The only unpinned refs are local (./.github/actions/setup, ./.github/actions/sync-wiki, ./.github/workflows/fro-bot.yaml).
  • Strip-only TS: no enum, namespace, import x =, or parameter properties in scripts/*.ts.
  • Least privilege: every workflow declares permissions:. The only broad grant is read-all in scorecard.yaml (the upstream OSSF template), narrowed per job.
  • Guards: wiki-authority, private-leak, and mutation-guard checks are present and green. None were changed.

One new thing this pass found (report-only, see Cross-Project Intelligence): 24 create-github-app-token steps use the deprecated app-id input.

Code Quality

pnpm bootstrap, pnpm check-types, pnpm lint, pnpm test all pass on main @ b8f7ff0: 80 test files, 3701 passing, 3 todo. The tree was clean afterwards, so there were no autofixes.

Outside that gate, workflow health has one failure: Merge Data Branch. It last succeeded on 2026-09-06 and failed on 2026-09-13 and 2026-09-20 (run 35545734311). See Needs Human Attention 1.

Oversight

Scope. Paginated user/repos (affiliation=owner,collaborator,organization_member) returned 38 repos, 34 of them non-archived, all public. user/orgs returned empty, so bfra-me/* is reachable through collaborator access, not org membership.

❔ Unavailable source. Dependabot alerts returned 403 on 28 of 34 repos. Only the 6 fro-bot/* repos are readable: fro-bot/.github has 1 medium, the other five have none. Security posture across the other 28 repos is unmeasured, which is not the same as clean.

Stale PRs (>14d without an update): 49, of which 44 are Fro-Bot-authored. Down from 57 yesterday.

Repo Stale PRs
marcusrbrown/gpt 15
marcusrbrown/vbs 8
marcusrbrown/marcusrbrown.com 6
marcusrbrown/containers · marcusrbrown/marcusrbrown · marcusrbrown/opencode-copilot-delegate · bfra-me/github-app 4 each
bfra-me/github-action 3
bfra-me/renovate-config 1

Oldest: bfra-me/renovate-config#1383 (195d, Copilot agent), marcusrbrown/gpt#2165 (178d, the HeroUI v3 migration), and bfra-me/github-app#840 / bfra-me/github-action#1463 (99d, both fix(security)).

Next step: use the existing #3652 for triage, starting with the two bfra-me/* security queues. Close #1383 or rebase it; after 195 days it's no longer a live proposal.

Aging PRs (>7d since creation): 74 of 91 open.

Stale issues (>30d without an update): 74, concentrated in marcusrbrown/gpt (19) and marcusrbrown/vbs (15).

Failing default-branch checks (7 repos, 2 new since yesterday):

New issues (last 24h): 17 total, 11 of them Fro-Bot-authored. Human-filed:

Unassigned bugs (6): bfra-me/.github#2767 (0d), marcusrbrown/systematic#1005 (4d), bfra-me/ha-addon-repository#569 (22d), marcusrbrown/marcusrbrown.com#517 (44d), marcusrbrown/systematic#740 (51d), marcusrbrown/marcusrbrown.com#465 (76d). Next step: #569 and the new github-action 404 are both Update Repo Settings failures, so check them together.

Top three hotspots (count of stale issues + stale PRs + unassigned bugs + red default branch):

  1. marcusrbrown/gpt: 34. 19 stale issues and 15 stale PRs. #2165 and the #2162 HeroUI tree account for most of it. Next step: decide whether the migration goes ahead or gets closed.
  2. marcusrbrown/vbs: 23. 15 stale issues and 8 stale Fro-Bot PRs, 4 of them fix(security). Next step: merge or close the security four.
  3. marcusrbrown/marcusrbrown.com: 12. 3 stale issues, 6 stale PRs, 2 unassigned a11y bugs, and a red Fro Bot context. Next step: fix the agent job first, because nothing in this repo self-heals while it's red.

Gateway rollout tracker (category 8, awareness only; no tracker writes and no Project edits). #3512 still has every drift reported yesterday. Its body text hasn't changed.

Claim in #3512 Live value
Status implies only a verification tail remains Project 1 item status: Todo
"releases have since advanced to v0.85.0" fro-bot/agent latest release: v0.114.1 (2026-09-22)
"deployed pin is v0.83.0" marcusrbrown/infra apps/gateway/upstream.json: v0.113.2
Push "released in v0.85.0 but not yet deployed" The pin is 28 minors past v0.85.0, so this premise no longer holds
dashboard#179, dashboard#125, #3525, infra#711 listed as open All four are closed (verified yesterday; unchanged)
Contract gate satisfied at v1.6.0 Holds. dashboard.fro.bot/operator/health → {"ok":true,"contractVersion":"1.6.0"}

marcusrbrown/infra#1412 (gateway deploy parked at the required-reviewer gate) is still open, so the running gateway still predates infra#1405. The tracker has no concept of a deploy waiting on a reviewer.

Cross-Project Intelligence

Coverage: partial, 29 of 34 metadata/repos.yaml entries (read from origin/data, the authoritative copy).

Bucket Count Detail
Scanned (survey succeeded) 29
Last survey failed 2 marcusrbrown/containers, marcusrbrown/dev-like, both dated 2026-09-12 and not retried in the 11 days since
Never surveyed 3 pending, private by classification. Counted only, not named.
lost-access 1 marcusrbrown/copiloting (archived)

The ledger gap from yesterday is still there: bfra-me/github-action, bfra-me/github-app, and bfra-me/renovate-config are writable but not in the ledger, and they hold 8 of the 49 stale PRs.

Adoptable findings (report-only):

  1. create-github-app-token app-id deprecation, from bfra-me/.github#2770. This repo passes app-id: ${{ secrets.APPLICATION_ID }} 24 times across 14 workflows, all pinned at bcd2ba49… # v3.2.0. Every run logs the deprecation warning. The upstream issue's key point: client-id takes the App's Client ID (Iv…), not the numeric App ID, so renaming the key alone would break every App-token step the moment it's minted. The fix order is: provision the Client ID as a variable, then edit the workflows. Nothing is red today; it breaks on the major release that removes the input. Persisted to the wiki this run.
  2. Upstream fix for the label-taxonomy wipe. bfra-me/.github#2767 is the root cause that #3916 patched locally, by duplicating the 48 base labels plus a drift guard. Once chore(dev): update dependency @bfra.me/eslint-config to v0.17.0 #2767 lands, fix(labels): restore the shared label taxonomy and declare control-plane labels #3916's duplication can be reverted. Keep scripts/settings-label-union.test.ts until then.
  3. Carried over from yesterday, still unadopted: capability-split agent jobs (the marcusrbrown/infra fro-bot.yaml shape) and out-of-band liveness monitoring. See #3913 for the full write-up.

Progressive Improvement

Compounding pipeline: stalled. 10 open learning-proposal issues: #3887–#3891 (9 days) and #3905–#3909 (2 days). The last authoring commit was #3868 on 2026-09-07, 16 days ago. docs/solutions/ still holds 59 entries. The first batch crosses the 14-day threshold on 2026-09-28. As instructed, the healthy reading on #3674 doesn't count as evidence here.

Tool-version drift: none unmanaged. Latest versions come from the latest dist-tag on registry.npmjs.org, and major drift was included:

Tool Pinned Registry latest Read
typescript 6.0.3 7.0.2 Deliberate hold: .github/renovate.json5 allowedVersions: '<6.1.0' (typescript-eslint peer ceiling)
vitest 4.1.11 5.0.1 Major is waiting on Dependency Dashboard approval
eslint 10.11.0 10.11.0 Current (#3912 merged)
prettier 3.9.1 3.9.8 Patch-only, within tolerance

Minor skew: @vitest/coverage-v8@4.1.4 vs vitest@4.1.11.

Stale TODO/FIXME: none. The one hit is this prompt's own text in .github/workflows/fro-bot.yaml:382.

Convention drift: none detected.

Needs Human Attention

1. Merge Data Branch is blocked by the privacy gate. The gate is working correctly; do not weaken it. The data branch's lead over main (origin/main..origin/data) is now 78 commits (72 yesterday). Publish Wiki last ran on 2026-09-06, so the public wiki is 17 days stale while every workflow shows green. The full agent note is in #3913 → Needs Human Attention 1, and nothing about it has changed. The fix requires a local operator run of check-wiki-private-presence.ts --operator-report followed by a one-field data-branch repair. No CI agent can do this.

2. Two surveys failed and nothing retried them. marcusrbrown/containers and marcusrbrown/dev-like (2026-09-12). Re-dispatch both with gh workflow run survey-repo.yaml -f node_id=<node_id from metadata/repos.yaml on data> and read the logs before touching any cadence logic. Verify: both show last_survey_status: success.

3. create-github-app-token app-id → client-id migration (24 steps, 14 workflows).

  • Files: .github/workflows/{manage-cache,capture-learnings,dispatch-renovate,status-truth,update-metadata,reset-survey-status,manage-issues,…}.yaml. List them all with grep -rn 'app-id:' .github/workflows.
  • Prerequisite (human): provision the fro-bot App's Client ID (Iv…) as a repo or org variable. APPLICATION_ID holds the numeric App ID and won't work as a client-id value.
  • Smallest safe fix after that: replace app-id: ${{ secrets.APPLICATION_ID }} with client-id: ${{ vars.<NAME> }} in a single PR, and nothing else in it.
  • Do not rename the key while still passing secrets.APPLICATION_ID. That produces a green lint and a failed token mint.
  • Verify: the deprecation warning is gone from a Dispatch Renovate / Update Metadata run log, and the token step succeeds.
  • Not urgent: this only breaks on the action's next major.

4. Scorecard BranchProtectionID (high). Leave it alone. Branch protection is out of scope, and on a single-operator repo requiring two reviewers would deadlock data → main promotion.

5. The learning-authoring loop has no owner and no alarm. Same as yesterday's item 5. The smallest useful fix is a visible count-and-age of open learning-proposal issues. Do not auto-author the proposals.


Persisted to the wiki this run: a new section in knowledge/wiki/topics/github-actions-ci.md (A Deprecated Input Whose Replacement Takes a Different Value), with knowledge/index.md and knowledge/log.md updated. No metadata/** file was written.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions