You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Remediation pass found no failing PRs (evidence). #3920 and #3901 are all green.
Security
⚠️
This repo: 1 medium transitive dev alert, below the remediation threshold. 4 Scorecard posture alerts are old.
Control-Plane Integrity
✅
SHA pinning, strip-only TS and top-level permissions: all verified by the remediation pass.
Code Quality
✅
bootstrap / check-types / lint / test all pass (3710 tests).
Oversight
⚠️
3 repos with a failing latest run on the default branch. 2 repos with critical alerts. 54 stale PRs, 50 of them Fro-Bot-authored.
Cross-Project Intelligence
⚠️
Partial coverage. 1 adoptable pattern. 1 stale wiki page. Non-public tracked entries were not scanned.
Progressive Improvement
⚠️
10 open learning-proposal issues, so the compounding pipeline is stalled. Major drift on TypeScript and Vitest.
Errored PRs
None. The remediation pass (comment) checked both check runs and legacy statuses. #3920 has 15 success / 3 skipped and is BLOCKED waiting on review. #3901 has 14 success / 4 skipped and is BEHIND main.
Verified clean by the remediation pass: every third-party uses: is pinned @<sha> # vX.Y.Z, scripts/*.ts uses only strip-only syntax, and every workflow declares permissions:. No guard was modified.
Code Quality
All four validation gates pass. There was no autofix drift, so no PR was opened.
Oversight
Scope: every public, non-archived repo visible to fro-bot in fro-bot, marcusrbrown, bfra-me, psware-ps2 and pro-actions (35 enumerated). Non-public repos were enumerated but are excluded from this public report. The Dependabot API is disabled for pro-actions/peter-murray_workflow-application-token-action.
Failing latest run on the default branch
marcusrbrown/marcusrbrown.com — Fro Bot schedule run failed at 03:38 today: APIError status=400 about 1s into execution, reported as "recoverable LLM error" with no delivery surface. This is a provider or model config failure, not a repo defect. Next: check the model/provider inputs in that repo's fro-bot.yaml against the working ones in this repo.
marcusrbrown/extend-vscode — Publish has been failing for a long time. Next: triage or retire the job.
Next: start with the two criticals. Several repos already have Fro-Bot security PRs that are stale (below), so merging or rebasing those comes before opening new ones.
Stale PRs (>14d since last activity). 50 of these 54 are Fro-Bot autoheal PRs nobody has acted on:
New issues (<24h): bfra-me/renovate-action#3835 (a stale v9 Docker deprecation notice warns on every run). The rest are sibling daily reports.
Stale issues (>30d): marcusrbrown/gpt (19), marcusrbrown/vbs (15), marcusrbrown/renovate-config (5), marcusrbrown/extend-vscode (4), marcusrbrown/marcusrbrown.com (3), plus 1–2 each in 20 other repos. Next: a triage sweep on gpt and vbs.
Top hotspots (score = stale PRs + stale issues + critical/high alerts + failing default-branch runs + unassigned bugs)
marcusrbrown/gpt: 58 (15 stale PRs, 19 stale issues, 24 high)
marcusrbrown/extend-vscode: 40 (35 critical/high, 4 stale issues, failing Publish)
marcusrbrown/vbs: 23 (8 stale PRs, 15 stale issues)
Cross-Project Intelligence
Coverage is partial. I used the survey wiki for public tracked entries in metadata/repos.yaml. Non-public entries were not scanned in this report. marcusrbrown/copiloting is archived and its wiki page was last updated 2026-04-23. Every other public repo page is dated 2026-08-30 or later.
Adoptable:marcusrbrown/infra runs its privileged schedule job under step-security/harden-runner with egress-policy: block, split from a read-only content-triggered job. None of this repo's 29 workflows use harden-runner. The privileged fro-bot.yaml schedule path is the obvious first candidate.
Tool drift (current version from the npm registry; major drift included): ESLint 10.11.0 = latest. Prettier 3.9.1 vs 3.9.9 (patch only). TypeScript 6.0.3 vs 7.0.2 (major).Vitest 4.1.11 vs 5.0.1 (major). Renovate owns these bumps. Check the Dependency Dashboard (Dependency Dashboard #2828) to see whether they're held deliberately.
CI/conventions: No degraded jobs. No real TODO/FIXME drift (the two hits are a test fixture and the prompt text).
Track cross-repo Gateway operator control-surface rollout #3512 says the deployed gateway is pinned to fro-bot/agentv0.83.0 and that push (v0.85.0) is "not yet deployed". But marcusrbrown/infraapps/gateway/upstream.json pins v0.113.2. The live /operator/health still returns contractVersion: 1.6.0, so the contract gate holds. Whether push is live (VAPID secrets) is unverified.
Fix: the Gateway Rollout Tracker workflow owns these writes. Re-run it or refresh the body by hand. This report path does not edit it.
Autoheal PR pile-up across repos. 50 stale Fro-Bot PRs, including duplicate security PRs (bfra-me/github-app, bfra-me/github-action) and near-duplicate a11y fixes (marcusrbrown/gpt). Root cause: the per-repo autoheal dedup is not matching its own earlier PRs when titles differ. Smallest safe fix: in each affected repo's fro-bot.yaml prompt, make dedup key on the root cause or advisory ID, not the title. A human should close the duplicates; automation must not close PRs.
marcusrbrown/marcusrbrown.com Fro Bot APIError 400. Compare that repo's agent/model inputs with this repo's .github/workflows/fro-bot.yaml. Verify with a workflow_dispatch run.
Daily Fro Bot Report — 2026-09-24 (UTC)
Run Summary
permissions:all verified by the remediation pass.bootstrap/check-types/lint/testall pass (3710 tests).learning-proposalissues, so the compounding pipeline is stalled. Major drift on TypeScript and Vitest.Errored PRs
None. The remediation pass (comment) checked both check runs and legacy statuses. #3920 has 15 success / 3 skipped and is
BLOCKEDwaiting on review. #3901 has 14 success / 4 skipped and isBEHINDmain.Security
@humanfs/nodeGHSA-p498-v437-472g, medium, transitive dev dependency, fixed in 0.16.8. Renovate owns the fix. The remediation pass opened no security PR.peter-murray/workflow-application-token-actionto v2 #7, Upliftsync-settingsworkflow #9) are Scorecard posture checks with no file location.Control-Plane Integrity
Verified clean by the remediation pass: every third-party
uses:is pinned@<sha> # vX.Y.Z,scripts/*.tsuses only strip-only syntax, and every workflow declarespermissions:. No guard was modified.Code Quality
All four validation gates pass. There was no autofix drift, so no PR was opened.
Oversight
Scope: every public, non-archived repo visible to
fro-botinfro-bot,marcusrbrown,bfra-me,psware-ps2andpro-actions(35 enumerated). Non-public repos were enumerated but are excluded from this public report. The Dependabot API is disabled forpro-actions/peter-murray_workflow-application-token-action.Failing latest run on the default branch
APIError status=400about 1s into execution, reported as "recoverable LLM error" with no delivery surface. This is a provider or model config failure, not a repo defect. Next: check the model/provider inputs in that repo'sfro-bot.yamlagainst the working ones in this repo.Critical/high Dependabot alerts
Stale PRs (>14d since last activity). 50 of these 54 are Fro-Bot autoheal PRs nobody has acted on:
Aging PRs (>7d, not yet stale): fro-bot/space-bus (5), bfra-me/ha-addon-repository (5), marcusrbrown/mothership (3), marcusrbrown/ha-config (2), bfra-me/renovate-config (1), bfra-me/works (1), fro-bot/agent (1), marcusrbrown/Presentations (1), marcusrbrown/sparkle (1). Next: normal review cadence.
New issues (<24h): bfra-me/renovate-action#3835 (a stale v9 Docker deprecation notice warns on every run). The rest are sibling daily reports.
Stale issues (>30d): marcusrbrown/gpt (19), marcusrbrown/vbs (15), marcusrbrown/renovate-config (5), marcusrbrown/extend-vscode (4), marcusrbrown/marcusrbrown.com (3), plus 1–2 each in 20 other repos. Next: a triage sweep on gpt and vbs.
Unassigned bugs: bfra-me/ha-addon-repository#569, marcusrbrown/marcusrbrown.com#517, marcusrbrown/marcusrbrown.com#465, marcusrbrown/systematic#1005, marcusrbrown/systematic#740.
Top hotspots (score = stale PRs + stale issues + critical/high alerts + failing default-branch runs + unassigned bugs)
Cross-Project Intelligence
Coverage is partial. I used the survey wiki for public tracked entries in
metadata/repos.yaml. Non-public entries were not scanned in this report.marcusrbrown/copilotingis archived and its wiki page was last updated 2026-04-23. Every other public repo page is dated 2026-08-30 or later.marcusrbrown/infraruns its privileged schedule job understep-security/harden-runnerwithegress-policy: block, split from a read-only content-triggered job. None of this repo's 29 workflows use harden-runner. The privilegedfro-bot.yamlschedule path is the obvious first candidate.Progressive Improvement
learning-proposalissues. Learning proposal: (e86b0877) #3887–Learning proposal: (31309d62) #3891 are 10 days old and Learning proposal: (bd4b7e68) #3905–Learning proposal: (374ddfe7) #3909 are 3 days old. None has passed 14 days yet, but 10 open at once already trips the threshold. Improvement Metrics #3674 cannot detect this.Needs Human Attention
In Progress, so the status matches. The body disagrees with current evidence in two places:fro-bot/agentv0.83.0and that push (v0.85.0) is "not yet deployed". Butmarcusrbrown/infraapps/gateway/upstream.jsonpinsv0.113.2. The live/operator/healthstill returnscontractVersion: 1.6.0, so the contract gate holds. Whether push is live (VAPID secrets) is unverified.fro-bot.yamlprompt, make dedup key on the root cause or advisory ID, not the title. A human should close the duplicates; automation must not close PRs.APIError 400. Compare that repo's agent/model inputs with this repo's.github/workflows/fro-bot.yaml. Verify with aworkflow_dispatchrun.docs/solutions/, or close any that are rejected.peter-murray/workflow-application-token-actionto v2 #7/Upliftsync-settingsworkflow #9. Dismiss them with a reason, or accept them.Run Summary