Skip to content

Daily Fro Bot Report — 2026-09-24 (UTC) #3923

Description

@fro-bot

Daily Fro Bot Report — 2026-09-24 (UTC)

Run Summary

Category Status Notes
Errored PRs ✅ Remediation pass found no failing PRs (evidence). #3920 and #3901 are all green.
Security ⚠️ This repo: 1 medium transitive dev alert, below the remediation threshold. 4 Scorecard posture alerts are old.
Control-Plane Integrity ✅ SHA pinning, strip-only TS and top-level permissions: all verified by the remediation pass.
Code Quality ✅ bootstrap / check-types / lint / test all pass (3710 tests).
Oversight ⚠️ 3 repos with a failing latest run on the default branch. 2 repos with critical alerts. 54 stale PRs, 50 of them Fro-Bot-authored.
Cross-Project Intelligence ⚠️ Partial coverage. 1 adoptable pattern. 1 stale wiki page. Non-public tracked entries were not scanned.
Progressive Improvement ⚠️ 10 open learning-proposal issues, so the compounding pipeline is stalled. Major drift on TypeScript and Vitest.

Errored PRs

None. The remediation pass (comment) checked both check runs and legacy statuses. #3920 has 15 success / 3 skipped and is BLOCKED waiting on review. #3901 has 14 success / 4 skipped and is BEHIND main.

Security

Control-Plane Integrity

Verified clean by the remediation pass: every third-party uses: is pinned @<sha> # vX.Y.Z, scripts/*.ts uses only strip-only syntax, and every workflow declares permissions:. No guard was modified.

Code Quality

All four validation gates pass. There was no autofix drift, so no PR was opened.

Oversight

Scope: every public, non-archived repo visible to fro-bot in fro-bot, marcusrbrown, bfra-me, psware-ps2 and pro-actions (35 enumerated). Non-public repos were enumerated but are excluded from this public report. The Dependabot API is disabled for pro-actions/peter-murray_workflow-application-token-action.

Failing latest run on the default branch

  • marcusrbrown/marcusrbrown.com — Fro Bot schedule run failed at 03:38 today: APIError status=400 about 1s into execution, reported as "recoverable LLM error" with no delivery surface. This is a provider or model config failure, not a repo defect. Next: check the model/provider inputs in that repo's fro-bot.yaml against the working ones in this repo.
  • marcusrbrown/extend-vscode — Publish has been failing for a long time. Next: triage or retire the job.
  • bfra-me/github-action — Update Repo Settings. Probably the same root cause as Update Repo Settings job fails with 500 bfra-me/ha-addon-repository#569 (Update Repo Settings returns 500). Next: triage both together.

Critical/high Dependabot alerts

  • Critical: marcusrbrown/containers (1 critical, 1 high), marcusrbrown/extend-vscode (1 critical, 34 high).
  • High: marcusrbrown/gpt (24), marcusrbrown/Presentations (8), bfra-me/github-app (3), marcusrbrown/marcusrbrown (3), marcusrbrown/sparkle (3), marcusrbrown/marcusrbrown.github.io (2), marcusrbrown/cortexkit_anthropic-auth (1).
  • Next: start with the two criticals. Several repos already have Fro-Bot security PRs that are stale (below), so merging or rebasing those comes before opening new ones.

Stale PRs (>14d since last activity). 50 of these 54 are Fro-Bot autoheal PRs nobody has acted on:

Aging PRs (>7d, not yet stale): fro-bot/space-bus (5), bfra-me/ha-addon-repository (5), marcusrbrown/mothership (3), marcusrbrown/ha-config (2), bfra-me/renovate-config (1), bfra-me/works (1), fro-bot/agent (1), marcusrbrown/Presentations (1), marcusrbrown/sparkle (1). Next: normal review cadence.

New issues (<24h): bfra-me/renovate-action#3835 (a stale v9 Docker deprecation notice warns on every run). The rest are sibling daily reports.

Stale issues (>30d): marcusrbrown/gpt (19), marcusrbrown/vbs (15), marcusrbrown/renovate-config (5), marcusrbrown/extend-vscode (4), marcusrbrown/marcusrbrown.com (3), plus 1–2 each in 20 other repos. Next: a triage sweep on gpt and vbs.

Unassigned bugs: bfra-me/ha-addon-repository#569, marcusrbrown/marcusrbrown.com#517, marcusrbrown/marcusrbrown.com#465, marcusrbrown/systematic#1005, marcusrbrown/systematic#740.

Top hotspots (score = stale PRs + stale issues + critical/high alerts + failing default-branch runs + unassigned bugs)

  1. marcusrbrown/gpt: 58 (15 stale PRs, 19 stale issues, 24 high)
  2. marcusrbrown/extend-vscode: 40 (35 critical/high, 4 stale issues, failing Publish)
  3. marcusrbrown/vbs: 23 (8 stale PRs, 15 stale issues)

Cross-Project Intelligence

Coverage is partial. I used the survey wiki for public tracked entries in metadata/repos.yaml. Non-public entries were not scanned in this report. marcusrbrown/copiloting is archived and its wiki page was last updated 2026-04-23. Every other public repo page is dated 2026-08-30 or later.

  • Adoptable: marcusrbrown/infra runs its privileged schedule job under step-security/harden-runner with egress-policy: block, split from a read-only content-triggered job. None of this repo's 29 workflows use harden-runner. The privileged fro-bot.yaml schedule path is the obvious first candidate.
  • Otherwise nothing new beyond earlier reports.

Progressive Improvement

Needs Human Attention

  1. Gateway tracker drift (Track cross-repo Gateway operator control-surface rollout #3512 vs Project 1). Both show Track cross-repo Gateway operator control-surface rollout #3512 as open / In Progress, so the status matches. The body disagrees with current evidence in two places:
  2. Autoheal PR pile-up across repos. 50 stale Fro-Bot PRs, including duplicate security PRs (bfra-me/github-app, bfra-me/github-action) and near-duplicate a11y fixes (marcusrbrown/gpt). Root cause: the per-repo autoheal dedup is not matching its own earlier PRs when titles differ. Smallest safe fix: in each affected repo's fro-bot.yaml prompt, make dedup key on the root cause or advisory ID, not the title. A human should close the duplicates; automation must not close PRs.
  3. marcusrbrown/marcusrbrown.com Fro Bot APIError 400. Compare that repo's agent/model inputs with this repo's .github/workflows/fro-bot.yaml. Verify with a workflow_dispatch run.
  4. Learning proposals. Write up Learning proposal: (e86b0877) #3887–Learning proposal: (31309d62) #3891 and Learning proposal: (bd4b7e68) #3905–Learning proposal: (374ddfe7) #3909 into docs/solutions/, or close any that are rejected.
  5. Scorecard alerts feat: set default settings #1/feat: add Renovate workflow for dependency auto-updates #5/Update peter-murray/workflow-application-token-action to v2 #7/Uplift sync-settings workflow #9. Dismiss them with a reason, or accept them.
Run Summary
  • Run: 35953969280 (schedule, oversight half, working-dir)
  • Remediation evidence: Daily Fro Bot Report — 2026-09-23 (UTC) #3917 comment 5807426578 (0 mutations)
  • Repos enumerated: 38 (35 public reported). Dependabot unavailable on 1.
  • Wiki writes: none from this pass. The working tree carries a data-branch wiki sync from earlier in the job, which I left untouched.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions