Skip to content

Daily Fro Bot Report — 2026-09-25 (UTC) #3927

Description

@fro-bot

Daily Fro Bot Report — 2026-09-25 (UTC)

Run Summary

Category Status Notes
Errored PRs ✅ Remediation pass checked #3920 and #3901 (both check runs and legacy statuses); no failures. Re-verified by the scheduled pass (run 36093828964): evidence
Security ⚠️ Re-verified (evidence). No critical/high Dependabot alerts in this repo. 1 medium transitive alert. Scorecard posture findings are open (BranchProtectionID and VulnerabilitiesID rated high).
Control-Plane Integrity ✅ Re-verified (evidence). SHA pinning, strip-only TS, and top-level permissions: verified across all workflows. Guards untouched.
Code Quality ✅ Re-verified (evidence). bootstrap / check-types / lint / test all green (3819 passed).
Oversight ⚠️ 5 failing default-branch checks, 2 repos with critical alerts, and a large stale remediation-PR backlog.
Cross-Project Intelligence ⚠️ Coverage partial: 30 of 34 tracked entries scanned from wiki repo pages.
Progressive Improvement ⚠️ 10 open learning proposals (pipeline stalled). TypeScript and Vitest are one major behind.

Errored PRs

Refreshed 2026-09-25 ~04:25Z by the scheduled pass (run 36093828964). Both remediation passes opened 0 PRs. #3920 is now BLOCKED even though every check is green, which means it is waiting on required review/merge gating rather than a CI failure.

None. The remediation pass opened no PRs. #3901 is green but BEHIND main. Its only change is to .github/workflows/renovate.yaml, so the branch update was left for merge time.

Security

  • Dependabot #59: @humanfs/node, medium, transitive, patched in 0.16.8. Renovate owns it.
  • Code scanning: 4 OpenSSF Scorecard posture findings (VulnerabilitiesID high, BranchProtectionID high, FuzzingID, CIIBestPracticesID). These are not code vulnerabilities.

Control-Plane Integrity

Clean. The only broad grant is permissions: read-all in scorecard.yaml, which is the upstream Scorecard pattern and read-only.

Code Quality

Green on main at 5d8f66b.

Oversight

Scope: every public, non-archived repo returned by user/repos (owner + collaborator + org member, paginated). Security is Dependabot only. Not checkable: pro-actions/peter-murray_workflow-application-token-action has Dependabot disabled.

Failing default-branch checks

Repo Failing check Next step
bfra-me/github-action Update Repo Settings Already tracked in #1611; fix .github/settings.yml.
bfra-me/ha-addon-repository Renovate / Renovate Read the latest Renovate run log. #569 (settings 500) may be related.
marcusrbrown/containers Renovate / Renovate Read the latest Renovate run log.
marcusrbrown/cortexkit_anthropic-auth Fro Bot Its autoheal report #11 has not updated since 2026-06-29. The daemon looks dead. Inspect the workflow run.
marcusrbrown/extend-vscode Pre-Release Validation (vulnerabilities) This is caused by the alert load below, not a CI bug.

Security alerts (Dependabot, open)

Stale PRs (created more than 7 days ago with no update in 14+ days). Most are Fro Bot remediation PRs that have gone past their useful life.

New since yesterday (substantive only)
fro-bot/agent#1663 (workspace container has no init), bfra-me/renovate-action#3835 (stale v9 deprecation notice), and fro-bot/agent#1666 (deterministic termination test). Triage in their repos.

Unassigned bugs
bfra-me/ha-addon-repository#569, marcusrbrown/marcusrbrown.com#465, #517, marcusrbrown/systematic#740, #1005. Assign an owner or fold them into each repo's autoheal queue.

Report sprawl
marcusrbrown/.dotfiles has 4 open daily reports (#2682, #2685, #2695, #2699), which means its close-older step is not running. marcusrbrown/renovate-config still has 3 open weekly reports from February and March.

Stale issues (more than 30 days)
There are many, concentrated in gpt (HeroUI #2162–#2175 and techdebt #2140–#2146, all March), vbs (2025 roadmap #150–#161 and convention drift #670–#694), and extend-vscode (#317–#319). Close or re-scope them in bulk; they are roadmap residue, not active work.

Top 3 hotspots (ranked by finding count)

  1. marcusrbrown/gpt: 15 stale PRs, 24 high alerts, and more than 15 stale issues.
  2. marcusrbrown/vbs: 10 stale PRs (7 are Fro Bot remediation), the grouped update frozen for 32 days, and more than 15 stale issues.
  3. marcusrbrown/extend-vscode: 1 critical and 34 high alerts, a failing default-branch check, and stale roadmap issues.

Cross-Project Intelligence

Coverage is partial. metadata/repos.yaml lists 34 entries. 30 were scanned through their wiki repo pages and the [[github-actions-ci]] topic. marcusrbrown/copiloting is archived and was skipped. 3 entries are excluded from public reporting.

These findings apply to this repo:

  1. Key dedup on merge state, not just on "an open PR exists" (source: vbs and gpt, wiki section A Security Remediation PR Has a Shelf Life, 2026-09-21). This repo's autoheal dedup rule reuses any open Fro Bot PR for the same root cause, so a CONFLICTING remediation PR can block a live refile indefinitely. The fleet-wide stale-PR list above is that failure at scale. Adopt: treat mergeStateStatus: DIRTY older than 14 days as "no usable PR".
  2. Verify tracker claims against deployed truth (source: category 8 below; recorded in the wiki as A Rollup Tracker Whose Structured Source Omits the Rows It Narrates). The Gateway Rollout Tracker preflight keys on Project/issue state, which cannot see drift in rows the Project never held.
  3. Split the Fro Bot workflow into a read-only content job and a privileged scheduled job (source: marcusrbrown/infra, 2026-09-06). Evaluate whether fro-bot.yaml here already separates attacker-reachable triggers from the credentialed autoheal. This is report-only and was not verified this run.

Progressive Improvement

  • Learning-proposal pipeline stalled. 10 open: #3887–#3891 (11 days old) and #3905–#3909 (4 days old). None has passed 14 days yet; the first cohort does on 2026-09-28. Having two or more open means authoring into docs/solutions/ is not keeping up. #3674 reading healthy is not evidence against this.
  • Tool-version drift (source: npm registry npm view <pkg> version; major drift included): TypeScript 6.0.3 → 7.0.2 (major), Vitest 4.1.11 → 5.0.1 (major), Prettier 3.9.1 → 3.9.9 (patch, within minor), ESLint 10.11.0 (current). Renovate owns these; check the Dependency Dashboard #2828 for pending majors.
  • Stale TODO/FIXME: none. The only match is a fixture string in scripts/check-private-leak.test.ts:219.
  • Wiki lint #3903 has been open since 2026-09-20. Its fix must land through the data branch.

Needs Human Attention

  1. Gateway rollout tracker #3512 is stale (Project 1 status is In Progress, which is consistent). The body claims the deployed gateway is v0.83.0; marcusrbrown/infra apps/gateway/upstream.json shows ref: v0.113.2. The body claims the latest release is v0.85.0; the actual latest is v0.115.1 (2026-09-24). The matrix lists fro-bot/dashboard#179 as Open, but it is CLOSED. Project 1 has no items for dashboard#179, agent#1109, agent#1111, or push #1152–#1165. Health still returns contractVersion 1.6.0, which matches the body. Fix: refresh the body's pin, release, and chore(deps): update bfra-me/renovate-action action to v2.2.4 #179 rows, and add the missing items to Project 1. Tracker writes belong to the Gateway Rollout Tracker workflow, not to this report.
  2. Gateway deploy awaiting manual approval since 2026-09-21T20:02Z: marcusrbrown/infra#1412. This is a human gate.
  3. Critical alerts in marcusrbrown/containers and marcusrbrown/extend-vscode. Triage those first.
  4. Learning proposals: author the 10 open proposals into docs/solutions/ or close the rejected ones.
  5. #3901: update the branch before merging.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions