| #1842 Reusable Workflow Runtime Self-Identity for Live Drift Audit |
GitHub shipped job.workflow_ref/job.workflow_sha on Sep 3 2026 β three weeks ago. The thin-caller ADR-0001 architecture and fleet_stub_drift.sh can absorb this immediately with no new dependencies. Directly addresses the drift-bug class from #1034. |
Initiative: Extend fleet_stub_drift.sh and the reusable workflow template to emit a runtime identity assertion on each execution, comparing the resolved SHA against the expected channel tag. Drift caught live, not just in nightly lint, closes a detection gap that scheduled audits structurally cannot cover. |
| #1839 ARM64 Runner Migration for Fleet-Wide CI Cost Reduction |
GitHub ARM64 runners for private repos launched Jan 2026 with a verified 39% pricing reduction. This org's CI is 100% bash/jq/Python with zero x86 binary dependencies β zero porting risk. The feature has been GA for 8 months with no reported issues. |
Initiative: Migrate all scheduled utility workflows (fleet-monitor, compliance-audit, health-checks) to ubuntu-24.04-arm runners in a phased rollout starting with lowest-risk jobs, measuring actual minute savings against baseline before rolling to the PR-review cascade. |
| #1841 MCP Server Provenance Pinning with Hash Attestation for Review Tiers |
A real-world malicious MCP server was disclosed in 2026; OX Security confirmed 10+ CVEs in Anthropic MCP SDKs affecting ~200K servers. This repo uses REVIEW_MCP_CONFIG for the deep review tier today β there is live exposure. |
Initiative: Implement an MCP server allowlist (name + version + hash tuples in a committed file) with a pre-flight verification step in the MCP-enabled review invocation path, blocking any server update that has not been explicitly reviewed and promoted via a signed PR. |
| #1838 Non-Required Check Circuit Breaker for Merge Pipeline Resilience |
A silent deadlock class exists today: one persistently failing non-required check causes every PR to appear CI-failing, halting the review pipeline with no fleet alert. ci-status.sh is the right insertion point and the circuit-breaker pattern is well-understood. |
Initiative: Add a circuit-breaker detector to ci-status.sh that tracks N consecutive failures of a non-required check across M distinct PRs, degrades it from the CI-passing determination automatically, and fires a fleet-monitor alert β turning a silent deadlock into a noisy, self-healing degradation. |
| #1157 GitInject-Class PR Content Sanitization Layer for Review Pipeline Defense |
The GitInject arXiv paper (Jun 2026) names GitHub Actions + Claude Code pipelines as the primary attack surface. OWASP reports a 340% YoY surge in prompt injection in CI/CD. review-one-pr.sh passes PR descriptions and commit messages to the LLM with no sanitization today. |
Initiative: Add a pre-LLM sanitization stage to review-one-pr.sh that detects and neutralizes injection patterns (hidden instructions, role-override attempts, data-exfiltration commands) in PR descriptions, commit messages, and code comments before they reach any agentic tier. |
Legend: π’ Ripe β ready to promote now Β· π‘ Soon β one gap to close Β· βͺ Not yet / covered
π’ Ripe to Promote
job.workflow_ref/job.workflow_shaon Sep 3 2026 β three weeks ago. The thin-caller ADR-0001 architecture andfleet_stub_drift.shcan absorb this immediately with no new dependencies. Directly addresses the drift-bug class from #1034.fleet_stub_drift.shand the reusable workflow template to emit a runtime identity assertion on each execution, comparing the resolved SHA against the expected channel tag. Drift caught live, not just in nightly lint, closes a detection gap that scheduled audits structurally cannot cover.ubuntu-24.04-armrunners in a phased rollout starting with lowest-risk jobs, measuring actual minute savings against baseline before rolling to the PR-review cascade.REVIEW_MCP_CONFIGfor the deep review tier today β there is live exposure.ci-status.shis the right insertion point and the circuit-breaker pattern is well-understood.ci-status.shthat tracks N consecutive failures of a non-required check across M distinct PRs, degrades it from the CI-passing determination automatically, and fires a fleet-monitor alert β turning a silent deadlock into a noisy, self-healing degradation.review-one-pr.shpasses PR descriptions and commit messages to the LLM with no sanitization today.review-one-pr.shthat detects and neutralizes injection patterns (hidden instructions, role-override attempts, data-exfiltration commands) in PR descriptions, commit messages, and code comments before they reach any agentic tier.π‘ Soon
needs-human-reviewholds are actually auto-approvable). Without that number the confidence threshold is arbitrary and the initiative has no success criterion.βͺ Not Yet / Covered
external.Already Approved (past triage)
These carry
idea:approvedand are active in the initiative pipeline β listed for reference, not re-ranked.