You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
No stale issues. 6 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~20 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are Renovate/release automation, 0–3 days old: #1016 (3 days), #1051 (0 days).
Unassigned Bugs
No open issues with the bug label. Note: operator issue #1036 (run-index scale follow-ups) remains unlabeled and unassigned (carried over, not new).
Recommended Actions
Review/merge the 2 open dependency & release PRs (#1016, #1051).
No stale issues. 6 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~19 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 5 open PRs are Renovate/release automation, 0–2 days old: #1016, #1021, #1022, #1042, #1043.
Unassigned Bugs
No open issues with the bug label. Note: new operator issue #1036 (run-index scale follow-ups) is unlabeled and unassigned.
No stale issues. 7 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~18 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Security posture steady: Dependabot 0 open ✅; code scanning holds at 1 open (carried over from last run).
★16 PRs merged since last run (Bun migration + operator/deploy hardening): pnpm→Bun workspace migration (#1002) with Bun CI/cache hardening (#1006) and verified Bun install in deploy images (#1008); operator fixes — GET /operator/repos now mounts (#1020) and deny-key backfill runnable in the shipped image (#1023); plus Renovate/runner reconciliation (#1009, #1011, #1012, #1025).
★Releases: v0.76.2 and v0.76.3 merged (#1007, #1019); v0.76.4 pending (#1026).
✅ 13 success, 3 skipped, 1 in progress (incl. this run)
Security alerts (Dependabot)
0 open ✅ (9 prior alerts now fixed)
Security alerts (code scanning)
1 open ⚠️ (down from 4)
Stale Issues (no activity >30 days)
No stale issues. 8 open issues. Oldest activity is #763 and #775 (~17 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
No open issues with the bug label. Note: new operator issues #1000 and #1001 describe defects but are unlabeled.
Recommended Actions
Review/merge the 7 open dependency & release PRs (#1007, #1013–#1018).
Triage new operator defects #1000 and #1001; apply bug label if confirmed.
Progress the gateway/security cluster (#763, #775, #919) before they reach 30 days stale.
Investigate the 1 remaining open code-scanning alert.
Notes
Dependabot alerts now resolve to 0 open (all 30 historical alerts in fixed state); the 9 previously carried-over alerts have been fixed.
Code-scanning open alerts dropped from 4 to 1.
Stale issue/PR lists empty this run, so no ★ first-time-stale markers apply.
2026-06-23 (UTC)
Summary Metrics
Metric
Value
New issues (since last run)
0
Open PRs
1 (★9 merged since last run)
Stale issues (>30 days)
0
Stale PRs (>7 days)
0
Main branch checks
✅ 11 success, 3 skipped, 1 in progress (incl. this run)
Security alerts (Dependabot)
9 open ⚠️ (carried over)
Security alerts (code scanning)
4 open ⚠️ (carried over)
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~16 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. The single open PR (#989, chore(release): pending release v0.76.1) was updated today.
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
Triage security issue #919 — example fro-bot.yaml exposes secrets to fork PRs via issue_comment checkout (add security label + assignee)
Plan/scope enhancement #907 — gateway inbound control surface + operator web auth (operator API surface documented/pinned today via #996)
Plan work on remaining gateway/harness issues: #763, #775
Review/merge open PR #989: chore(release): pending release v0.76.1
Notes
Security posture unchanged: Dependabot holds at 9 open, code scanning holds at 4 open (both carried over) — recommend prompt triage.
★9 PRs merged since last run (release v0.76.0 + build/harness hardening, advancing #907): operator API surface documented + pinned (#996), reverted harness install-time shims (#995) after the shim attempt (#992), operator control-surface plan reconciled to shipped reality (#994), license-notice collection before bundling (#991), dist hidden-unicode scrub/verify independent of the bundler (#988), plus build-pipeline lifecycle + durable-dist solution docs (#993, #990).
✅ 8 success, 2 skipped, 2 in progress (incl. this run)
Security alerts (Dependabot)
9 open ⚠️ (carried over)
Security alerts (code scanning)
4 open ⚠️ (carried over)
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~15 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs — zero open PRs (queue fully drained).
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
Triage security issue #919 — example fro-bot.yaml exposes secrets to fork PRs via issue_comment checkout (add security label + assignee)
Plan/scope enhancement #907 — gateway inbound control surface + operator web auth (web tool-approval flow shipped today via #986)
Plan work on remaining gateway/harness issues: #763, #775
✅ PR queue fully drained — 0 open PRs
Notes
Security posture unchanged: Dependabot holds at 9 open, code scanning holds at 4 open (both carried over) — recommend prompt triage.
★8 PRs merged since last run (operator web tool-approval + OpenCode 1.17.9 upgrade, advancing #907): web tool-approval flow for the operator surface (#986), OpenCode upgrade to 1.17.9 with SQLite-reliability carries (#984), default harness build 1.17.9+harness.bd89c818 (#985), squash carries into one fingerprint commit (#982), committed-bundle attribution + SBOM hygiene (#979).
No new issues since last run; #973 (operator OAuth return_to) was opened and resolved/closed via #977. #919 (security) and #907 (enhancement) still awaiting triage.
CI: ✅ main checks green; this scheduled run + pending release in progress.
✅ 11 success, 4 skipped; this scheduled run in progress
Security alerts (Dependabot)
9 open ⚠️ (carried over)
Security alerts (code scanning)
4 open ⚠️ (↓ from 5)
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~14 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs — ★zero open PRs (queue fully drained).
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
Recommended Actions
Triage 9 open Dependabot alerts (carried over from last run) — review Security → Dependabot
✅ CI, CodeQL, Scorecard success; this scheduled run in progress
Security alerts (Dependabot)
9 open ⚠️ (↑ from 2)
Security alerts (code scanning)
5 open ⚠️
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~13 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. The single open PR (#957) was updated today.
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
✅ CI, CodeQL, Scorecard success; this scheduled run in progress
Security alerts (Dependabot)
★2 open ⚠️
Security alerts (code scanning)
5 open ⚠️
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~12 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs opened/updated today.
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
Recommended Actions
★Triage 2 open Dependabot alerts (newly surfaced this run, was 0) — review Security → Dependabot
✅ ~24 success, ~4 skipped, 1 in progress (status: pending)
Security alerts (Dependabot)
0 open ✅
Security alerts (code scanning)
★4 open ⚠️
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~11 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 3 open PRs updated within the last day (all dependency/release automation).
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).
★Code scanning reports 4 open alerts (Dependabot remains 0). First appearance in this report — recommend triage.
All 3 open PRs are automation (Renovate deps + pending release); none stale.
Dependency Dashboard #579 active (auto-updated by Renovate).
No daily sections older than 14 days to archive this run; Historical Summary unchanged.
2026-06-17 (UTC)
Summary Metrics
Metric
Value
New issues (since last run)
0
Open PRs
2 (★6 merged since last run)
Stale issues (>30 days)
0
Stale PRs (>7 days)
0
Main branch checks
✅ ~9 success, 2 skipped, 1 in progress
Security alerts (Dependabot)
0 open ✅
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (10 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are 0 days old (opened today).
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled) and #763/#775 (reliability/harness) remain unassigned.
Recommended Actions
Triage security issue #919 — example fro-bot.yaml exposes secrets to fork PRs via issue_comment checkout (add security label + assignee)
Plan/scope enhancement #907 — gateway inbound control surface + operator web auth (web-command spine actively shipping; see merged PRs below)
Plan work on remaining gateway/harness issues: #763, #775
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (9 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are 0 days old (opened today).
Unassigned Bugs
No open issues with the bug label. Note: #919 (security, unlabeled) and #763/#775 (reliability/harness) remain unassigned.
Recommended Actions
★Triage security issue #919 — example fro-bot.yaml exposes secrets to fork PRs via issue_comment checkout (add security label + assignee)
Plan/scope enhancement #907 — gateway inbound control surface + operator web auth
Plan work on remaining gateway/harness issues: #763, #775
✅ All Dependabot security alerts remain resolved
Review/merge 2 open PRs:
★#928: build(deps): update Node.js to 21f403a (opened today)
#926: fix(deps): update aws-sdk-js-v3 monorepo to v3.1068.0
Notes
★2 PRs merged since last run:
#927: fix(cache): save session database when storage directory is empty
Runs archived: 101 prior runs (2026-02-24 through 2026-06-12).
No unresolved items carried forward from archived runs — all prior security alerts in those runs resolved (incl. #72 brace-expansion, #814 topology guard), and no long-stale PRs/issues pending. Current security posture (Dependabot 0 open, code scanning 2 open) and untriaged issues #1036/#919/#907/#763/#775 are tracked in the dated sections above, not here.
2026-06-27 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~20 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are Renovate/release automation, 0–3 days old: #1016 (3 days), #1051 (0 days).
Unassigned Bugs
No open issues with the
buglabel. Note: operator issue #1036 (run-index scale follow-ups) remains unlabeled and unassigned (carried over, not new).Recommended Actions
Notes
869d4dd— "fix: split Renovate node artifact updates (fix: split Renovate node artifact updates #1052)".2026-06-26 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~19 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 5 open PRs are Renovate/release automation, 0–2 days old: #1016, #1021, #1022, #1042, #1043.
Unassigned Bugs
No open issues with the
buglabel. Note: new operator issue #1036 (run-index scale follow-ups) is unlabeled and unassigned.Recommended Actions
Notes
GET /operator/runsrun-index route (#1035), operator listing fanout dedupe (#1038), OpenCode 1.17.11 (#1040), harness-release workspace deps fix (#1041), plus Renovate/deps updates (#1018, #1024, #1028, #1029, #1034, #1037).6e323f1— "fix: install workspace deps for harness release (fix: install workspace deps for harness release #1041)".2026-06-25 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 7 open issues including meta (#252, #579). Oldest activity is #763 and #775 (~18 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 6 open PRs are Renovate/release automation, 0–1 days old: #1016, #1018, #1021, #1022, #1026, #1028.
Unassigned Bugs
No open issues with the
buglabel. Note: new operator issue #1027 (run-index route) is unlabeled and unassigned.Recommended Actions
GET /operator/runsrun-index (advances #907).Notes
GET /operator/reposnow mounts (#1020) and deny-key backfill runnable in the shipped image (#1023); plus Renovate/runner reconciliation (#1009, #1011, #1012, #1025).b38c559— "fix(workflows): update renovate action to v4.16.30 (fix(workflows): update renovate action to v4.16.30 #1025)".2026-06-24 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 8 open issues. Oldest activity is #763 and #775 (~17 days) — under the 30-day threshold. Next step: triage the gateway/security cluster (#763, #775, #919) before they cross 30 days.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 7 open PRs are Renovate/release automation updated today: #1007, #1013, #1014, #1015, #1016, #1017, #1018.
Unassigned Bugs
No open issues with the
buglabel. Note: new operator issues #1000 and #1001 describe defects but are unlabeled.Recommended Actions
buglabel if confirmed.Notes
fixedstate); the 9 previously carried-over alerts have been fixed.2026-06-23 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~16 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. The single open PR (#989,
chore(release): pending release v0.76.1) was updated today.Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)chore(release): pending release v0.76.1Notes
7defaba— "docs(gateway): document and pin the operator API surface (docs(gateway): document and pin the operator API surface #996)".2026-06-22 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~15 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs — zero open PRs (queue fully drained).
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)Notes
1ad74fc— "feat(gateway): web tool-approval flow for the operator surface (feat(gateway): web tool-approval flow for the operator surface #986)".return_to) was opened and resolved/closed via #977. #919 (security) and #907 (enhancement) still awaiting triage.2026-06-21 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~14 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs — ★zero open PRs (queue fully drained).
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)Notes
aaaf91d— "refactor(build): track third-party notices deterministically + add CI SBOM (refactor(build): track third-party notices deterministically + add CI SBOM #978)".2026-06-20 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~13 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. The single open PR (#957) was updated today.
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)chore(release): pending release v0.72.0Notes
2026-06-19 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~12 days) — under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs opened/updated today.
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)feat(gateway): retain the operator token and resolve runs server-sidechore(release): pending release v0.72.0Notes
2026-06-18 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (~11 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 3 open PRs updated within the last day (all dependency/release automation).
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled), #763, and #775 remain unassigned (carried over, not new).Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)build(deps): update Node.js to v24.17.0chore(dev): update vitest monorepo to v4.1.9chore(release): pending release v0.69.0Notes
2026-06-17 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (10 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are 0 days old (opened today).
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled) and #763/#775 (reliability/harness) remain unassigned.Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)feat(gateway): add operator audit seam(opened today)chore(release): pending release v0.67.0(opened today)Notes
feat(gateway): add operator route guardrail seam— ★FEATUREfeat(gateway): add operator listener topology— ★FEATUREchore(release): pending release v0.66.0feat(gateway): prepare web operator surface spine— ★FEATUREbuild(deps): update Node.js to 21f403afix(deps): update aws-sdk-js-v3 monorepo to v3.1068.02026-06-16 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919). Oldest activity is #763/#775 (9 days) — well under the 30-day threshold.
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are 0 days old (opened today).
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled) and #763/#775 (reliability/harness) remain unassigned.Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)build(deps): update Node.js to 21f403a(opened today)fix(deps): update aws-sdk-js-v3 monorepo to v3.1068.0Notes
fix(cache): save session database when storage directory is emptychore(release): pending release v0.65.02026-06-15 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/security issues (#763, #775, #907, #919).
Stale PRs (no activity >7 days/>14 days)
No stale PRs. Both open PRs are 0–1 days old.
Unassigned Bugs
No open issues with the
buglabel. Note: #919 (security, unlabeled) and #763/#775 (reliability/harness) remain unassigned.Recommended Actions
fro-bot.yamlexposes secrets to fork PRs viaissue_commentcheckout (addsecuritylabel + assignee)fix(deps): update aws-sdk-js-v3 monorepo to v3.1068.0(opened today)chore(release): pending release v0.65.0Notes
chore(dev): update eslint monorepo to v10.5.0chore(deps): update GitHub Actions to v6.0.9ci(renovate): hold release-pipeline packages for 3 daysdocs(solutions): transport-agnostic execution and approval seamfeat(gateway): transport-agnostic execution and approval seam— ★FEATUREdocs(solutions): capture compose topology egress-guard hardeningchore(release): pending release v0.64.3docs: Gateway control surface spine — Phase A implementation planfix(deploy): reject host-namespace-sharing compose keys in the topology guard— ★SECURITYbuild(deps): update dependency @fro.bot/systematic to v2.32.0chore(deps): update pnpm to v11.6.0fix(deploy): reject egress-escalation compose keys in the topology guard— ★SECURITYfix(deploy): reject egress-weakening compose keys in the topology guard— ★SECURITYci(deps): update bfra-me/.github to v4.16.26docs(wiki): update project wikibuild(deps): update dependency @fro.bot/systematic to v2.31.1chore(release): pending release v0.64.2fix(session): scope schedule sessions per run to stop silent no-opsfix(deploy): close egress-relay bypass in the topology guard + add live egress smoke— ★resolves Topology guard misses sidecar egress relays on non-mitmproxy non-internal networks #814chore(release): pending release v0.64.1fix(deps): update aws-sdk-js-v3 monorepo to v3.1067.0ci(deps): update dependency npm to v11.17.0487f719— "chore(deps): update GitHub Actions to v6.0.9 (chore(deps): update GitHub Actions to v6.0.9 #924)"2026-06-14 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/workspace issues (#745, #763, #775, #814).
Stale PRs (no activity >7 days/>14 days)
No stale PRs — ★zero open PRs (queue fully drained).
Unassigned Bugs
No open issues with the
buglabel. Note: #814 (security) remains unassigned.Recommended Actions
Notes
feat: default to OpenCode harness build 1.17.6+harness.13169873— ★FEATUREchore(release): pending release v0.64.0feat(opencode): upgrade to 1.17.6— ★FEATUREdocs: harness rollout + release-pipeline incident learningschore(release): pending release v0.63.0fix(harness): publish harness releases under non-v tagsfeat(deploy): run the harness OpenCode build in the workspace executor— ★FEATUREfeat(action): default to OpenCode harness build 1.17.3+harness.94c10df9— ★FEATUREfeat(harness): build and publish musl Linux release assetsfix(deps): update aws-sdk-js-v3 monorepo to v3.1066.0feat(action): run the harness OpenCode build by default— ★FEATUREchore(deps): update pnpm to v11.5.3chore(dev): update dependency @vitest/eslint-plugin to v1.6.20chore(release): pending release v0.63.0chore(deps): update bfra-me/renovate-config preset to v5.2.374c4601— "feat: default to OpenCode harness build 1.17.6+harness.13169873 (feat: default to OpenCode harness build 1.17.6+harness.13169873 #895)"2026-06-13 (UTC)
Summary Metrics
Stale Issues (no activity >30 days)
No stale issues. 6 open issues including meta (#252, #579) and 4 gateway/workspace issues (#745, #763, #775, #814).
Stale PRs (no activity >7 days/>14 days)
No stale PRs. All 4 open PRs are 0–1 days old.
Unassigned Bugs
No open issues with the
buglabel. Note: #814 (security) remains unassigned.Recommended Actions
chore(deps): update pnpm to v11.5.3(opened today)chore(dev): update dependency @vitest/eslint-plugin to v1.6.20(opened today)chore(release): pending release v0.63.0(opened today)chore(deps): update bfra-me/renovate-config preset to v5.2.3(opened today)Notes
fix(harness): publish prerelease packages with explicit --tag latestfix(harness): set GH_REPO for the release stepfix(harness): only version-check the runner-native binary in releasechore(release): pending release v0.62.0fix(release): bump semantic-release to 25.0.5 to restore Perform Releasefeat(harness): publish a GitHub Release and let the action run the harness build— ★FEATUREfeat(harness): post-bridge hardening — redaction, doctor version, per-ref provenance— addresses Harness: post-bridge hardening (merge-agent isolation, doctor version check, per-ref provenance) #775docs(gateway): correct misleading tool-event comment in run-coredocs(solutions): capture duplicate-version-source drift learningbuild(dev): update semantic-release monorepo to v25.0.4chore(dev): update Prettier packages to v3.8.4chore(release): pending release v0.62.0fix(deps): update aws-sdk-js-v3 monorepo to v3.1065.0fix(deps): update dependency hono to v4.12.250989350— "fix(harness): publish prerelease packages with explicit --tag latest (fix(harness): publish prerelease packages with explicit --tag latest #882)"Historical Summary
Runs archived: 101 prior runs (2026-02-24 through 2026-06-12).
No unresolved items carried forward from archived runs — all prior security alerts in those runs resolved (incl. #72 brace-expansion, #814 topology guard), and no long-stale PRs/issues pending. Current security posture (Dependabot 0 open, code scanning 2 open) and untriaged issues #1036/#919/#907/#763/#775 are tracked in the dated sections above, not here.