Skip to content

Weekly Report 2026-08-18 #2390

Description

@clawgenti

Org Weekly Report: 2026-08-11 -- 2026-08-18

Generated for rossoctl by the github-weekly-report skill.

Org-Wide Summary

Repo Merged PRs Open PRs Open Issues New Issues CI Pass Rate Status
cortex 11 20 33 3 19/30 (63%) active
rossoctl 6 24 191 15 19/30 (63%) active
automation 5 4 6 2 30/30 (100%) active
workload-harness 5 1 11 1 14/30 (47%) active
agent-skills 2 1 1 0 22/30 (73%) active
operator 2 5 16 2 30/30 (100%) active
examples 1 36 14 1 22/30 (73%) active
.github 0 1 3 0 22/30 (73%) quiet
TOTAL 32 92 275 24

Cross-Repo Highlights

Multi-repo contributors

  • @rubambiza was the busiest cross-repo contributor, merging into agent-skills, automation, and workload-harness (6 PRs) — largely the org migration work: repointing reusable-workflow refs to rossoctl/.github (automation#51, workload-harness#60, agent-skills#31), decomposing program-lib.sh into portable modules (automation#50), and the link-health fixer breadcrumb (automation#56).
  • @vz-ibm drove cortex and workload-harness (5 PRs) on the SPARC service: WatsonX reasoning-model support (cortex#739), request-logging docs (cortex#741), and the authbridge SPARC plugin integration in the harness (workload-harness#54).
  • @evaline-ju touched cortex, examples, and rossoctl (3 PRs), including the session budget-enforcement plugin (cortex#723) and link fixes.
  • @esnible was the dominant contributor in rossoctl — the busiest repo by issue volume — landing the identity-config endpoint (feat: Add PUT /{namespace}/{name}/identity-config endpoint #2369) and k8s resource-limit overrides (feat: allow k8sResourceLimits/k8sResourceRequests overrides for agents and tools #2383), plus a cortex plugin-catalog doc.

Org-wide CI

  • Aggregate pass rate is 178/240 (74%). automation and operator are the clean repos at 100%.
  • workload-harness drags the average down at 47% — the failing workflows are pr-verifier.yml (3 failures) and project.yml (2). cortex and rossoctl both sit at 63%, with cortex's "Security Scans" (3) and "CI" (2) the main culprits.

Security concerns (open PRs flagged SECURITY, unreviewed >7 days)

Dependabot accumulation

  • 64 open dependabot PRs across the org — well past the batching threshold. Breakdown: examples 36, cortex 16, rossoctl 9, operator 3. The examples backlog alone is the single largest review liability this week.

Shared themes

  • Org rename tail — reusable-workflow repointing and program-lib modularization landed across three repos.
  • AIAC / SPARC buildout — event broker + OPA enforcement (cortex#752/Feat/terraform validation checks #754), plus harness integration, is the dominant feature thread.
  • Link-health automation — clawgenti-authored broken-link fixes and reports recur across rossoctl, automation, and workload-harness.

Active Epics

Epic Lead Key Result (inferred) This Week
rossoctl/rossoctl#2244 Cortex Phase 1 @esnible Ship Cortex data-plane phase 1 1 sub-issue closed (#684), 4 open
rossoctl/rossoctl#2277 AIAC MVP @omerboehm Agent-Identity-and-Access-Control MVP 1 sub-issue closed, 2 open
rossoctl/rossoctl#1461 User access to Kagenti Sandbox with OpenShell @aslom Multi-tenant sandbox access via OpenShell 15 open
rossoctl/rossoctl#1817 Sandbox CRD extensions for agent state & session mgmt @cwiklik Stateful agent infra (CRD extensions) 8 open
rossoctl/rossoctl#1469 Rossoctl Documentation and Usability Improvements @esnible Docs + usability polish 6 open
rossoctl/rossoctl#1460 Authorization and Identity for Event-Driven Agent @aslom Authz/identity for event-driven agents 8 open
rossoctl/rossoctl#2254 Automated cross-version benchmarking for regression @webchang Cross-version regression benchmarking 10 open
rossoctl/rossoctl#2074 Skill-bound agent identity — deny tool access on scope unassigned Deny tool access outside granted scope 6 open
rossoctl/rossoctl#2087 AIAC Quality Framework — Guardrails, Testing @omerboehm AIAC guardrails + testing framework 4 open
rossoctl/rossoctl#1302 Runtime-Attested Agent Card @webchang Runtime attestation for agent cards 6 open

Action Items

# Action Repo Owner Priority
1 Merge APPROVED security fix #490 (go.sum regen), open+approved 28 days operator @Ibrahim2595 P0
2 Merge or re-triage APPROVED security PR #677 (tls_bridge upstream_insecure), open 31 days cortex @aslom P0
3 Investigate workload-harness CI at 47% — pr-verifier.yml (3 fails) and project.yml (2 fails) workload-harness @vz-ibm P0
4 Review 21–31 day security dep bumps #704, #2224, #2235–2240 cortex, rossoctl @esnible P1
5 Fix cortex CI — "Security Scans" (3) and "CI" (2) failures at 63% pass rate cortex @oblinder P1
6 Batch-review the 36 open dependabot PRs (many SECURITY-flagged, 17–31 days) examples @evaline-ju P2
7 Batch-review the 16 open dependabot PRs cortex @vz-ibm P2
8 Batch-review the 9 open dependabot PRs rossoctl @esnible P2
9 Triage 24 broken-link issues opened this week (#2373#2382, workload-harness#62) rossoctl @clawgenti P3
10 Resolve stale non-dependabot PRs >16 days: #2335, #2327 rossoctl @w3lld1, @Alan-Cha P3

cortex

Merged PRs (11)

Top contributors: @app/dependabot (4), @vz-ibm (3), @oblinder (2), @esnible (1), @evaline-ju (1)

# Title Author Merged
#757 Docs: Add plugin catalog @esnible 2026-08-14
#754 Feat: AIAC Event Broker + Keycloak SPI listener (phase 2,... @oblinder 2026-08-16
#752 Feat: AIAC OPA plugin integration + live enforcement (pha... @oblinder 2026-08-13
#750 chore(sparc-service): bump agent-lifecycle-toolkit to 0.11.0 @vz-ibm 2026-08-11
#749 build(deps): Bump github/codeql-action/upload-sarif from ... @app/dependabot 2026-08-11
#748 build(deps): Bump github/codeql-action/init from 4.37.4 t... @app/dependabot 2026-08-11
#747 build(deps): Bump rojopolis/spellcheck-github-actions fro... @app/dependabot 2026-08-11
#743 build(deps): Bump docker/login-action from 4.2.0 to 4.6.0 @app/dependabot 2026-08-11
#741 docs(sparc-service): document SPARC_LOG_REQUESTS and SPAR... @vz-ibm 2026-08-11
#739 fix(sparc-service): WatsonX reasoning-model support + Doc... @vz-ibm 2026-08-11
#723 feat: ✨ Session budget enforcement plugin @evaline-ju 2026-08-12

Open PRs (20)

Ready to Merge (1)

# Title Author Notes
#677 Feat: Add tls_bridge.upstream_insecure to skip ori... @aslom SECURITY, stale (31d)

Changes Requested (1)

# Title Author Days Notes
#760 Fix: Propagate every plugin header mutation in ext... @JoshSag 1 SECURITY

Needs Review (16)

# Title Author Days Notes
#774 build(deps): Bump github/codeql-action/init from 4... @app/dependabot 0
#773 build(deps): Bump github/codeql-action/upload-sari... @app/dependabot 0
#772 build(deps): Bump github/codeql-action/analyze fro... @app/dependabot 0
#771 build(deps): Bump github.com/maximhq/bifrost/core ... @app/dependabot 0 SECURITY
#770 build(deps): Bump golang.org/x/net from 0.57.0 to ... @app/dependabot 0
#769 build(deps): Bump langchain-core from 1.4.9 to 1.5.5 @app/dependabot 0
#768 build(deps): Bump github.com/envoyproxy/go-control... @app/dependabot 0
#767 build(deps): Bump langchain-openai from 1.3.5 to 1... @app/dependabot 0
... +8 more

Draft PRs (2)

  • #762 — Feat: Add the lineage demo — per-request lineage from the sidecar
  • #761 — Feat: Lineage telemetry plugin — two facts-only spans per exchange

CI Health

  • 19/30 (63%) passed
  • Failing: "Security Scans" — 3 failure(s)
  • Failing: "CI" — 2 failure(s)

New Issues (3)

# Title Created
#759 feature: token-budget human-in-the-loop approval when bud... 2026-08-14
#758 Add JTI-based revocation to token exchange cache 2026-08-14
#756 [dep-bump] Stale routine bump: github.com/rossoctl/contex... 2026-08-13

rossoctl

Merged PRs (6)

Top contributors: @app/dependabot (3), @esnible (2), @evaline-ju (1)

# Title Author Merged
#2386 build(deps): Bump astral-sh/setup-uv from 9.0.0 to 10.0.1... @app/dependabot 2026-08-18
#2383 feat: allow k8sResourceLimits/k8sResourceRequests overrid... @esnible 2026-08-17
#2372 build(deps): Bump the minor-and-patch group across 1 dire... @app/dependabot 2026-08-13
#2369 feat: Add PUT /{namespace}/{name}/identity-config endpoint @esnible 2026-08-13
#2366 fix: 🐛 Fix links @evaline-ju 2026-08-12
#2271 build(deps): Bump the major group across 1 directory with... @app/dependabot 2026-08-13

Open PRs (24)

Needs Review (19)

# Title Author Days Notes
#2388 🌱 Split agents.py router into modules under 1000 l... @esnible 0
#2385 build(deps): Bump hadolint/hadolint-action from 3.... @app/dependabot 2
#2384 build(deps): Bump the minor-and-patch group across... @app/dependabot 2
#2371 chore: Remove migrated github-pr-review skill @rubambiza 4
#2348 docs: Link health report (auto-updated) @clawgenti 12
#2336 chore(deps): Update mcp requirement from <2,>=1.0.... @app/dependabot 16 stale (16d)
#2335 fix(backend): fall back to legacy agent card endpoint @w3lld1 16 stale (16d)
#2327 docs: add SVG diagram style guide @Alan-Cha 18 stale (18d)
... +11 more

Draft PRs (5)

  • #2368 — fix: use Istio gateway for E2E tests instead of direct service port-forwards
  • #2207 — docs: Rosso vision brief + landing page (DRAFT, for review)
  • #2180 — Docs: local (Kind, gate-only) skill-attestation demo harness
  • #2176 — Docs: add docs-temp source and website sync trigger
  • #2084 — feat(openshell): switch to upstream in-process Kubernetes driver

CI Health

  • 19/30 (63%) passed
  • Failing: "Cleanup Stale HyperShift Clusters" — 1 failure(s)
  • Failing: "RC Release Validation" — 1 failure(s)

New Issues (15)

# Title Created
#2389 check-release-pins doesn't render subcharts — can't catch... 2026-08-17
#2387 Weekly Report 2026-08-17 2026-08-17
#2382 🐛 Broken link in rossoctl/ui-v2/AUTHENTICATION.md: ht... 2026-08-14
#2381 🐛 Broken link in rossoctl/ui-v2/AUTHENTICATION.md: ht... 2026-08-14
#2380 🐛 Broken link in PERSONAS_AND_ROLES.md: http://rossoc... 2026-08-14
#2379 🐛 Broken link in docs/users-guides/PERSONAS_AND_ROLES... 2026-08-14
#2378 🐛 Broken link in docs/users-guides/PERSONAS_AND_ROLES... 2026-08-14
#2377 🐛 Broken link in docs/README.md: https://github.com/r... 2026-08-14
#2376 🐛 Broken link in docs/gateway.md: https://github.com/... 2026-08-14
#2375 🐛 Broken link in docs/demos/demo-slack-research-agent... 2026-08-14
#2374 🐛 Broken link in CLAUDE-ORG.md: https://github.com/ro... 2026-08-14
#2373 🐛 Broken link in CLAUDE-ORG.md: http://rossoctl.io/ 2026-08-14
#2367 E2E tests bypass Istio gateway - should test production r... 2026-08-11
#2363 Audit non-default branches for reintroduced kagenti/ work... 2026-08-11
#2362 Istio ambient mode certificates expired without automatic... 2026-08-11

automation

Merged PRs (5)

Top contributors: @rubambiza (3), @clawgenti (2)

# Title Author Merged
#56 feat: Add standing-order breadcrumb to link-health fixer PRs @rubambiza 2026-08-17
#51 ci: Repoint reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#50 refactor: Decompose program-lib.sh into portable modules ... @rubambiza 2026-08-12
#48 docs: Link health report (auto-updated) @clawgenti 2026-08-11
#46 docs: Automation health dashboard (auto-updated) @clawgenti 2026-08-11

Open PRs (4)

Needs Review (3)

# Title Author Days Notes
#59 feat: Add weekly-report.sh scoped to core repos @rubambiza 0
#54 docs: Link health report (auto-updated) @clawgenti 5
#53 docs: Automation health dashboard (auto-updated) @clawgenti 6

Draft PRs (1)

  • #41 — Feat: Add a link back to the skill when opening a link issue (breadcrumb)

CI Health

  • 30/30 (100%) passed

New Issues (2)

# Title Created
#58 Add context-service to core-repos.txt 2026-08-17
#57 feat: Scope weekly report to core repos 2026-08-17

workload-harness

Merged PRs (5)

Top contributors: @vz-ibm (2), @clawgenti (1), @rubambiza (1), @yoavkatz (1)

# Title Author Merged
#61 docs: Fix broken internal link to #963 @clawgenti 2026-08-11
#60 ci: Migrate reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#54 feat(authbridge): add sparc plugin integration to the pip... @vz-ibm 2026-08-11
#53 fix(deploy-benchmark): add --subset flag for tau2 domain ... @vz-ibm 2026-08-11
#48 Refactor Keycloak direct-access-grants into shared helper... @yoavkatz 2026-08-12

Open PRs (1)

Needs Review (1)

# Title Author Days Notes
#64 feat(analyze): add --save-analysis flag to save co... @yoavkatz 4 SECURITY

CI Health

  • 14/30 (47%) passed
  • Failing: ".github/workflows/pr-verifier.yml" — 3 failure(s)
  • Failing: ".github/workflows/project.yml" — 2 failure(s)

New Issues (1)

# Title Created
#62 🐛 Broken link in exgentic_a2a_runner/README.md: https... 2026-08-12

agent-skills

Merged PRs (2)

Top contributors: @rubambiza (2)

# Title Author Merged
#31 ci: Migrate reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#30 chore: Rename marketplace to rossoctl-agent-skills @rubambiza 2026-08-11

Open PRs (1)

Needs Review (1)

# Title Author Days Notes
#32 feat: Add --repos flag to scope weekly report @rubambiza 0

CI Health

  • 22/30 (73%) passed
  • Failing: ".github/workflows/pr-verifier.yml" — 4 failure(s)
  • Failing: ".github/workflows/project.yml" — 2 failure(s)
  • Failing: ".github/workflows/self-assign.yml" — 2 failure(s)

operator

Merged PRs (2)

Top contributors: @cwiklik (1), @Alan-Cha (1)

# Title Author Merged
#506 Fix: stop rendering duplicate rossoctl-authbridge SCC (ro... @cwiklik 2026-08-11
#505 fix: clarify SPIRE warning message to avoid confusion @Alan-Cha 2026-08-11

Open PRs (5)

Ready to Merge (1)

# Title Author Notes
#490 Fix: regenerate token-broker go.sum for renamed co... @Ibrahim2595 SECURITY, stale (28d)

Needs Review (3)

# Title Author Days Notes
#509 build(deps): bump the minor-and-patch group across... @app/dependabot 0 SECURITY
#503 build(deps): bump the minor-and-patch group across... @app/dependabot 14
#495 build(deps): bump the major group across 1 directo... @app/dependabot 21 stale (21d)

Draft PRs (1)

  • #478 — feat(operator): fetch JWT-SVID via go-spiffe SDK, remove spiffe-helper sidecar

CI Health

  • 30/30 (100%) passed

New Issues (2)

# Title Created
#508 release.yml doesn't pin injected AuthBridge images (they ... 2026-08-17
#507 [dep-bump] Stale routine bump: major group in operator 2026-08-13

examples

Merged PRs (1)

Top contributors: @evaline-ju (1)

# Title Author Merged
#789 🐛 Update link @evaline-ju 2026-08-11

Open PRs (36)

Needs Review (36)

# Title Author Days Notes
#804 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#803 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#802 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#801 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#800 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#799 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#798 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#797 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
... +28 more

CI Health

  • 22/30 (73%) passed
  • Failing: "Build-Publish" — 1 failure(s)

New Issues (1)

# Title Created
#788 [dep-bump] Stale routine bump: Update a2a-sdk[http-server... 2026-08-11

.github

Open PRs (1)

Ready to Merge (1)

# Title Author Notes
#116 Update Platform Tools title and description @Ronen-Levy

CI Health

  • 22/30 (73%) passed

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions