Snapshot: 2026-05-11 03:59 UTC. Scope: fro-bot/{agent, .github, systematic, fro-bot.github.io} (tokentoilet archived).
Summary metrics
| Metric |
Count |
Δ vs. 2026-05-10 |
| New issues (<24h) |
1 |
0 |
| Open PRs |
8 |
0 |
| Aging PRs (>7d, ≤14d) |
0 |
−1 |
| Stale PRs (>14d) |
1 |
+1 |
| Stale issues (>30d) |
2 |
0 |
| Failing default-branch checks |
0 |
0 |
| Dependabot alerts (open) |
5 (all agent) |
0 |
| Code-scanning alerts (open, high) |
2 (agent) + 1 (.github) |
0 |
Unassigned bugs (label:bug) |
0 |
0 |
Critical items
No failing default-branch CI runs (last 24h agent/main and .github/main workflows green or skipped). No broken release pipelines.
Aging PRs
The seven open PRs in fro-bot/agent are all Renovate/automerge-tagged or recently opened (#605 wiki update opened yesterday, #602 from @marcusrbrown opened 2d). None has crossed the 7d aging line — they're cycling normally.
Stale issues
The 42 daily [YYYY-MM-DD] Fro Bot operational log / Daily Org Oversight Report / Daily Autohealing Report issues in fro-bot/.github are inside their automation lifecycle and excluded from the stale count.
Unassigned bugs / high-signal issues
label:bug + no:assignee across the org: 0. Nothing to triage.
Repo hotspots
| Rank |
Repo |
Open PRs |
Stale items |
Notes |
| 1 |
fro-bot/agent |
7 |
0 |
All Renovate or recently opened. Backlog moves but the fast-uri/fast-xml-builder security chain hasn't been resolved in 2 cycles. |
| 2 |
fro-bot/systematic |
1 |
1 |
Same two items as yesterday, both now older. Dormancy is hardening. |
| 3 |
fro-bot/fro-bot.github.io |
0 |
1 |
Single stale issue; placeholder repo. |
Recommended actions
Snapshot: 2026-05-11 03:59 UTC. Scope:
fro-bot/{agent, .github, systematic, fro-bot.github.io}(tokentoilet archived).Summary metrics
agent)agent) + 1 (.github)label:bug)Critical items
fast-urihost confusion (Dependabot #71)fast-uripin directly; Renovate hasn't surfaced it on its own.fast-uripath traversal (Dependabot #70)fast-xml-builderattribute-quote bypass (Dependabot #69)bun pm ls; pin if no upstream patch lands.fast-xml-buildercomment-regex bypass (Dependabot #68)ip-addressXSS in Address6 HTML methods (Dependabot #67)ip-address. No consumer renders Address6 HTML, so risk is latent but the alert remains.BranchProtectionID,VulnerabilitiesIDmainprotection throughcommon-settings.yaml; the Vulnerabilities finding clears once the Dependabot block above lands.BranchProtectionIDNo failing default-branch CI runs (last 24h
agent/mainand.github/mainworkflows green orskipped). No broken release pipelines.Aging PRs
The seven open PRs in
fro-bot/agentare all Renovate/automerge-tagged or recently opened (#605 wiki update opened yesterday, #602 from @marcusrbrown opened 2d). None has crossed the 7d aging line — they're cycling normally.Stale issues
gh-pages(static docs). No buildable code surface for CodeQL. Close as wontfix or scope down to Scorecard-only.The 42 daily
[YYYY-MM-DD] Fro Bot operational log/Daily Org Oversight Report/Daily Autohealing Reportissues infro-bot/.githubare inside their automation lifecycle and excluded from the stale count.Unassigned bugs / high-signal issues
label:bug+no:assigneeacross the org: 0. Nothing to triage.Repo hotspots
fast-uri/fast-xml-buildersecurity chain hasn't been resolved in 2 cycles.Recommended actions
fast-uri/fast-xml-builder/ip-addressDependabot block onfro-bot/agent— these are entering their second day open. Manual transitive pin if Renovate doesn't surface them this cycle.mainbranch protection onfro-bot/agentandfro-bot/.githubviacommon-settings.yamlto clear the ScorecardBranchProtectionIDhighs.fro-bot/systematic#2(Renovate config) — now officially stale at 15d.fro-bot/systematic#1andfro-bot/fro-bot.github.io#1(CodeQL on non-buildable repos).