Snapshot: 2026-05-12 03:42 UTC. Scope: fro-bot/{agent, .github, systematic, fro-bot.github.io} (tokentoilet archived).
Summary metrics
| Metric |
Count |
Δ vs. 2026-05-11 |
| New issues (<24h) |
3 (all daily-automation logs) |
+2 |
| Open PRs |
9 |
+1 |
| Aging PRs (>7d, ≤14d) |
0 |
0 |
| Stale PRs (>14d) |
1 |
0 |
| Stale issues (>30d) |
2 |
0 |
| Failing default-branch checks |
0 |
0 |
| Dependabot alerts (open) |
5 (all agent) |
0 |
| Code-scanning alerts (open, high) |
2 (agent) + 1 (.github) |
0 |
Unassigned bugs (label:bug) |
0 |
0 |
Critical items
No failing default-branch CI runs. No broken release pipelines — agent's pending release v0.42.10 (fro-bot/agent#606) is open and queued.
Aging PRs
All seven fro-bot/agent PRs are within 4 days. fro-bot/agent#602 (feat: disable oMo by default) is 3 days old but was updated 8h ago — moving, not aging.
Stale issues
42 daily operational-log / autohealing / oversight issues in fro-bot/.github are inside their automation lifecycle and excluded from the stale count.
Unassigned bugs / high-signal issues
label:bug + no:assignee org-wide: 0. Nothing to triage.
Repo hotspots
| Rank |
Repo |
Open PRs |
Stale items |
Notes |
| 1 |
fro-bot/agent |
8 |
0 |
Renovate queue active (#607–#610 opened yesterday). Security block still squatting on fast-uri / fast-xml-builder / ip-address for the third cycle. |
| 2 |
fro-bot/systematic |
1 |
1 |
Same two items. Both aging. |
| 3 |
fro-bot/fro-bot.github.io |
0 |
1 |
Single stale issue; placeholder repo. |
Recommended actions
Snapshot: 2026-05-12 03:42 UTC. Scope:
fro-bot/{agent, .github, systematic, fro-bot.github.io}(tokentoilet archived).Summary metrics
agent)agent) + 1 (.github)label:bug)Critical items
fast-urihost confusion (Dependabot #71)pnpm-workspace.overridesor open a manual PR.fast-uripath traversal (Dependabot #70)fast-xml-builderattribute-quote bypass (Dependabot #69)fast-xml-buildercomment-regex bypass (Dependabot #68)ip-addressXSS in Address6 HTML methods (Dependabot #67)ip-address; latent risk only (no Address6 HTML rendering in tree).BranchProtectionID,VulnerabilitiesIDmainprotection throughcommon-settings.yaml;VulnerabilitiesIDclears with the Dependabot block.BranchProtectionIDNo failing default-branch CI runs. No broken release pipelines —
agent's pending release v0.42.10 (fro-bot/agent#606) is open and queued.Aging PRs
All seven
fro-bot/agentPRs are within 4 days. fro-bot/agent#602 (feat: disable oMo by default) is 3 days old but was updated 8h ago — moving, not aging.Stale issues
gh-pages(static docs); no buildable surface for CodeQL. Close as wontfix or rescope to Scorecard-only.42 daily operational-log / autohealing / oversight issues in
fro-bot/.githubare inside their automation lifecycle and excluded from the stale count.Unassigned bugs / high-signal issues
label:bug+no:assigneeorg-wide: 0. Nothing to triage.Repo hotspots
fast-uri/fast-xml-builder/ip-addressfor the third cycle.Recommended actions
fast-uri/fast-xml-builder/ip-addressDependabot block onfro-bot/agent— Day 3 unresolved. Addpnpm-workspace.overridesentries for the transitive packages. Renovate has had three cycles to surface these and hasn't.mainbranch protection onfro-bot/agentandfro-bot/.githubviacommon-settings.yamlto clear the ScorecardBranchProtectionIDhighs.fro-bot/systematic#2(Renovate config) — 16d stale, second cycle past threshold.fro-bot/systematic#1andfro-bot/fro-bot.github.io#1(CodeQL on non-buildable repos).