Snapshot: 2026-05-13 03:52 UTC. Scope: fro-bot/{agent, .github, systematic, fro-bot.github.io} (tokentoilet archived).
Summary metrics
| Metric |
Count |
Δ vs. 2026-05-12 |
| New issues (<24h, ex-automation) |
0 |
0 |
| Open PRs |
7 |
−2 |
| Aging PRs (>7d, ≤14d) |
0 |
0 |
| Stale PRs (>14d) |
1 |
0 |
| Stale issues (>30d) |
2 |
0 |
| Failing default-branch checks |
0 |
0 |
| Dependabot alerts (open) |
5 (all agent) |
0 |
| Code-scanning alerts (open, high) |
2 (agent) + 1 (.github) |
0 |
Unassigned bugs (label:bug) |
0 |
0 |
Shipped since yesterday: agent cut v0.43.0 (release PR #606 merged, plus #602 oMo opt-in and #611 streamed-activity tracking). New action-version bump now in flight in fro-bot/.github (PR #3282).
Critical items
No failing default-branch CI runs. No broken release pipelines — agent v0.43.0 cut cleanly.
Aging PRs
All fro-bot/agent PRs and the new .github#3282 action-version bump were updated today.
Stale issues
43 daily operational-log / autohealing / oversight issues in fro-bot/.github are inside their automation lifecycle and excluded.
Unassigned bugs / high-signal issues
label:bug + no:assignee org-wide: 0. Nothing to triage.
Repo hotspots
| Rank |
Repo |
Open PRs |
Stale items |
Notes |
| 1 |
fro-bot/agent |
5 |
0 |
v0.43.0 released yesterday; queue cleared three PRs. The Dependabot security block is still untouched after the release window. |
| 2 |
fro-bot/systematic |
1 |
1 |
Same two parked items, both aging. |
| 3 |
fro-bot/.github / fro-bot/fro-bot.github.io |
1 / 0 |
0 / 1 |
.github now has the agent v0.43.0 action bump; fro-bot.github.io carries one stale issue. |
Recommended actions
Snapshot: 2026-05-13 03:52 UTC. Scope:
fro-bot/{agent, .github, systematic, fro-bot.github.io}(tokentoilet archived).Summary metrics
agent)agent) + 1 (.github)label:bug)Shipped since yesterday:
agentcut v0.43.0 (release PR #606 merged, plus #602 oMo opt-in and #611 streamed-activity tracking). New action-version bump now in flight infro-bot/.github(PR #3282).Critical items
fast-urihost confusion (Dependabot #71)pnpm-workspace.overridesPR.fast-uripath traversal (Dependabot #70)fast-xml-builderattribute-quote bypass (Dependabot #69)fast-xml-buildercomment-regex bypass (Dependabot #68)ip-addressXSS in Address6 HTML methods (Dependabot #67)ip-address. Latent risk (no Address6 HTML rendering in tree).BranchProtectionID,VulnerabilitiesIDmainprotection viacommon-settings.yaml;VulnerabilitiesIDclears with the Dependabot block.BranchProtectionIDNo failing default-branch CI runs. No broken release pipelines —
agentv0.43.0 cut cleanly.Aging PRs
All
fro-bot/agentPRs and the new.github#3282action-version bump were updated today.Stale issues
gh-pages(static docs); no buildable surface for CodeQL. Close as wontfix or rescope to Scorecard-only.43 daily operational-log / autohealing / oversight issues in
fro-bot/.githubare inside their automation lifecycle and excluded.Unassigned bugs / high-signal issues
label:bug+no:assigneeorg-wide: 0. Nothing to triage.Repo hotspots
.githubnow has the agent v0.43.0 action bump;fro-bot.github.iocarries one stale issue.Recommended actions
pnpm-workspace.overridesPR onfro-bot/agentforfast-uri,fast-xml-builder, andip-address. v0.43.0 went out without addressing the security block — Renovate has had four cycles to surface it. Stop waiting on Renovate.mainbranch protection onfro-bot/agentandfro-bot/.githubviacommon-settings.yamlto clear the ScorecardBranchProtectionIDhighs.