Snapshot: 2026-05-14 03:52 UTC. Scope: fro-bot/{agent, .github, systematic, fro-bot.github.io} (tokentoilet archived).
Summary metrics
| Metric |
Count |
Δ vs. 2026-05-13 |
| New issues (<24h, ex-automation) |
0 |
0 |
| Open PRs |
6 |
−1 |
| Aging PRs (>7d, ≤14d) |
0 |
0 |
| Stale PRs (>14d) |
1 |
0 |
| Stale issues (>30d) |
2 |
0 |
| Failing default-branch checks |
0 |
0 |
| Dependabot alerts (open) |
5 (all agent) |
0 |
| Code-scanning alerts (open, high) |
2 (agent) + 1 (.github) |
0 |
Unassigned bugs (label:bug) |
0 |
0 |
fro-bot/agent/main had a fresh push 3 min before snapshot — CI, CodeQL, Scorecard, and Update Repo Settings all green. PR #599 (eslint v10.3.0) merged since yesterday.
Critical items
No failing default-branch CI. No broken release pipelines.
Aging PRs
All other open PRs were updated today.
Stale issues
44 daily automation-lifecycle issues in fro-bot/.github excluded.
Unassigned bugs / high-signal issues
label:bug + no:assignee org-wide: 0.
Repo hotspots
Recommended actions
The pattern across these reports is clear: the org's automation is healthy, but the manual decisions queued by past reports keep being deferred. Five days of recommending the same security fix is the report consuming its own tail. Marcus — these are blocking on a human decision, not on more data.
Snapshot: 2026-05-14 03:52 UTC. Scope:
fro-bot/{agent, .github, systematic, fro-bot.github.io}(tokentoilet archived).Summary metrics
agent)agent) + 1 (.github)label:bug)fro-bot/agent/mainhad a fresh push 3 min before snapshot — CI, CodeQL, Scorecard, and Update Repo Settings all green. PR #599 (eslint v10.3.0) merged since yesterday.Critical items
fast-urihost confusion (Dependabot #71)pnpm-workspace.overridesPR has now been repeated for three reports without movement.fast-uripath traversal (Dependabot #70)fast-xml-builderattribute-quote bypass (Dependabot #69)fast-xml-buildercomment-regex bypass (Dependabot #68)ip-addressXSS in Address6 HTML methods (Dependabot #67)ip-address. Latent risk only.BranchProtectionID,VulnerabilitiesIDmainprotection viacommon-settings.yaml;VulnerabilitiesIDclears with the Dependabot block.BranchProtectionIDNo failing default-branch CI. No broken release pipelines.
Aging PRs
All other open PRs were updated today.
Stale issues
gh-pages(static docs); no buildable surface for CodeQL. Close as wontfix or rescope to Scorecard-only.44 daily automation-lifecycle issues in
fro-bot/.githubexcluded.Unassigned bugs / high-signal issues
label:bug+no:assigneeorg-wide: 0.Repo hotspots
Recommended actions
pnpm-workspace.overridesPR onfro-bot/agentforfast-uri,fast-xml-builder, andip-address. Five cycles in, no movement. The "wait for Renovate" strategy has failed.mainbranch protection onfro-bot/agentandfro-bot/.githubviacommon-settings.yaml.The pattern across these reports is clear: the org's automation is healthy, but the manual decisions queued by past reports keep being deferred. Five days of recommending the same security fix is the report consuming its own tail. Marcus — these are blocking on a human decision, not on more data.