You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Quiet day on the new-issue front (only 4 created, all bot housekeeping), but the backlog from yesterday's audit is entirely untouched. All 4 privacy-gate issues and all 9 reconciler issues remain OPEN with no assignees. The org is accumulating triaged-but-unactioned work faster than it's discharging it.
Summary metrics
Metric
Count
Δ vs yesterday
Repositories scanned
5 (tokentoilet archived)
—
New issues (last 24h, org-wide)
4 (2 op logs, 1 autohealing, 1 oversight — all bot-generated)
All other 8 PRs updated within the last 24h. New on .github: #3354 (actions/stale v10.3.0 bump) and #3357 (Node.js v24.16.0). Note: the actions/stale PR confirms a stale-bot is already deployed somewhere — worth checking why the 47-issue op-log queue isn't being closed by it.
Op-log entropy: 24 op-log/autohealing issues >14d (+2 since yesterday). If actions/stale is already wired into a workflow (per #3354), then either its config doesn't match op-log titles or its days-before-stale is set too high. Worth a 5-minute config audit.
Unassigned bugs or high-signal issues
No bug-labeled issues open org-wide. The 14 untriaged P0/P1 issues from yesterday's audit are the high-signal items but remain unlabeled:
Carryover ×2: Assign owners to the privacy-gate cluster (#3326–#3328, #3345). Start with #3328.
Carryover ×2: Assign owner to the 9-issue reconciler cluster — one hardening pass.
Carryover ×2: Patch the social-broadcast TOCTOU (#3325).
New: Audit the actions/stale workflow config in fro-bot/.github. The bump PR #3354 proves it's already wired in — figure out why 24 op-log issues past 14d aren't being closed by it. Saves implementing what already exists.
Carryover ×5: Decide fro-bot/agent → Auto Release (delete or fix). 61 days red. The repetition is the diagnosis.
Scope: all repositories in the
fro-botGitHub organization. Data pulled viaghat run start. Links only; no content duplication.Previous report: #3352.
Quiet day on the new-issue front (only 4 created, all bot housekeeping), but the backlog from yesterday's audit is entirely untouched. All 4 privacy-gate issues and all 9 reconciler issues remain
OPENwith no assignees. The org is accumulating triaged-but-unactioned work faster than it's discharging it.Summary metrics
tokentoiletarchived).github)agent→Auto Release, ~61d red).github=3,agent=6)Critical items
fro-bot/.githubfro-bot/.githubfro-bot/.githubfro-bot/agentAuto Releasefailing onmainsince 2026-03-22 (~61d red). Fifth report.fro-bot/agentVulnerabilities(#13),SAST,Fuzzing,CII-Best-Practices,Code-Review,Branch-Protectionfro-bot/.githubBranch-Protection,CII-Best-Practices,FuzzingNo new Dependabot alerts. No broken release pipelines blocking shipping.
Aging PRs (>7d no activity)
fro-bot/systematicAll other 8 PRs updated within the last 24h. New on
.github: #3354 (actions/stalev10.3.0 bump) and #3357 (Node.js v24.16.0). Note: theactions/stalePR confirms a stale-bot is already deployed somewhere — worth checking why the 47-issue op-log queue isn't being closed by it.Stale issues (>30d no activity)
fro-bot/systematicfro-bot/fro-bot.github.ioOp-log entropy: 24 op-log/autohealing issues >14d (+2 since yesterday). If
actions/staleis already wired into a workflow (per #3354), then either its config doesn't match op-log titles or itsdays-before-staleis set too high. Worth a 5-minute config audit.Unassigned bugs or high-signal issues
No
bug-labeled issues open org-wide. The 14 untriaged P0/P1 issues from yesterday's audit are the high-signal items but remain unlabeled:Carryover (×4): apply
bug/securitylabels to these so they surface in standard triage queries.Repo hotspots
fro-bot/.github— 75 open issues (47 op logs + ~14 substantive carryover + 4 autohealing + 3 oversight + survey/dashboard residue), 3 open PRs. Substantive backlog static, noise queue growing.fro-bot/agent— 5 open PRs (all Renovate), 2 open issues. Healthy Renovate churn;Auto Releasestill the lone red mark.fro-bot/systematic— Sixth report flagging the same stalest PR (fix: add @fro-bot as a collaborator to prevent it from being "removed" #2, 26d) and stalest issue (feat: set default settings #1, 74d). Treat the repeated mention as proof of orphaning.Recommended actions (checklist)
actions/staleworkflow config infro-bot/.github. The bump PR #3354 proves it's already wired in — figure out why 24 op-log issues past 14d aren't being closed by it. Saves implementing what already exists.fro-bot/agent→Auto Release(delete or fix). 61 days red. The repetition is the diagnosis.fro-bot/systematic#2(26d cold).fro-bot/systematic#1andfro-bot/fro-bot.github.io#1(CodeQL, 74d cold).agent's #13 Vulnerabilities.bug/securitylabels to the 14 untriaged audit issues.Run Summary
gh issue list,gh pr list,gh api actions/workflows,gh api code-scanning/alerts,gh api dependabot/alerts