Skip to content

Weekly Report 2026-08-18 #2390

Description

@clawgenti

Org Weekly Report: 2026-08-11 -- 2026-08-18

Generated for rossoctl by the github-weekly-report skill.

Org-Wide Summary

Repo Merged PRs Open PRs Open Issues New Issues CI Pass Rate Status
cortex 11 20 33 3 19/30 (63%) active
rossoctl 6 24 191 15 19/30 (63%) active
automation 5 4 6 2 30/30 (100%) active
workload-harness 5 1 11 1 14/30 (47%) active
agent-skills 2 1 1 0 22/30 (73%) active
operator 2 5 16 2 30/30 (100%) active
examples 1 36 14 1 22/30 (73%) active
.github 0 1 3 0 22/30 (73%) quiet
TOTAL 32 92 275 24

Cross-Repo Highlights

Multi-repo contributors

  • @rubambiza was the busiest cross-repo contributor, merging into agent-skills, automation, and workload-harness (6 PRs) — largely the org migration work: repointing reusable-workflow refs to rossoctl/.github (automation#51, workload-harness#60, agent-skills#31), decomposing program-lib.sh into portable modules (automation#50), and the link-health fixer breadcrumb (automation#56).
  • @vz-ibm drove cortex and workload-harness (5 PRs) on the SPARC service: WatsonX reasoning-model support (cortex#739), request-logging docs (cortex#741), and the authbridge SPARC plugin integration in the harness (workload-harness#54).
  • @evaline-ju touched cortex, examples, and rossoctl (3 PRs), including the session budget-enforcement plugin (cortex#723) and link fixes.
  • @esnible was the dominant contributor in rossoctl — the busiest repo by issue volume — landing the identity-config endpoint (feat: Add PUT /{namespace}/{name}/identity-config endpoint #2369) and k8s resource-limit overrides (feat: allow k8sResourceLimits/k8sResourceRequests overrides for agents and tools #2383), plus a cortex plugin-catalog doc.

Org-wide CI

  • Aggregate pass rate is 178/240 (74%). automation and operator are the clean repos at 100%.
  • workload-harness drags the average down at 47% — the failing workflows are pr-verifier.yml (3 failures) and project.yml (2). cortex and rossoctl both sit at 63%, with cortex's "Security Scans" (3) and "CI" (2) the main culprits.

Security concerns (open PRs flagged SECURITY, unreviewed >7 days)

Dependabot accumulation

  • 64 open dependabot PRs across the org — well past the batching threshold. Breakdown: examples 36, cortex 16, rossoctl 9, operator 3. The examples backlog alone is the single largest review liability this week.

Shared themes

  • Org rename tail — reusable-workflow repointing and program-lib modularization landed across three repos.
  • AIAC / SPARC buildout — event broker + OPA enforcement (cortex#752/Feat/terraform validation checks #754), plus harness integration, is the dominant feature thread.
  • Link-health automation — clawgenti-authored broken-link fixes and reports recur across rossoctl, automation, and workload-harness.

Active Epics

Epic Lead Key Result (inferred) This Week
rossoctl/rossoctl#2244 Cortex Phase 1 @esnible Ship Cortex data-plane phase 1 1 sub-issue closed (#684), 4 open
rossoctl/rossoctl#2277 AIAC MVP @omerboehm Agent-Identity-and-Access-Control MVP 1 sub-issue closed, 2 open
rossoctl/rossoctl#1461 User access to Kagenti Sandbox with OpenShell @aslom Multi-tenant sandbox access via OpenShell 15 open
rossoctl/rossoctl#1817 Sandbox CRD extensions for agent state & session mgmt @cwiklik Stateful agent infra (CRD extensions) 8 open
rossoctl/rossoctl#1469 Rossoctl Documentation and Usability Improvements @esnible Docs + usability polish 6 open
rossoctl/rossoctl#1460 Authorization and Identity for Event-Driven Agent @aslom Authz/identity for event-driven agents 8 open
rossoctl/rossoctl#2254 Automated cross-version benchmarking for regression @webchang Cross-version regression benchmarking 10 open
rossoctl/rossoctl#2074 Skill-bound agent identity — deny tool access on scope unassigned Deny tool access outside granted scope 6 open
rossoctl/rossoctl#2087 AIAC Quality Framework — Guardrails, Testing @omerboehm AIAC guardrails + testing framework 4 open
rossoctl/rossoctl#1302 Runtime-Attested Agent Card @webchang Runtime attestation for agent cards 6 open

Action Items

# Action Repo Owner Priority
1 Merge APPROVED security fix #490 (go.sum regen), open+approved 28 days operator @Ibrahim2595 P0
2 Merge or re-triage APPROVED security PR #677 (tls_bridge upstream_insecure), open 31 days cortex @aslom P0
3 Investigate workload-harness CI at 47% — pr-verifier.yml (3 fails) and project.yml (2 fails) workload-harness @vz-ibm P0
4 Review 21–31 day security dep bumps #704, #2224, #2235–2240 cortex, rossoctl @esnible P1
5 Fix cortex CI — "Security Scans" (3) and "CI" (2) failures at 63% pass rate cortex @oblinder P1
6 Batch-review the 36 open dependabot PRs (many SECURITY-flagged, 17–31 days) examples @evaline-ju P2
7 Batch-review the 16 open dependabot PRs cortex @vz-ibm P2
8 Batch-review the 9 open dependabot PRs rossoctl @esnible P2
9 Triage 24 broken-link issues opened this week (#2373#2382, workload-harness#62) rossoctl @clawgenti P3
10 Resolve stale non-dependabot PRs >16 days: #2335, #2327 rossoctl @w3lld1, @Alan-Cha P3

cortex

Merged PRs (11)

Top contributors: @app/dependabot (4), @vz-ibm (3), @oblinder (2), @esnible (1), @evaline-ju (1)

# Title Author Merged
#757 Docs: Add plugin catalog @esnible 2026-08-14
#754 Feat: AIAC Event Broker + Keycloak SPI listener (phase 2,... @oblinder 2026-08-16
#752 Feat: AIAC OPA plugin integration + live enforcement (pha... @oblinder 2026-08-13
#750 chore(sparc-service): bump agent-lifecycle-toolkit to 0.11.0 @vz-ibm 2026-08-11
#749 build(deps): Bump github/codeql-action/upload-sarif from ... @app/dependabot 2026-08-11
#748 build(deps): Bump github/codeql-action/init from 4.37.4 t... @app/dependabot 2026-08-11
#747 build(deps): Bump rojopolis/spellcheck-github-actions fro... @app/dependabot 2026-08-11
#743 build(deps): Bump docker/login-action from 4.2.0 to 4.6.0 @app/dependabot 2026-08-11
#741 docs(sparc-service): document SPARC_LOG_REQUESTS and SPAR... @vz-ibm 2026-08-11
#739 fix(sparc-service): WatsonX reasoning-model support + Doc... @vz-ibm 2026-08-11
#723 feat: ✨ Session budget enforcement plugin @evaline-ju 2026-08-12

Open PRs (20)

Ready to Merge (1)

# Title Author Notes
#677 Feat: Add tls_bridge.upstream_insecure to skip ori... @aslom SECURITY, stale (31d)

Changes Requested (1)

# Title Author Days Notes
#760 Fix: Propagate every plugin header mutation in ext... @JoshSag 1 SECURITY

Needs Review (16)

# Title Author Days Notes
#774 build(deps): Bump github/codeql-action/init from 4... @app/dependabot 0
#773 build(deps): Bump github/codeql-action/upload-sari... @app/dependabot 0
#772 build(deps): Bump github/codeql-action/analyze fro... @app/dependabot 0
#771 build(deps): Bump github.com/maximhq/bifrost/core ... @app/dependabot 0 SECURITY
#770 build(deps): Bump golang.org/x/net from 0.57.0 to ... @app/dependabot 0
#769 build(deps): Bump langchain-core from 1.4.9 to 1.5.5 @app/dependabot 0
#768 build(deps): Bump github.com/envoyproxy/go-control... @app/dependabot 0
#767 build(deps): Bump langchain-openai from 1.3.5 to 1... @app/dependabot 0
... +8 more

Draft PRs (2)

  • #762 — Feat: Add the lineage demo — per-request lineage from the sidecar
  • #761 — Feat: Lineage telemetry plugin — two facts-only spans per exchange

CI Health

  • 19/30 (63%) passed
  • Failing: "Security Scans" — 3 failure(s)
  • Failing: "CI" — 2 failure(s)

New Issues (3)

# Title Created
#759 feature: token-budget human-in-the-loop approval when bud... 2026-08-14
#758 Add JTI-based revocation to token exchange cache 2026-08-14
#756 [dep-bump] Stale routine bump: github.com/rossoctl/contex... 2026-08-13

rossoctl

Merged PRs (6)

Top contributors: @app/dependabot (3), @esnible (2), @evaline-ju (1)

# Title Author Merged
#2386 build(deps): Bump astral-sh/setup-uv from 9.0.0 to 10.0.1... @app/dependabot 2026-08-18
#2383 feat: allow k8sResourceLimits/k8sResourceRequests overrid... @esnible 2026-08-17
#2372 build(deps): Bump the minor-and-patch group across 1 dire... @app/dependabot 2026-08-13
#2369 feat: Add PUT /{namespace}/{name}/identity-config endpoint @esnible 2026-08-13
#2366 fix: 🐛 Fix links @evaline-ju 2026-08-12
#2271 build(deps): Bump the major group across 1 directory with... @app/dependabot 2026-08-13

Open PRs (24)

Needs Review (19)

# Title Author Days Notes
#2388 🌱 Split agents.py router into modules under 1000 l... @esnible 0
#2385 build(deps): Bump hadolint/hadolint-action from 3.... @app/dependabot 2
#2384 build(deps): Bump the minor-and-patch group across... @app/dependabot 2
#2371 chore: Remove migrated github-pr-review skill @rubambiza 4
#2348 docs: Link health report (auto-updated) @clawgenti 12
#2336 chore(deps): Update mcp requirement from <2,>=1.0.... @app/dependabot 16 stale (16d)
#2335 fix(backend): fall back to legacy agent card endpoint @w3lld1 16 stale (16d)
#2327 docs: add SVG diagram style guide @Alan-Cha 18 stale (18d)
... +11 more

Draft PRs (5)

  • #2368 — fix: use Istio gateway for E2E tests instead of direct service port-forwards
  • #2207 — docs: Rosso vision brief + landing page (DRAFT, for review)
  • #2180 — Docs: local (Kind, gate-only) skill-attestation demo harness
  • #2176 — Docs: add docs-temp source and website sync trigger
  • #2084 — feat(openshell): switch to upstream in-process Kubernetes driver

CI Health

  • 19/30 (63%) passed
  • Failing: "Cleanup Stale HyperShift Clusters" — 1 failure(s)
  • Failing: "RC Release Validation" — 1 failure(s)

New Issues (15)

# Title Created
#2389 check-release-pins doesn't render subcharts — can't catch... 2026-08-17
#2387 Weekly Report 2026-08-17 2026-08-17
#2382 🐛 Broken link in rossoctl/ui-v2/AUTHENTICATION.md: ht... 2026-08-14
#2381 🐛 Broken link in rossoctl/ui-v2/AUTHENTICATION.md: ht... 2026-08-14
#2380 🐛 Broken link in PERSONAS_AND_ROLES.md: http://rossoc... 2026-08-14
#2379 🐛 Broken link in docs/users-guides/PERSONAS_AND_ROLES... 2026-08-14
#2378 🐛 Broken link in docs/users-guides/PERSONAS_AND_ROLES... 2026-08-14
#2377 🐛 Broken link in docs/README.md: https://github.com/r... 2026-08-14
#2376 🐛 Broken link in docs/gateway.md: https://github.com/... 2026-08-14
#2375 🐛 Broken link in docs/demos/demo-slack-research-agent... 2026-08-14
#2374 🐛 Broken link in CLAUDE-ORG.md: https://github.com/ro... 2026-08-14
#2373 🐛 Broken link in CLAUDE-ORG.md: http://rossoctl.io/ 2026-08-14
#2367 E2E tests bypass Istio gateway - should test production r... 2026-08-11
#2363 Audit non-default branches for reintroduced kagenti/ work... 2026-08-11
#2362 Istio ambient mode certificates expired without automatic... 2026-08-11

automation

Merged PRs (5)

Top contributors: @rubambiza (3), @clawgenti (2)

# Title Author Merged
#56 feat: Add standing-order breadcrumb to link-health fixer PRs @rubambiza 2026-08-17
#51 ci: Repoint reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#50 refactor: Decompose program-lib.sh into portable modules ... @rubambiza 2026-08-12
#48 docs: Link health report (auto-updated) @clawgenti 2026-08-11
#46 docs: Automation health dashboard (auto-updated) @clawgenti 2026-08-11

Open PRs (4)

Needs Review (3)

# Title Author Days Notes
#59 feat: Add weekly-report.sh scoped to core repos @rubambiza 0
#54 docs: Link health report (auto-updated) @clawgenti 5
#53 docs: Automation health dashboard (auto-updated) @clawgenti 6

Draft PRs (1)

  • #41 — Feat: Add a link back to the skill when opening a link issue (breadcrumb)

CI Health

  • 30/30 (100%) passed

New Issues (2)

# Title Created
#58 Add context-service to core-repos.txt 2026-08-17
#57 feat: Scope weekly report to core repos 2026-08-17

workload-harness

Merged PRs (5)

Top contributors: @vz-ibm (2), @clawgenti (1), @rubambiza (1), @yoavkatz (1)

# Title Author Merged
#61 docs: Fix broken internal link to #963 @clawgenti 2026-08-11
#60 ci: Migrate reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#54 feat(authbridge): add sparc plugin integration to the pip... @vz-ibm 2026-08-11
#53 fix(deploy-benchmark): add --subset flag for tau2 domain ... @vz-ibm 2026-08-11
#48 Refactor Keycloak direct-access-grants into shared helper... @yoavkatz 2026-08-12

Open PRs (1)

Needs Review (1)

# Title Author Days Notes
#64 feat(analyze): add --save-analysis flag to save co... @yoavkatz 4 SECURITY

CI Health

  • 14/30 (47%) passed
  • Failing: ".github/workflows/pr-verifier.yml" — 3 failure(s)
  • Failing: ".github/workflows/project.yml" — 2 failure(s)

New Issues (1)

# Title Created
#62 🐛 Broken link in exgentic_a2a_runner/README.md: https... 2026-08-12

agent-skills

Merged PRs (2)

Top contributors: @rubambiza (2)

# Title Author Merged
#31 ci: Migrate reusable-workflow refs to rossoctl/.github @rubambiza 2026-08-11
#30 chore: Rename marketplace to rossoctl-agent-skills @rubambiza 2026-08-11

Open PRs (1)

Needs Review (1)

# Title Author Days Notes
#32 feat: Add --repos flag to scope weekly report @rubambiza 0

CI Health

  • 22/30 (73%) passed
  • Failing: ".github/workflows/pr-verifier.yml" — 4 failure(s)
  • Failing: ".github/workflows/project.yml" — 2 failure(s)
  • Failing: ".github/workflows/self-assign.yml" — 2 failure(s)

operator

Merged PRs (2)

Top contributors: @cwiklik (1), @Alan-Cha (1)

# Title Author Merged
#506 Fix: stop rendering duplicate rossoctl-authbridge SCC (ro... @cwiklik 2026-08-11
#505 fix: clarify SPIRE warning message to avoid confusion @Alan-Cha 2026-08-11

Open PRs (5)

Ready to Merge (1)

# Title Author Notes
#490 Fix: regenerate token-broker go.sum for renamed co... @Ibrahim2595 SECURITY, stale (28d)

Needs Review (3)

# Title Author Days Notes
#509 build(deps): bump the minor-and-patch group across... @app/dependabot 0 SECURITY
#503 build(deps): bump the minor-and-patch group across... @app/dependabot 14
#495 build(deps): bump the major group across 1 directo... @app/dependabot 21 stale (21d)

Draft PRs (1)

  • #478 — feat(operator): fetch JWT-SVID via go-spiffe SDK, remove spiffe-helper sidecar

CI Health

  • 30/30 (100%) passed

New Issues (2)

# Title Created
#508 release.yml doesn't pin injected AuthBridge images (they ... 2026-08-17
#507 [dep-bump] Stale routine bump: major group in operator 2026-08-13

examples

Merged PRs (1)

Top contributors: @evaline-ju (1)

# Title Author Merged
#789 🐛 Update link @evaline-ju 2026-08-11

Open PRs (36)

Needs Review (36)

# Title Author Days Notes
#804 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#803 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#802 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#801 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#800 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#799 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#798 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
#797 chore(deps): Bump the minor-and-patch group across... @app/dependabot 3 SECURITY
... +28 more

CI Health

  • 22/30 (73%) passed
  • Failing: "Build-Publish" — 1 failure(s)

New Issues (1)

# Title Created
#788 [dep-bump] Stale routine bump: Update a2a-sdk[http-server... 2026-08-11

.github

Open PRs (1)

Ready to Merge (1)

# Title Author Notes
#116 Update Platform Tools title and description @Ronen-Levy

CI Health

  • 22/30 (73%) passed

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions