Skip to content

fix(ci): repair the permissions block indentation (invalid YAML) #127

fix(ci): repair the permissions block indentation (invalid YAML)

fix(ci): repair the permissions block indentation (invalid YAML) #127

Triggered via pull request September 21, 2026 07:54
Status Failure
Total duration 21m 26s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
5s
panic-attack assail
Hypatia neurosymbolic scan
32s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
6s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
10s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

12 errors, 10 warnings, and 6 notices
Hypatia neurosymbolic scan
Process completed with exit code 1.
Hypatia neurosymbolic scan
Hypatia found 7 critical security issue(s) — blocking merge
Hypatia neurosymbolic scan: Justfile#L55
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .github/workflows/openssf-compliance.yml#L73
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L1
[hypatia] workflow .github/workflows/dependabot-automerge.yml performs a write (push/commit/release/PR) but grants no `contents: write` at the workflow level or any job level — the write will be denied at run time.
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L51
[hypatia] workflow .github/workflows/dependabot-automerge.yml:51 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
Hypatia neurosymbolic scan: .github/workflows/sonarqube.yml#L32
[hypatia] job in .github/workflows/sonarqube.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/instant-sync.yml#L22
[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/labels.yml#L38
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/label-triage.yml#L52
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L59
[hypatia] job in .github/workflows/dependabot-automerge.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/boj-build.yml#L27
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/release.yml#L145
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/push-email-notify.yml#L44
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
panic-attack assail
panic-attack binary not available — skipping assail
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:51a337fbd7385966c7cc3b59176926f0135743a617dc56e0fbe1d576918340ce
hypatia-findings
2.06 KB
sha256:3d59cfc909d8e084c8c9e13d149008701d2baec257064440f983e2518dff0632
panic-attack-findings
171 Bytes
sha256:bf98cafb6d6fae06a8ea83508ab84de8947aefcf768b7f667f61efb878ab5eee
unified-findings
2.31 KB
sha256:308d6d107d98b358878788d79dea00d9384578d4c3f27ffbcaa69687e8b87d53