Skip to content

chore(deps): bump the actions group across 1 directory with 4 updates #140

chore(deps): bump the actions group across 1 directory with 4 updates

chore(deps): bump the actions group across 1 directory with 4 updates #140

Triggered via pull request September 17, 2026 05:56
Status Success
Total duration 46s
Artifacts –

governance.yml

on: pull_request
governance  /  Check Workflow Staleness
12s
governance / Check Workflow Staleness
governance  /  Allowlist Preflight
8s
governance / Allowlist Preflight
governance  /  Live Actions policy (credentialed advisory)
7s
governance / Live Actions policy (credentialed advisory)
governance  /  ...  /  package anti-pattern policy
7s
governance / Language / package anti-pattern policy
governance  /  Guix packaging policy (Nix retired)
8s
governance / Guix packaging policy (Nix retired)
governance  /  Security policy checks
5s
governance / Security policy checks
governance  /  Code quality + docs
28s
governance / Code quality + docs
governance  /  Well-Known (RFC 9116 + RSR)
5s
governance / Well-Known (RFC 9116 + RSR)
governance  /  Workflow security linter
13s
governance / Workflow security linter
governance  /  Actions lockfile verify
6s
governance / Actions lockfile verify
governance  /  Trusted-base reduction policy
6s
governance / Trusted-base reduction policy
governance  /  Licence consistency
7s
governance / Licence consistency
governance  /  Exemption ratchet
7s
governance / Exemption ratchet
governance  /  Debt ratchet
9s
governance / Debt ratchet
governance  /  Validate Hypatia Baseline
4s
governance / Validate Hypatia Baseline
Fit to window
Zoom out
Zoom in

Annotations

1 error and 3 warnings
governance / Code quality + docs
Error: Unexpected HTTP response: 500
governance / Actions lockfile verify
actions-lock gate: no .github/workflows/actions.lock. All refs are SHA-pinned, but the lockfile becomes REQUIRED on 2026-10-01 (today is 2026-09-17). Run scripts/update-actions-lock.sh.
governance / Live Actions policy (credentialed advisory)
Live Actions policy was not evaluated: HYPATIA_SCAN_PAT was not supplied by the caller. The separate tree allowlist gate still ran.
governance / Workflow security linter
UNVERIFIED: 1 of 18 pin(s) could not be checked