Skip to content

fix(ci): remove rust-ci.yml as repo has no Cargo.toml #119

fix(ci): remove rust-ci.yml as repo has no Cargo.toml

fix(ci): remove rust-ci.yml as repo has no Cargo.toml #119

Triggered via pull request September 11, 2026 09:07
Status Failure
Total duration 49s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
8s
panic-attack assail
Hypatia neurosymbolic scan
32s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
7s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
10s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

12 errors, 10 warnings, and 2 notices
Hypatia neurosymbolic scan
Process completed with exit code 1.
Hypatia neurosymbolic scan
Hypatia found 8 critical security issue(s) — blocking merge
Hypatia neurosymbolic scan: .machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .envrc#L23
[hypatia] Secret found: Generic API key
Hypatia neurosymbolic scan: build/setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L51
[hypatia] workflow .github/workflows/dependabot-automerge.yml:51 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
Hypatia neurosymbolic scan: instant-sync.yml#L1
[hypatia] Issue in instant-sync.yml
Hypatia neurosymbolic scan: .github/workflows/boj-build.yml#L1
[hypatia] workflow .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — no outbound-egress telemetry
Hypatia neurosymbolic scan: .github/workflows/release.yml#L1
[hypatia] workflow .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — no outbound-egress telemetry
Hypatia neurosymbolic scan: .github/workflows/push-email-notify.yml#L1
[hypatia] workflow .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — no outbound-egress telemetry
Hypatia neurosymbolic scan: labels.yml#L1
[hypatia] Issue in labels.yml
Hypatia neurosymbolic scan: label-triage.yml#L1
[hypatia] Issue in label-triage.yml
Hypatia neurosymbolic scan: release.yml#L1
[hypatia] Action softprops/action-gh-release@v3.0.3 needs attention
Hypatia neurosymbolic scan: quality.yml#L1
[hypatia] Action editorconfig-checker/action-editorconfig-checker@v3.0.0 needs attention
Hypatia neurosymbolic scan: pages.yml#L1
[hypatia] Action actions/deploy-pages@v5.0.1 needs attention
Hypatia neurosymbolic scan: codeql.yml#L1
[hypatia] Action github/codeql-action/analyze@v4.37.9 needs attention
Hypatia neurosymbolic scan: codeql.yml#L1
[hypatia] Action github/codeql-action/init@v4.37.9 needs attention
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
panic-attack assail
panic-attack binary not available — skipping assail

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:525b055beb8fa8b0c26779e6bb4c351ef92dd2aede85269a387e1490aa40b37d
hypatia-findings
2.2 KB
sha256:9d44ed09df14700a249ec7f430abbb8188a8a10b5589e3e82d0a33e8028a7f8b
panic-attack-findings
171 Bytes
sha256:b8a2c6d9c9c49c87f4ba28d69ed54c6be8332e12989d7ba278fe6b3e7ad418c9
unified-findings
2.46 KB
sha256:2998886c2c09601b98fba35e0b6130e330874547fb03d89044615c7f96bbd53d