Repository navigation
fix(ci): make the dogfood gate .deed-aware #125
static-analysis-gate.yml
on: pull_request
panic-attack assail
8s
Hypatia neurosymbolic scan
28s
Patch Bridge CVE triage
6s
Deposit findings for gitbot-fleet
5s
Annotations
12 errors, 10 warnings, and 2 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 7 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
.github/workflows/openssf-compliance.yml#L72
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
build/setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L51
[hypatia] workflow .github/workflows/dependabot-automerge.yml:51 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
|
|
Hypatia neurosymbolic scan:
instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
|
|
Hypatia neurosymbolic scan:
.github/workflows/release.yml#L143
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/push-email-notify.yml#L45
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
release.yml#L1
[hypatia] Action `softprops/action-gh-release@v3.0.3` in release.yml is not pinned to a commit SHA — `v3.0.3` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
quality.yml#L1
[hypatia] Action `editorconfig-checker/action-editorconfig-checker@v3.0.0` in quality.yml is not pinned to a commit SHA — `v3.0.0` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
push-email-notify.yml#L1
[hypatia] Action `hyperpolymath/smtp-notify-action@v0.3.0` in push-email-notify.yml is not pinned to a commit SHA — `v0.3.0` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
pages.yml#L1
[hypatia] Action `actions/deploy-pages@v5.0.1` in pages.yml is not pinned to a commit SHA — `v5.0.1` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
codeql.yml#L1
[hypatia] Action `github/codeql-action/analyze@v4.38.0` in codeql.yml is not pinned to a commit SHA — `v4.38.0` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
codeql.yml#L1
[hypatia] Action `github/codeql-action/init@v4.38.0` in codeql.yml is not pinned to a commit SHA — `v4.38.0` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:a216cc0eb9f13da229c5857d1fc06cfdec7fd738667eb333d34f20a5af30a8ee
|
|
|
hypatia-findings
|
2.85 KB |
sha256:84222d37e70450aa187b920d2ee4390a719dc6459840d7aa4c08c8122781d3bb
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:1c93811d88934754ce95a74778eb90125bd9cc9ca3df8e54b07a82a1661b60bf
|
|
|
unified-findings
|
3.1 KB |
sha256:00f95cda26b08c06f2e3400cdaa3e9ef55b17d1ded85fe7b5d5595426fedb188
|
|