chore(www): migrate root .well-known/ to www/.well-known/ (#94) #263
static-analysis-gate.yml
on: push
panic-attack assail
7s
Hypatia neurosymbolic scan
27s
Patch Bridge CVE triage
8s
Deposit findings for gitbot-fleet
4s
Annotations
2 errors, 14 warnings, and 6 notices
|
Hypatia neurosymbolic scan:
.github/workflows/hypatia-scan.yml#L1
[hypatia] workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.
|
|
Static Analysis Gate
The run was canceled by @hyperpolymath.
|
|
panic-attack assail
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Patch Bridge CVE triage
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan:
.github/workflows/rhodibot.yml#L225
[hypatia] job in .github/workflows/rhodibot.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/instant-sync.yml#L24
[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/labels.yml#L38
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/label-triage.yml#L52
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/hypatia-scan.yml#L83
[hypatia] job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/boj-build.yml#L23
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/release.yml#L119
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/push-email-notify.yml#L44
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Deposit findings for gitbot-fleet
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
|
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:26a1e506a19d40234602e5b9e1446dbe5e4ae553b736fdfdafc3f63f9a0f77f9
|
|
|
hypatia-findings
|
1.6 KB |
sha256:bd317865c6150c68f68594a14166ae92d6b94057b95909bf86b86d5372064f00
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:b7425c4d5bf6d18f5c22b3e6776672df90dbcc784e832383e81794fc258f5311
|
|
|
unified-findings
|
1.84 KB |
sha256:6cf55d70b7446d81ae9be46e647dd632adbe49a0f782960467e78469c1e2c2a0
|
|