Supervised Fleet Scan #5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: PMPL-1.0-or-later | |
| # Scheduled/dispatch pipeline for supervised-repo scanning via Hypatia + gitbot-fleet. | |
| name: Supervised Fleet Scan | |
| on: | |
| schedule: | |
| - cron: '0 3 * * 1' | |
| workflow_dispatch: | |
| inputs: | |
| limit: | |
| description: 'Maximum repos to scan (0 = all resolved)' | |
| required: false | |
| default: '0' | |
| inventory_file: | |
| description: 'Optional inventory file path (.git-private-repos or .git-private-farm.scm)' | |
| required: false | |
| default: '' | |
| process_findings: | |
| description: 'Run fleet process-findings after scan' | |
| required: false | |
| type: boolean | |
| default: true | |
| permissions: | |
| contents: read | |
| jobs: | |
| supervised-scan: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout gitbot-fleet | |
| uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 | |
| - name: Clone Hypatia scanner | |
| run: | | |
| set -euo pipefail | |
| git clone --depth=1 https://github.com/hyperpolymath/hypatia.git ../hypatia | |
| - name: Run supervised fleet scan | |
| env: | |
| LIMIT: ${{ github.event.inputs.limit || '0' }} | |
| INVENTORY_FILE: ${{ github.event.inputs.inventory_file || '' }} | |
| PROCESS_FINDINGS: ${{ github.event.inputs.process_findings || 'true' }} | |
| FLEET_SUPERVISED_REPOS_FILE: ${{ github.event.inputs.inventory_file || '' }} | |
| # GITHUB_TOKEN is required for Hypatia's DependabotAlerts | |
| # rule (DA001-DA004) to query per-repo Dependabot alerts via | |
| # the GitHub REST API. The built-in secrets.GITHUB_TOKEN | |
| # only has scope for the gitbot-fleet repo itself — for | |
| # cross-repo scanning across the estate, promote this to a | |
| # PAT secret (FLEET_SCAN_PAT) with `security_events` scope | |
| # on every target repo. Without a valid token, the rule | |
| # silently returns no findings and Dependabot alerts are | |
| # missed. See | |
| # 007-lang/audits/audit-dependabot-automation-gap-2026-04-17.md. | |
| GITHUB_TOKEN: ${{ secrets.FLEET_SCAN_PAT || secrets.GITHUB_TOKEN }} | |
| # HYPATIA_SEVERITY=low surfaces low-severity findings from | |
| # every rule module. The Hypatia CLI's default threshold is | |
| # "medium"; without this override, low-severity findings | |
| # from any rule (not just DependabotAlerts) are dropped. | |
| HYPATIA_SEVERITY: low | |
| run: | | |
| set -euo pipefail | |
| ARGS=(--limit "$LIMIT") | |
| if [[ -n "$INVENTORY_FILE" ]]; then | |
| ARGS+=(--inventory "$INVENTORY_FILE") | |
| fi | |
| if [[ "$PROCESS_FINDINGS" == "true" ]]; then | |
| ARGS+=(--process) | |
| fi | |
| echo "Running: fleet-coordinator.sh scan-supervised ${ARGS[*]}" | |
| bash fleet-coordinator.sh scan-supervised "${ARGS[@]}" |