Repository navigation
chore(deps): bump uuid in /bots/accessibilitybot (#525) #1160
governance.yml
on: push
governance
/
Check Workflow Staleness
7s
governance
/
Allowlist Preflight
5s
governance
/
Live Actions policy (credentialed advisory)
4s
governance
/
...
/
package anti-pattern policy
6s
governance
/
Guix packaging policy (Nix retired)
9s
governance
/
Security policy checks
7s
governance
/
Code quality + docs
10s
governance
/
Well-Known (RFC 9116 + RSR)
5s
governance
/
Workflow security linter
14s
governance
/
Actions lockfile verify
10s
governance
/
Trusted-base reduction policy
7s
governance
/
Licence consistency
7s
governance
/
Exemption ratchet
governance
/
Debt ratchet
0s
governance
/
Validate Hypatia Baseline
30s
Annotations
2 errors and 4 warnings
|
governance / Actions lockfile verify
Process completed with exit code 1.
|
|
governance / Actions lockfile verify
actions-lock gate: lockfile verification FAILED (exit 1). Regenerate with scripts/update-actions-lock.sh in the same PR as the uses: change.
|
|
governance / Live Actions policy (credentialed advisory)
Live Actions policy was not evaluated: HYPATIA_SCAN_PAT was not supplied by the caller. The separate tree allowlist gate still ran.
|
|
governance / Well-Known (RFC 9116 + RSR)
Missing RSR recommended files: ai.txt humans.txt
|
|
governance / Security policy checks
HTTP URLs found — ADVISORY, does not fail this job. Use HTTPS:
|
|
governance / Security policy checks
Weak crypto (MD5/SHA1) detected — ADVISORY, does not fail this job. Use SHA256+:
|