Skip to content

fix(claude): exact check-script rules instead of a mid-command wildca… #195

fix(claude): exact check-script rules instead of a mid-command wildca…

fix(claude): exact check-script rules instead of a mid-command wildca… #195

Triggered via push October 7, 2026 07:25
Status Failure
Total duration 1m 2s
Artifacts 4
panic-attack assail
5s
panic-attack assail
Hypatia neurosymbolic scan
33s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
5s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
9s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

12 errors, 10 warnings, and 6 notices
Hypatia neurosymbolic scan
Process completed with exit code 1.
Hypatia neurosymbolic scan
Hypatia found 9 critical security issue(s) — blocking merge
Hypatia neurosymbolic scan: build/setup.sh#L144
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494, line 144, 156)
Hypatia neurosymbolic scan: .github/workflows/hypatia-scan.yml#L1
[hypatia] workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.GITEA_SSH_KEY }}` but has no `if: secrets.GITEA_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.DISROOT_SSH_KEY }}` but has no `if: secrets.DISROOT_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.SOURCEHUT_SSH_KEY }}` but has no `if: secrets.SOURCEHUT_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.CODEBERG_SSH_KEY }}` but has no `if: secrets.CODEBERG_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.BITBUCKET_SSH_KEY }}` but has no `if: secrets.BITBUCKET_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/mirror.yml#L1
[hypatia] Step uses `webfactory/ssh-agent` with `ssh-private-key: ${{ secrets.GITLAB_SSH_KEY }}` but has no `if: secrets.GITLAB_SSH_KEY != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: .github/workflows/scorecard-enforcer.yml#L1
[hypatia] Job runs `ossf/scorecard-action` with `publish_results: true` AND contains a `run:` step. The OSSF publish endpoint enforces "scorecard job must only have steps with uses" — the run-step presence will fail the publish step and the whole workflow. Move any `run:` step (e.g. threshold gate) into a `needs: scorecard` downstream job that consumes the SARIF via upload/download-artifact.
Hypatia neurosymbolic scan: .github/workflows/estate-rules.yml#L1
[hypatia] Job `estate-rules` in estate-rules.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `k9-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `groove-check` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `empty-lint` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `eclexiaiser-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dogfood-gate.yml#L1
[hypatia] Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L1
[hypatia] Job `automerge` in dependabot-automerge.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/codeql.yml#L1
[hypatia] Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: .github/workflows/boj-build.yml#L1
[hypatia] Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
panic-attack assail
panic-attack binary not available — skipping assail
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:40e97a94d034c93df6226e7c0220a4dfddc9e7e6238ffd623721080bf89c8bf4
hypatia-findings
4.12 KB
sha256:2c9f56afbdc6246f8be0c860998063eb7f44c26551e7dd3575f93fceb1410661
panic-attack-findings
171 Bytes
sha256:a52de0ba0506b2a9a74e9874dc84017042d0c7b6e9e0cf97bc13e5b118e300d4
unified-findings
4.41 KB
sha256:2fc1bacccd110d82ed86ed9b339fb76428f4a643d5f6d70ac9e3fed43d0f6bcb