Skip to content

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) #215

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure)

fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) #215

Triggered via pull request September 22, 2026 11:32
Status Failure
Total duration 1m 24s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
7s
panic-attack assail
Hypatia neurosymbolic scan
29s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
5s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
5s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

12 errors, 10 warnings, and 6 notices
Hypatia neurosymbolic scan
Process completed with exit code 1.
Hypatia neurosymbolic scan
Hypatia found 7 critical security issue(s) — blocking merge
Hypatia neurosymbolic scan: Justfile#L55
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: .machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
Hypatia neurosymbolic scan: setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L55
[hypatia] workflow .github/workflows/dependabot-automerge.yml:55 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
Hypatia neurosymbolic scan: instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
Hypatia neurosymbolic scan: dogfood-gate.yml#L1
[hypatia] Job `k9-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: dogfood-gate.yml#L1
[hypatia] Job `groove-check` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: dogfood-gate.yml#L1
[hypatia] Job `empty-lint` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: dogfood-gate.yml#L1
[hypatia] Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: dogfood-gate.yml#L1
[hypatia] Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: dependabot-automerge.yml#L1
[hypatia] Job `automerge` in dependabot-automerge.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: codeql.yml#L1
[hypatia] Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: casket-pages.yml#L1
[hypatia] Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: casket-pages.yml#L1
[hypatia] Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: boj-build.yml#L1
[hypatia] Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
panic-attack assail
panic-attack binary not available — skipping assail
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:9c201ce28e0e0937b7bf337aad7d6b9793d4c95538c7ca8a4a665ce78792ca72
hypatia-findings
2.23 KB
sha256:d21fab6da5d20a5302c48e59e6295d4481363511eab514bca359c01b32fbffcf
panic-attack-findings
171 Bytes
sha256:7e707b62d909441ebeefa1adda1134865c6e0e5fc1f84f6344669e7105eab439
unified-findings
2.49 KB
sha256:0256d894ddfafc01a2e94dec9e6bf90070a26e340ffce2855ebe566d4828cbb7