Skip to content

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) #232

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) #232

Triggered via pull request September 20, 2026 02:21
Status Failure
Total duration 1h 5m 18s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
8s
panic-attack assail
Hypatia neurosymbolic scan
34s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
7s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
5s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

7 errors, 14 warnings, and 6 notices
Hypatia neurosymbolic scan
Process completed with exit code 1.
Hypatia neurosymbolic scan
Hypatia found 1 critical security issue(s) — blocking merge
Hypatia neurosymbolic scan: setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
Hypatia neurosymbolic scan: .github/workflows/actions.lock#L1
[hypatia] actions.lock failed closed: {:workflow_dependencies_missing, [{".github/workflows/rhodibot.yml", "actions/checkout@v7.0.1"}]}
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L53
[hypatia] workflow .github/workflows/dependabot-automerge.yml:53 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
Hypatia neurosymbolic scan: rsr-antipattern.yml#L1
[hypatia] inline-python heading-detection regex is not anchored to `^#` / `^#{1,4}\s+`; it also matches prose mentions of the heading phrase, so the parser can silently walk the wrong section. Anchor the regex to the heading shape (e.g. `^#{1,4}\s+.*Phrase`) and name the intended heading in a comment.
Hypatia neurosymbolic scan: actions.lock#L1
[hypatia] Invalid .github/workflows/actions.lock: {:workflow_dependencies_missing, [{".github/workflows/rhodibot.yml", "actions/checkout@v7.0.1"}]}. Regenerate and verify it with gh actions-lock.
Patch Bridge CVE triage
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
panic-attack assail
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2, erlef/setup-beam@v1.20.4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan: .github/workflows/instant-sync.yml#L24
[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/labels.yml#L39
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/label-triage.yml#L53
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/dependabot-automerge.yml#L62
[hypatia] job in .github/workflows/dependabot-automerge.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/boj-build.yml#L35
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/release.yml#L154
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/push-email-notify.yml#L46
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: GEMINI.md#L1
[hypatia] Stale AI session file -- delete
Deposit findings for gitbot-fleet
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4.1.8, actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
panic-attack assail
panic-attack binary not available — skipping assail
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:7576c1e4a97c9573db80dd644002972da7feaecb70c43891aa315deb7f5d4ede
hypatia-findings
2.29 KB
sha256:6fd1bac1eb8db799b54b8a800564542351f3252f04218c7b3cb1cf418513ab0d
panic-attack-findings
171 Bytes
sha256:d3de8b20d5e089ea95d2fb924b76b7fb8b2c1ceb75e57bfd3ee18a3892d772fe
unified-findings
2.54 KB
sha256:a940a536d0de216c7585b56cf7db92e003128e0a9ecfbb59dac193a51d25e085