Skip to content

ci: Hypatia fails on two findings #117 does not cover (dependabot-automerge actor gate, rsr-antipattern regex); SonarCloud red on main 86cb69e #121

Description

@hyperpolymath

Measured (2026-09-30 about 16:05Z)

The Hypatia neurosymbolic scan check-run on PR #120 (head f423714, which changes only docs/TYPE-CONNECTIONS.adoc) concludes FAILURE with four failure-level annotations:

  1. setup.sh: download-and-execute pattern, CWE-494 ×2. Already tracked in ci: two pre-existing reds on main — Static Analysis Gate (Hypatia CWE-494 ×2 in setup.sh) and Well-Known Standards (security.txt under www/.well-known, validator reads the root) #117.
  2. .github/workflows/dependabot-automerge.yml:53 gates on github.actor == 'dependabot[bot]'. Not tracked. The actor is spoofable as a trust boundary; the robust predicate is github.event.pull_request.user.login together with dependabot/fetch-metadata.
  3. rsr-antipattern.yml: the heading-detection regex is not anchored to ^#{1,4}\s+, so it also matches prose mentions. Not tracked.
  4. The rolled-up "1 critical security issue — blocking merge".

SonarCloud Code Analysis is also FAILURE on main 86cb69e5, with the cause unmeasured. It did not report on #120.

None of these touch a file #120 changes. They block #120 only through the standing owner ruling of 2026-09-22 ("land only fully-green PRs … a pre-existing red gets a triage issue, not a merge over it").

Acceptance criteria

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    choreRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions