Repository navigation
chore(deps): bump github/codeql-action from 4.38.1 to 4.38.2 in the a… #205
static-analysis-gate.yml
on: push
panic-attack assail
7s
Hypatia neurosymbolic scan
36s
Deposit findings for gitbot-fleet
5s
Annotations
11 errors, 10 warnings, and 4 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 6 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
/home/runner/work/nimiser/nimiser#L1
[hypatia] 1 workflow(s) missing permissions declaration in nimiser
|
|
Hypatia neurosymbolic scan:
setup.sh#L144
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494, line 144, 156)
|
|
Hypatia neurosymbolic scan:
.github/workflows/instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
|
|
Hypatia neurosymbolic scan:
.github/workflows/codeql.yml#L1
[hypatia] Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/casket-pages.yml#L1
[hypatia] Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/casket-pages.yml#L1
[hypatia] Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/boj-build.yml#L1
[hypatia] Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/abi-ffi-gate.yml#L1
[hypatia] Job `zig-build` in abi-ffi-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/abi-ffi-gate.yml#L1
[hypatia] Job `conformance` in abi-ffi-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/k9-svc-validation.yml#L1
[hypatia] No permissions declaration -- add permissions: read-all
|
|
Hypatia neurosymbolic scan:
.github/workflows/codeql.yml#L1
[hypatia] Action `github/codeql-action/analyze@v4.38.2` in codeql.yml is not pinned to a commit SHA — `v4.38.2` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
.github/workflows/codeql.yml#L1
[hypatia] Action `github/codeql-action/init@v4.38.2` in codeql.yml is not pinned to a commit SHA — `v4.38.2` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
.github/workflows/casket-pages.yml#L1
[hypatia] Action `haskell-actions/setup@v2.12.1` in casket-pages.yml is not pinned to a commit SHA — `v2.12.1` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
hypatia-findings
|
2.82 KB |
sha256:ddd14daabc44d720ebbc7655d0a26cc24de48669d63d39d55e9597e496b2c824
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:dd84ba713a4cfb5bdc75a89f185ad25b13ca1902605d2158033dcfa3fc521ad6
|
|
|
unified-findings
|
3.01 KB |
sha256:f049fcdc4cbf90ca998bc98711da52a1ddfbfdb56a98662a2d0a44a37e13d289
|
|