Repository navigation
Chore/phase11 final #176
static-analysis-gate.yml
on: pull_request
panic-attack assail
8s
Hypatia neurosymbolic scan
29s
Patch Bridge CVE triage
4s
Deposit findings for gitbot-fleet
9s
Annotations
6 errors, 10 warnings, and 6 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 1 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
build/setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L51
[hypatia] workflow .github/workflows/dependabot-automerge.yml:51 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
|
|
Hypatia neurosymbolic scan:
instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
|
|
Hypatia neurosymbolic scan:
0-AI-MANIFEST.a2ml#L1
[hypatia] Required file missing
|
|
Hypatia neurosymbolic scan:
.github/workflows/labels.yml#L39
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/label-triage.yml#L53
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L59
[hypatia] job in .github/workflows/dependabot-automerge.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/boj-build.yml#L27
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/release.yml#L130
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/push-email-notify.yml#L46
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
quality.yml#L1
[hypatia] Action `trufflesecurity/trufflehog@v3.97.5` in quality.yml is not pinned to a commit SHA — `v3.97.5` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
GEMINI.md#L1
[hypatia] Stale AI session file -- delete
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
|
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:cf074c79e3b39a01e1d167fb4c7f5887090407d86b185ff10c817b5857b69da7
|
|
|
hypatia-findings
|
2.69 KB |
sha256:cab1979a169f4c7cf986f0013d77417963c6feb7c7a62676985d4cbab6991cd1
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:72d8e0b663d34e74783b9f9ff68a3a05255d6c60b11a5f1a4ad824344ea1ed11
|
|
|
unified-findings
|
2.93 KB |
sha256:0ba2126c56345e3a34da8904f32c0b8e987e5313c6dcf9c56af21dbd48d5fc66
|
|