Repository navigation
ci(rhodibot): switch to the report-only canary (standards#759) (#55) #144
static-analysis-gate.yml
on: push
panic-attack assail
6s
Hypatia neurosymbolic scan
37s
Patch Bridge CVE triage
5s
Deposit findings for gitbot-fleet
6s
Annotations
12 errors, 14 warnings, and 6 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 10 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
|
|
Hypatia neurosymbolic scan:
.machine_readable/svc/k9/methodology-guard.k9.ncl#L1
[hypatia] K9 contractile missing pedigree section (1 occurrences, CWE-1104)
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L52
[hypatia] workflow .github/workflows/dependabot-automerge.yml:52 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
|
|
Hypatia neurosymbolic scan:
instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
|
|
Patch Bridge CVE triage
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
panic-attack assail
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan:
dogfood-gate.yml#L1
[hypatia] Job `empty-lint` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
dogfood-gate.yml#L1
[hypatia] Job `eclexiaiser-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
dogfood-gate.yml#L1
[hypatia] Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
dogfood-gate.yml#L1
[hypatia] Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
dependabot-automerge.yml#L1
[hypatia] Job `automerge` in dependabot-automerge.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
codeql.yml#L1
[hypatia] Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
casket-pages.yml#L1
[hypatia] Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
casket-pages.yml#L1
[hypatia] Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
boj-build.yml#L1
[hypatia] Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
rhodibot.yml#L1
[hypatia] Action `actions/checkout@v7.0.1` in rhodibot.yml is not pinned to a commit SHA — `v7.0.1` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Deposit findings for gitbot-fleet
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
|
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:dbd00a0da0ac501512138fe08d2864b31cc32319a6ff1d214ba5f080a3273998
|
|
|
hypatia-findings
|
3.19 KB |
sha256:25075af869ce8ae30829bb421266a0d3280c88e7928b3d542f497a282bd13879
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:c6af499af29256dcd81d32b31382ec7dc6394846bb5b27d9694feb39aa498714
|
|
|
unified-findings
|
3.44 KB |
sha256:2a9b5658ba787b3e47a90617377c8dc68aaccde6ebfb2d2ba56db0e9fe677acd
|
|