Repository navigation
refactor: rename Hexadeca → unified-api-adapter (estate-wide) #223
Triggered via pull request
September 21, 2026 00:44
Status
Failure
Total duration
1h 25m 29s
Artifacts
4
static-analysis-gate.yml
on: pull_request
panic-attack assail
6s
Hypatia neurosymbolic scan
37s
Patch Bridge CVE triage
6s
Deposit findings for gitbot-fleet
8s
Annotations
12 errors, 14 warnings, and 6 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 1 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
setup.sh#L1
[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494)
|
|
Hypatia neurosymbolic scan:
crates/burrower-wasm/src/lib.rs#L1
[hypatia] from_raw constructs types from raw pointers without safety checks (2 occurrences, CWE-676)
|
|
Hypatia neurosymbolic scan:
affinescript/runtime/src/gc.rs#L1
[hypatia] unimplemented! macro marks unfinished code that will panic (1 occurrences, CWE-754)
|
|
Hypatia neurosymbolic scan:
affinescript/runtime/src/ffi.rs#L1
[hypatia] from_raw constructs types from raw pointers without safety checks (1 occurrences, CWE-676)
|
|
Hypatia neurosymbolic scan:
affinescript/tools/affinescript-lsp/src/document.rs#L1
[hypatia] RwLock read/write unwrap -- poison will cascade panic (5 occurrences, CWE-754)
|
|
Hypatia neurosymbolic scan:
affinescript/tools/affinescript-lsp/src/main.rs#L1
[hypatia] Lock.unwrap() without poison handling (5 occurrences, CWE-754)
|
|
Hypatia neurosymbolic scan:
.github/workflows/actions.lock#L1
[hypatia] actions.lock failed closed: {:line, 138, {:repository_id_reused, 1275649586, "hyperpolymath/a2ml-ecosystem", "hyperpolymath/deed-ecosystem"}}
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L51
[hypatia] workflow .github/workflows/dependabot-automerge.yml:51 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork
|
|
Hypatia neurosymbolic scan:
instant-sync.yml#L1
[hypatia] Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.
|
|
Hypatia neurosymbolic scan:
actions.lock#L1
[hypatia] Invalid .github/workflows/actions.lock: {:line, 138, {:repository_id_reused, 1275649586, "hyperpolymath/a2ml-ecosystem", "hyperpolymath/deed-ecosystem"}}. Regenerate and verify it with gh actions-lock.
|
|
panic-attack assail
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Patch Bridge CVE triage
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2, erlef/setup-beam@v1.20.4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Hypatia neurosymbolic scan:
.github/workflows/security-policy.yml#L26
[hypatia] workflow .github/workflows/security-policy.yml:26 step `Security checks` swallows non-zero exit via `|| true` — failures will be masked
|
|
Hypatia neurosymbolic scan:
.github/workflows/instant-sync.yml#L22
[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/labels.yml#L40
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/label-triage.yml#L54
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L59
[hypatia] job in .github/workflows/dependabot-automerge.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/boj-build.yml#L27
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/release.yml#L141
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/push-email-notify.yml#L46
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Deposit findings for gitbot-fleet
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4.1.8, actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
|
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:717ebcfbfe3092d363a3f78cb83d34632b7c13dc4c23451228f623f1a7e56485
|
|
|
hypatia-findings
|
2.87 KB |
sha256:9b89f55c35b286799d01f12af7aab86091ed1a01c9ffbe40ccafab2cd5844da0
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:897032010ea082123dbb92be1610206ebe4ee52624554161b86f3e31b282b426
|
|
|
unified-findings
|
3.11 KB |
sha256:fbf1a279adfdb5ae822eb4dee14c1d9bb6b719a18b885584fb5f742a1de6fa53
|
|