Repository navigation
chore(Item 11 tail): resolve 10 stale .md (keep canonical .adoc) + 2 .md→.adoc conversions #178
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: PMPL-1.0-or-later | |
| # Hypatia Neurosymbolic CI/CD Security Scan — SELF-SCAN (dogfooding) | |
| # The standards repo that defines Hypatia scans itself with Hypatia. | |
| name: Hypatia Self-Scan | |
| on: | |
| push: | |
| branches: [ main ] | |
| pull_request: | |
| branches: [ main ] | |
| schedule: | |
| - cron: '0 0 * * 0' # Weekly on Sunday | |
| workflow_dispatch: | |
| permissions: read-all | |
| jobs: | |
| scan: | |
| name: Hypatia Neurosymbolic Analysis (Dogfooding) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout repository | |
| # Repinned from 34e114876b… (unique to this workflow, job fast-failed | |
| # ~12s at this first step) to the SHA used by every other passing | |
| # workflow in the repo. The setup-beam pins were a red herring. | |
| uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Setup Elixir for Hypatia scanner | |
| uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0 | |
| with: | |
| # Pinned to currently-published, setup-beam-resolvable versions. | |
| # The previous pins (elixir 1.19.4 / otp 28.3) do not exist in the | |
| # setup-beam index, so this step failed fast on every run and made | |
| # the dogfooding job red estate-wide regardless of PR content. | |
| # Major/minor (loose) so patch availability cannot re-break it. | |
| # Bump deliberately to whatever Hypatia's scanner actually requires. | |
| # (no-op touch to trigger a verification run of these pins) | |
| elixir-version: '1.18' | |
| otp-version: '27' | |
| - name: Clone Hypatia | |
| run: | | |
| git clone --depth 1 https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia" | |
| - name: Build Hypatia scanner | |
| run: | | |
| cd "$HOME/hypatia" | |
| if [ ! -f hypatia-v2 ]; then | |
| cd scanner && mix deps.get && mix escript.build && mv hypatia ../hypatia-v2 | |
| fi | |
| - name: Run Hypatia scan | |
| id: scan | |
| env: | |
| # Suppress the "Dependabot alerts unavailable: GITHUB_TOKEN not set" | |
| # warning so the run is silent-warning-free. | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| run: | | |
| echo "Scanning standards repo (dogfooding)" | |
| # --exit-zero so a findings-found exit-1 doesn't short-circuit the | |
| # rest of this step under `set -e`. The "Check for critical or | |
| # high-severity issues" step below is the explicit gate. | |
| HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json | |
| FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0) | |
| CRITICAL=$(jq '[.[] | select(.severity == "critical")] | length' hypatia-findings.json 2>/dev/null || echo 0) | |
| HIGH=$(jq '[.[] | select(.severity == "high")] | length' hypatia-findings.json 2>/dev/null || echo 0) | |
| MEDIUM=$(jq '[.[] | select(.severity == "medium")] | length' hypatia-findings.json 2>/dev/null || echo 0) | |
| echo "findings_count=$FINDING_COUNT" >> $GITHUB_OUTPUT | |
| echo "critical=$CRITICAL" >> $GITHUB_OUTPUT | |
| echo "high=$HIGH" >> $GITHUB_OUTPUT | |
| echo "medium=$MEDIUM" >> $GITHUB_OUTPUT | |
| echo "## Hypatia Self-Scan Results (Dogfooding)" >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "The standards repo scans itself. Findings here are compliance" >> $GITHUB_STEP_SUMMARY | |
| echo "gaps between what we define and what we practice." >> $GITHUB_STEP_SUMMARY | |
| echo "" >> $GITHUB_STEP_SUMMARY | |
| echo "| Severity | Count |" >> $GITHUB_STEP_SUMMARY | |
| echo "|----------|-------|" >> $GITHUB_STEP_SUMMARY | |
| echo "| Critical | $CRITICAL |" >> $GITHUB_STEP_SUMMARY | |
| echo "| High | $HIGH |" >> $GITHUB_STEP_SUMMARY | |
| echo "| Medium | $MEDIUM |" >> $GITHUB_STEP_SUMMARY | |
| echo "| **Total**| $FINDING_COUNT |" >> $GITHUB_STEP_SUMMARY | |
| - name: Run panic-attack assail | |
| run: | | |
| # Install panic-attack if available | |
| if command -v panic-attack >/dev/null 2>&1; then | |
| panic-attack assail . > panic-attack-findings.json 2>&1 || true | |
| echo "panic-attack scan complete" | |
| else | |
| echo "panic-attack not available in CI — install from hyperpolymath/panic-attacker" | |
| echo "[]" > panic-attack-findings.json | |
| fi | |
| - name: Upload findings artifacts | |
| uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 | |
| with: | |
| name: standards-self-scan | |
| path: | | |
| hypatia-findings.json | |
| panic-attack-findings.json | |
| retention-days: 90 | |
| - name: Check for critical issues | |
| if: steps.scan.outputs.critical > 0 | |
| run: | | |
| echo "Critical self-scan issues found in the standards repo!" | |
| echo "The repo that defines standards has compliance gaps." | |
| echo "Review hypatia-findings.json for details." | |
| # Warn but don't fail — fix forward |