Skip to content

chore(Item 11 tail): resolve 10 stale .md (keep canonical .adoc) + 2 .md→.adoc conversions #178

chore(Item 11 tail): resolve 10 stale .md (keep canonical .adoc) + 2 .md→.adoc conversions

chore(Item 11 tail): resolve 10 stale .md (keep canonical .adoc) + 2 .md→.adoc conversions #178

Workflow file for this run

# SPDX-License-Identifier: PMPL-1.0-or-later
# Hypatia Neurosymbolic CI/CD Security Scan — SELF-SCAN (dogfooding)
# The standards repo that defines Hypatia scans itself with Hypatia.
name: Hypatia Self-Scan
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
schedule:
- cron: '0 0 * * 0' # Weekly on Sunday
workflow_dispatch:
permissions: read-all
jobs:
scan:
name: Hypatia Neurosymbolic Analysis (Dogfooding)
runs-on: ubuntu-latest
steps:
- name: Checkout repository
# Repinned from 34e114876b… (unique to this workflow, job fast-failed
# ~12s at this first step) to the SHA used by every other passing
# workflow in the repo. The setup-beam pins were a red herring.
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
with:
fetch-depth: 0
- name: Setup Elixir for Hypatia scanner
uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
with:
# Pinned to currently-published, setup-beam-resolvable versions.
# The previous pins (elixir 1.19.4 / otp 28.3) do not exist in the
# setup-beam index, so this step failed fast on every run and made
# the dogfooding job red estate-wide regardless of PR content.
# Major/minor (loose) so patch availability cannot re-break it.
# Bump deliberately to whatever Hypatia's scanner actually requires.
# (no-op touch to trigger a verification run of these pins)
elixir-version: '1.18'
otp-version: '27'
- name: Clone Hypatia
run: |
git clone --depth 1 https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia"
- name: Build Hypatia scanner
run: |
cd "$HOME/hypatia"
if [ ! -f hypatia-v2 ]; then
cd scanner && mix deps.get && mix escript.build && mv hypatia ../hypatia-v2
fi
- name: Run Hypatia scan
id: scan
env:
# Suppress the "Dependabot alerts unavailable: GITHUB_TOKEN not set"
# warning so the run is silent-warning-free.
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
echo "Scanning standards repo (dogfooding)"
# --exit-zero so a findings-found exit-1 doesn't short-circuit the
# rest of this step under `set -e`. The "Check for critical or
# high-severity issues" step below is the explicit gate.
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json
FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0)
CRITICAL=$(jq '[.[] | select(.severity == "critical")] | length' hypatia-findings.json 2>/dev/null || echo 0)
HIGH=$(jq '[.[] | select(.severity == "high")] | length' hypatia-findings.json 2>/dev/null || echo 0)
MEDIUM=$(jq '[.[] | select(.severity == "medium")] | length' hypatia-findings.json 2>/dev/null || echo 0)
echo "findings_count=$FINDING_COUNT" >> $GITHUB_OUTPUT
echo "critical=$CRITICAL" >> $GITHUB_OUTPUT
echo "high=$HIGH" >> $GITHUB_OUTPUT
echo "medium=$MEDIUM" >> $GITHUB_OUTPUT
echo "## Hypatia Self-Scan Results (Dogfooding)" >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "The standards repo scans itself. Findings here are compliance" >> $GITHUB_STEP_SUMMARY
echo "gaps between what we define and what we practice." >> $GITHUB_STEP_SUMMARY
echo "" >> $GITHUB_STEP_SUMMARY
echo "| Severity | Count |" >> $GITHUB_STEP_SUMMARY
echo "|----------|-------|" >> $GITHUB_STEP_SUMMARY
echo "| Critical | $CRITICAL |" >> $GITHUB_STEP_SUMMARY
echo "| High | $HIGH |" >> $GITHUB_STEP_SUMMARY
echo "| Medium | $MEDIUM |" >> $GITHUB_STEP_SUMMARY
echo "| **Total**| $FINDING_COUNT |" >> $GITHUB_STEP_SUMMARY
- name: Run panic-attack assail
run: |
# Install panic-attack if available
if command -v panic-attack >/dev/null 2>&1; then
panic-attack assail . > panic-attack-findings.json 2>&1 || true
echo "panic-attack scan complete"
else
echo "panic-attack not available in CI — install from hyperpolymath/panic-attacker"
echo "[]" > panic-attack-findings.json
fi
- name: Upload findings artifacts
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
with:
name: standards-self-scan
path: |
hypatia-findings.json
panic-attack-findings.json
retention-days: 90
- name: Check for critical issues
if: steps.scan.outputs.critical > 0
run: |
echo "Critical self-scan issues found in the standards repo!"
echo "The repo that defines standards has compliance gaps."
echo "Review hypatia-findings.json for details."
# Warn but don't fail — fix forward