Repository navigation
chore(deps): bump the actions group with 2 updates (#81) #184
static-analysis-gate.yml
on: push
panic-attack assail
4s
Hypatia neurosymbolic scan
35s
Patch Bridge CVE triage
7s
Deposit findings for gitbot-fleet
10s
Annotations
12 errors, 10 warnings, and 6 notices
|
Hypatia neurosymbolic scan
Process completed with exit code 1.
|
|
Hypatia neurosymbolic scan
Hypatia found 6 critical security issue(s) — blocking merge
|
|
Hypatia neurosymbolic scan:
Justfile#L390
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
Justfile#L51
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.github/workflows/openssf-compliance.yml#L76
[hypatia] CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/PLAYBOOK.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/NEUROSYM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/AGENTIC.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/ECOSYSTEM.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/META.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.machine_readable/6a2/STATE.a2ml#L1
[hypatia] Descriptile in retired location -- must be in .machine_readable/descriptiles/
|
|
Hypatia neurosymbolic scan:
.github/workflows/dependabot-automerge.yml#L1
[hypatia] workflow .github/workflows/dependabot-automerge.yml performs a write (push/commit/release/PR) but grants no `contents: write` at the workflow level or any job level — the write will be denied at run time.
|
|
Hypatia neurosymbolic scan:
.github/workflows/release.yml#L150
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/sonarqube.yml#L35
[hypatia] job in .github/workflows/sonarqube.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/push-email-notify.yml#L46
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/labels.yml#L39
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
|
|
Hypatia neurosymbolic scan:
.github/workflows/labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
|
|
Hypatia neurosymbolic scan:
.github/workflows/sonarqube.yml#L1
[hypatia] Action `SonarSource/sonarqube-scan-action@v8.3.0` in sonarqube.yml is not pinned to a commit SHA — `v8.3.0` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
.github/workflows/pages.yml#L1
[hypatia] Action `haskell-actions/setup@v2.12.1` in pages.yml is not pinned to a commit SHA — `v2.12.1` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
.github/workflows/codeql.yml#L1
[hypatia] Action `github/codeql-action/analyze@v4.38.2` in codeql.yml is not pinned to a commit SHA — `v4.38.2` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Hypatia neurosymbolic scan:
.github/workflows/codeql.yml#L1
[hypatia] Action `github/codeql-action/init@v4.38.2` in codeql.yml is not pinned to a commit SHA — `v4.38.2` is a tag, and a tag can be moved to a different commit. Pin it to a full 40-character commit SHA, with the version in a trailing comment.
|
|
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
|
|
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
panic-attack assail
panic-attack binary not available — skipping assail
|
|
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
bridge-report
|
218 Bytes |
sha256:81c493fb56183006c1d10514218ba0e1994c780f4f0cb6b827d78bc23d0b7979
|
|
|
hypatia-findings
|
2.37 KB |
sha256:1cd567a465204d9e240ffff5161d1ba1ffccaed501e577a180333a87b24bbb22
|
|
|
panic-attack-findings
|
171 Bytes |
sha256:ba7b167b7430f7187891d535d04709c12f82938b3712413210423fef3552ec5f
|
|
|
unified-findings
|
2.61 KB |
sha256:943d66f997917ebfd4520f601b6545730b2bdf871c7da3d02e73dd529291acef
|
|