Skip to content

chore(ci): convert hypatia-scan.yml to wrapper of standards reusable - #37

Merged
hyperpolymath merged 2 commits into
mainfrom
chore/hypatia-scan-reusable-wrapper
May 26, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
chore/hypatia-scan-reusable-wrapper

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Replaces the per-repo hypatia-scan.yml (416 lines) with a 29-line wrapper calling hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@2569c10e831e293f9dd6580d82a494aca039deee (standards#191 HEAD SHA).

Behaviour-preserving: identical triggers (push/pull_request/schedule/workflow_dispatch), same concurrency group, same permissions (contents:read + security-events:write + pull-requests:write), same secrets passthrough.

Same pattern as the rust-ci wrapper sweep (standards#174 + 82 wrapper PRs filed 2026-05-26).

Pin-to-not-yet-merged-SHA

Intentional: the SHA points at standards#191's PR HEAD. The wrapper file is staged but the action runner won't load the reusable until standards#191 lands on main.

Test plan

  • pull_request triggers run main's old workflow file (target-branch semantics)
  • After standards#191 merges, the next push exercises the reusable end-to-end
  • SARIF still uploads on non-fork triggers; gitbot-fleet submission still best-effort

Refs standards#191.

🤖 Generated with Claude Code

…able

Replaces ~416 lines of duplicated Hypatia scan plumbing with a 29-line
wrapper calling hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml
at SHA 2569c10e831e293f9dd6580d82a494aca039deee (standards#191 HEAD).

Behaviour-preserving: same triggers, same concurrency group, same
permissions, same secrets passthrough.

Refs standards#191.
@hyperpolymath
hyperpolymath enabled auto-merge (squash) May 26, 2026 11:28
Standards #191 was closed in favour of #193 (parallel-session implementation
with simpler API: zero inputs except runs-on). Repointing the wrapper at
#193 HEAD 97df762107501909f50bb770e9bc200b6c415600 so it picks up the merged reusable once #193 lands.

Refs standards#193.
@hyperpolymath
hyperpolymath merged commit c764baa into main May 26, 2026
6 of 15 checks passed
@hyperpolymath
hyperpolymath deleted the chore/hypatia-scan-reusable-wrapper branch May 26, 2026 12:41
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 60 issues detected

Severity Count
🔴 Critical 0
🟠 High 36
🟡 Medium 24
View findings
[
  {
    "reason": "No test directory or test files found",
    "type": "no_tests",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd",
    "action": "flag",
    "rule_module": "honest_completion",
    "severity": "high",
    "deduction": 20
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "mirror.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "codeql.yml lists `language: javascript-typescript` but the repo has no source files in any CodeQL-scannable language. The analyze job will exit 'no source files' on every run. Switch the matrix to `actions` (which scans workflow files — every repo has those).",
    "type": "codeql_language_matrix_mismatch",
    "file": "codeql.yml",
    "action": "switch_codeql_matrix_to_actions",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Obj.magic bypassing type safety (2 occurrences, CWE-704)",
    "type": "obj_magic",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd/vext-tools/src/bindings/Std.res",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Obj.magic bypassing type safety (1 occurrences, CWE-704)",
    "type": "obj_magic",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd/vext-tools/src/hooks/Git.res",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "Js.Nullable deprecated -- use Nullable (1 occurrences)",
    "type": "deprecated_api",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd/vext-tools/src/bindings/Deno.res",
    "action": "module_replace",
    "rule_module": "migration_rules",
    "severity": "medium"
  },
  {
    "reason": "Js.Dict deprecated -- use Dict (4 occurrences)",
    "type": "deprecated_api",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd/vext-tools/src/bindings/Std.res",
    "action": "module_replace",
    "rule_module": "migration_rules",
    "severity": "high"
  },
  {
    "reason": "Js.Nullable deprecated -- use Nullable (1 occurrences)",
    "type": "deprecated_api",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd/vext-tools/src/hooks/Git.res",
    "action": "module_replace",
    "rule_module": "migration_rules",
    "severity": "medium"
  },
  {
    "reason": "Nominal-only SAST in vcs-ircd: codeql.yml language matrix contains no language present in the repo and lacks `actions`, so CodeQL records zero results on every commit. Remediation: set the CodeQL matrix to `language: actions`.",
    "type": "StaticAnalysis",
    "file": "/home/runner/work/vcs-ircd/vcs-ircd",
    "action": "auto_fix",
    "rule_module": "scorecard",
    "severity": "medium",
    "remediation": "Add CodeQL or equivalent SAST workflow.",
    "scorecard_check": "SAST"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit that referenced this pull request Sep 18, 2026
Adds `open-pull-requests-limit` to Dependabot update blocks that had no
cap, following the estate per-ecosystem cap doctrine (task #37). No
other line in the file is touched.


Claude-Session: https://claude.ai/code/session_011eQ7hibx92N7fBDtwgReWk

<!--
SPDX-License-Identifier: CC-BY-SA-4.0
Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
-->
## Summary

<!-- What does this PR do, and why? -->

Closes #

## Type of change

- [ ] 🐛 Bug fix (non-breaking change that fixes an issue)
- [ ] ✨ New feature (non-breaking change that adds functionality)
- [ ] 💥 Breaking change (would change existing behaviour)
- [ ] 🕳️ Soundness fix (fixes a checker/proof false-negative)
- [ ] 📖 Documentation
- [ ] 🧹 Refactor / tech debt (behaviour-preserving)
- [ ] ⚡ Performance
- [ ] 🔧 Build / CI / tooling

## How has this been verified?

<!-- Establish ground truth: which tool did you RUN, and what did it
report?
     Don't cite a status doc — cite the command and its output. -->

## Checklist

- [ ] My commits are **signed** (`git commit -S`).
- [ ] I ran the project's own checks/tests locally and they pass.
- [ ] New files carry the correct `SPDX-License-Identifier` (code/config
`MPL-2.0`,
      prose `CC-BY-SA-4.0`); I did not relicense existing files.
- [ ] Docs are updated, and no public claim now overstates what the code
does.
- [ ] I have not introduced a soundness hole (or I have flagged where I
might have).

## Notes for reviewers

<!-- Anything that needs special attention, follow-up, or context. -->

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant