Skip to content

chore(deps): bump actions/download-artifact from 6.0.0 to 8.0.1 #155

chore(deps): bump actions/download-artifact from 6.0.0 to 8.0.1

chore(deps): bump actions/download-artifact from 6.0.0 to 8.0.1 #155

Triggered via pull request June 25, 2026 05:26
Status Failure
Total duration 11h 54m 57s
Artifacts

governance.yml

on: pull_request
governance  /  Check Workflow Staleness
13s
governance / Check Workflow Staleness
governance  /  ...  /  package anti-pattern policy
29s
governance / Language / package anti-pattern policy
governance  /  ...  /  Nix fallback policy
31s
governance / Guix primary / Nix fallback policy
governance  /  Security policy checks
36s
governance / Security policy checks
governance  /  Code quality + docs
45s
governance / Code quality + docs
governance  /  Well-Known (RFC 9116 + RSR)
25s
governance / Well-Known (RFC 9116 + RSR)
governance  /  Workflow security linter
29s
governance / Workflow security linter
governance  /  Trusted-base reduction policy
38s
governance / Trusted-base reduction policy
governance  /  Licence consistency
45s
governance / Licence consistency
governance  /  Validate Hypatia Baseline
governance / Validate Hypatia Baseline
Fit to window
Zoom out
Zoom in

Annotations

37 errors and 2 notices
governance / Check Workflow Staleness
Process completed with exit code 1.
governance / Check Workflow Staleness
Remove legacy scorecard-enforcer.yml, refresh out-of-window standards reusable pins toward a recent commit, and keep Scorecard out of GitHub Code Scanning unless it runs for every PR head commit.
governance / Check Workflow Staleness: ./.github/workflows/scorecard.yml#L0
OSSF Scorecard must not upload SARIF to GitHub Code Scanning unless it runs for every PR head commit.
governance / Check Workflow Staleness: ./.github/workflows/scorecard-enforcer.yml#L0
OSSF Scorecard must not upload SARIF to GitHub Code Scanning unless it runs for every PR head commit.
governance / Check Workflow Staleness
scorecard-enforcer.yml is retired. Use scorecard.yml -> standards scorecard-reusable.yml instead.
governance / Language / package anti-pattern policy
The process '/usr/bin/git' failed with exit code 128
governance / Language / package anti-pattern policy
couldn't find remote ref refs/pull/136/merge
governance / Language / package anti-pattern policy
couldn't find remote ref refs/pull/136/merge
governance / Language / package anti-pattern policy
couldn't find remote ref refs/pull/136/merge
governance / Workflow security linter
The process '/usr/bin/git' failed with exit code 128
governance / Workflow security linter
couldn't find remote ref refs/pull/136/merge
governance / Workflow security linter
couldn't find remote ref refs/pull/136/merge
governance / Workflow security linter
couldn't find remote ref refs/pull/136/merge
governance / Guix primary / Nix fallback policy
The process '/usr/bin/git' failed with exit code 128
governance / Guix primary / Nix fallback policy
couldn't find remote ref refs/pull/136/merge
governance / Guix primary / Nix fallback policy
couldn't find remote ref refs/pull/136/merge
governance / Guix primary / Nix fallback policy
couldn't find remote ref refs/pull/136/merge
governance / Code quality + docs
The process '/usr/bin/git' failed with exit code 128
governance / Code quality + docs
couldn't find remote ref refs/pull/136/merge
governance / Code quality + docs
couldn't find remote ref refs/pull/136/merge
governance / Code quality + docs
couldn't find remote ref refs/pull/136/merge
governance / Security policy checks
The process '/usr/bin/git' failed with exit code 128
governance / Security policy checks
couldn't find remote ref refs/pull/136/merge
governance / Security policy checks
couldn't find remote ref refs/pull/136/merge
governance / Security policy checks
couldn't find remote ref refs/pull/136/merge
governance / Trusted-base reduction policy
The process '/usr/bin/git' failed with exit code 128
governance / Trusted-base reduction policy
couldn't find remote ref refs/pull/136/merge
governance / Trusted-base reduction policy
couldn't find remote ref refs/pull/136/merge
governance / Trusted-base reduction policy
couldn't find remote ref refs/pull/136/merge
governance / Well-Known (RFC 9116 + RSR)
The process '/usr/bin/git' failed with exit code 128
governance / Well-Known (RFC 9116 + RSR)
couldn't find remote ref refs/pull/136/merge
governance / Well-Known (RFC 9116 + RSR)
couldn't find remote ref refs/pull/136/merge
governance / Well-Known (RFC 9116 + RSR)
couldn't find remote ref refs/pull/136/merge
governance / Licence consistency
The process '/usr/bin/git' failed with exit code 128
governance / Licence consistency
couldn't find remote ref refs/pull/136/merge
governance / Licence consistency
couldn't find remote ref refs/pull/136/merge
governance / Licence consistency
couldn't find remote ref refs/pull/136/merge
governance / Check Workflow Staleness: ./.github/workflows/hypatia-scan.yml#L0
hypatia-scan-reusable.yml pin d135b05bfc64 is 10 commit(s) / 1d behind standards HEAD — within the recency window (<=50 commits or <=14d). Bump deliberately with scripts/propagate-workflow-pins.sh when convenient.
governance / Check Workflow Staleness: ./.github/workflows/governance.yml#L0
governance-reusable.yml pin d135b05bfc64 is 10 commit(s) / 1d behind standards HEAD — within the recency window (<=50 commits or <=14d). Bump deliberately with scripts/propagate-workflow-pins.sh when convenient.