Skip to content

fix(ci): group Dependabot updates into one PR per ecosystem #235

fix(ci): group Dependabot updates into one PR per ecosystem

fix(ci): group Dependabot updates into one PR per ecosystem #235

Triggered via pull request July 21, 2026 17:03
Status Failure
Total duration 8m 22s
Artifacts

governance.yml

on: pull_request
governance  /  Check Workflow Staleness
9s
governance / Check Workflow Staleness
governance  /  ...  /  package anti-pattern policy
40s
governance / Language / package anti-pattern policy
governance  /  ...  /  Nix fallback policy
10s
governance / Guix primary / Nix fallback policy
governance  /  Security policy checks
9s
governance / Security policy checks
governance  /  Code quality + docs
19s
governance / Code quality + docs
governance  /  Well-Known (RFC 9116 + RSR)
9s
governance / Well-Known (RFC 9116 + RSR)
governance  /  Workflow security linter
9s
governance / Workflow security linter
governance  /  Trusted-base reduction policy
12s
governance / Trusted-base reduction policy
governance  /  Licence consistency
8s
governance / Licence consistency
governance  /  Validate Hypatia Baseline
governance / Validate Hypatia Baseline
Fit to window
Zoom out
Zoom in

Annotations

5 errors and 2 notices
governance / Check Workflow Staleness
Process completed with exit code 1.
governance / Check Workflow Staleness
Staleness gate failed. Each error above names a specific defect: a pin predating a known false-green fix (refresh it — waiting will not help), a pin that is not a published standards commit, a retired scorecard-enforcer.yml, or Scorecard uploading SARIF to Code Scanning. Pins that are merely old are reported as notices and do not fail.
governance / Check Workflow Staleness: ./.github/workflows/scorecard.yml#L0
OSSF Scorecard must not upload SARIF to GitHub Code Scanning unless it runs for every PR head commit.
governance / Check Workflow Staleness: ./.github/workflows/hypatia-scan.yml#L0
hypatia-scan-reusable.yml pin d7c22711e830 predates e9c8888769a7 and carries the frozen-Hypatia-scanner-cache defect (#441): the first scanner build ever cached is restored forever, so scanner fixes never take effect and the scan reports a FALSE GREEN. Refresh this pin — waiting will not fix it (scripts/propagate-workflow-pins.sh).
governance / Workflow security linter
Process completed with exit code 1.
governance / Check Workflow Staleness: ./.github/workflows/governance.yml#L0
governance-reusable.yml pin 412a70315771 is 44 commit(s) / 18d behind standards HEAD — within the recency window (<=50 commits or <=14d). Bump deliberately with scripts/propagate-workflow-pins.sh when convenient.
governance / Language / package anti-pattern policy
affinescript compiler unavailable on runner — skipping drift check