Skip to content

Commit 5755341

Browse files
hyperpolymathclaude
andcommitted
fix(ci): hypatia-scan.yml -- pass GITHUB_TOKEN, use --exit-zero (hyperpolymath/hypatia#213)
The Hypatia Security Scan workflow exits 1 on any findings (>= medium) because lib/hypatia/cli.ex halts with System.halt(1). Under `set -e`, that short-circuits the step before jq/artifact-upload/PR-comment run. Mirrors hyperpolymath/hypatia#228: * pass GITHUB_TOKEN so the Dependabot rule stops warning * append --exit-zero so the downstream critical/high gate stays the explicit gate * bump actions/upload-artifact to v4.6.2 (ea165f8d) to match the estate-wide pin See hyperpolymath/hypatia#213 for the diagnosis. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
1 parent 7c208c6 commit 5755341

1 file changed

Lines changed: 5 additions & 2 deletions

File tree

.github/workflows/hypatia-scan.yml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -50,11 +50,14 @@ jobs:
5050
5151
- name: Run Hypatia scan
5252
id: scan
53+
env:
54+
# Suppress the Dependabot "GITHUB_TOKEN not set" warning.
55+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
5356
run: |
5457
echo "Scanning repository: ${{ github.repository }}"
5558
5659
# Run scanner
57-
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . > hypatia-findings.json
60+
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json
5861
5962
# Count findings
6063
FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0)
@@ -76,7 +79,7 @@ jobs:
7679
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
7780
7881
- name: Upload findings artifact
79-
uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 # v4
82+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
8083
with:
8184
name: hypatia-findings
8285
path: hypatia-findings.json

0 commit comments

Comments
 (0)