Skip to content

ci(hypatia-scan): repin reusable to merge-commit SHA (orphan-SHA fix) #41

ci(hypatia-scan): repin reusable to merge-commit SHA (orphan-SHA fix)

ci(hypatia-scan): repin reusable to merge-commit SHA (orphan-SHA fix) #41

Triggered via pull request May 26, 2026 23:05
Status Success
Total duration 8h 8m 16s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
6s
panic-attack assail
Hypatia neurosymbolic scan
31s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
7s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
6s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

4 warnings and 2 notices
panic-attack assail
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Patch Bridge CVE triage
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Deposit findings for gitbot-fleet
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
panic-attack assail
panic-attack binary not available — skipping assail
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:c5a9bd8756ac259a1a6834d2be6fc6215a8b55ed53021be19c9ef240cd532a83
hypatia-findings
161 Bytes
sha256:715074276cbb424c7846187fc8f27197aee444d169598f657c7d00eaf28c03c9
panic-attack-findings
171 Bytes
sha256:c7e71912bb00ff097e0f78723b8424266092cb76d31e12504d1bfcefbbe51012
unified-findings
420 Bytes
sha256:441dd981cda28a03ada4137f4d6e219202e5a0abdb052aa0190c22e49138b8ef