Skip to content

Commit 4fc7da6

Browse files
committed
fix(ci): adopt canonical hypatia-scan.yml (env.HOME/scanner-layout + Comment-step gate)
1 parent 3bf543f commit 4fc7da6

1 file changed

Lines changed: 29 additions & 4 deletions

File tree

.github/workflows/hypatia-scan.yml

Lines changed: 29 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -10,12 +10,26 @@ on:
1010
schedule:
1111
- cron: '0 0 * * 0' # Weekly on Sunday
1212
workflow_dispatch:
13+
# Estate guardrail: cancel superseded runs so re-pushes don't pile up
14+
# queued runs across the estate. Safe here because this workflow only
15+
# performs read-only checks/lint/test/scan with no publish or mutation.
16+
concurrency:
17+
group: ${{ github.workflow }}-${{ github.ref }}
18+
cancel-in-progress: true
1319

1420
permissions:
1521
contents: read
1622
# security-events: read lets the built-in GITHUB_TOKEN query this
17-
# repo\'s own Dependabot alerts via the Hypatia DependabotAlerts rule.
23+
# repo's own Dependabot alerts via the Hypatia DependabotAlerts rule
24+
# (DA001-DA004). Without this, `scan_from_path` gets HTTP 403 and
25+
# the rule silently returns no findings.
26+
# See 007-lang/audits/audit-dependabot-automation-gap-2026-04-17.md.
1827
security-events: read
28+
# pull-requests: write lets the advisory "Comment on PR with findings"
29+
# step post its summary. Without it the built-in GITHUB_TOKEN gets
30+
# "Resource not accessible by integration" and (absent continue-on-error)
31+
# hard-fails the scan — exactly what the gate-decoupling design forbids.
32+
pull-requests: write
1933

2034
jobs:
2135
scan:
@@ -29,7 +43,7 @@ jobs:
2943
fetch-depth: 0 # Full history for better pattern analysis
3044

3145
- name: Setup Elixir for Hypatia scanner
32-
uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.18.2
46+
uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.18.2
3347
with:
3448
elixir-version: '1.19.4'
3549
otp-version: '28.3'
@@ -51,11 +65,17 @@ jobs:
5165
5266
- name: Run Hypatia scan
5367
id: scan
68+
env:
69+
# Pass the built-in Actions token through to Hypatia so the
70+
# DependabotAlerts rule can query this repo's own alerts.
71+
# For cross-repo scanning (fleet-coordinator scan-supervised),
72+
# a PAT with `security_events` scope is required instead.
73+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
5474
run: |
5575
echo "Scanning repository: ${{ github.repository }}"
5676
5777
# Run scanner (exits non-zero when findings exist — suppress to continue)
58-
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . > hypatia-findings.json || true
78+
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json || true
5979
6080
# Count findings
6181
FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0)
@@ -77,7 +97,7 @@ jobs:
7797
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
7898
7999
- name: Upload findings artifact
80-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
100+
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
81101
with:
82102
name: hypatia-findings
83103
path: hypatia-findings.json
@@ -196,6 +216,11 @@ jobs:
196216
197217
- name: Comment on PR with findings
198218
if: github.event_name == 'pull_request' && steps.scan.outputs.findings_count > 0
219+
# Advisory only — posting findings as a PR comment must never gate
220+
# the scan (hypatia#213 gate decoupling). Belt-and-braces alongside
221+
# the pull-requests: write permission above: a token/API hiccup or
222+
# a fork PR (read-only token) skips the comment, not the check.
223+
continue-on-error: true
199224
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7
200225
with:
201226
script: |

0 commit comments

Comments
 (0)