1010 schedule :
1111 - cron : ' 0 0 * * 0' # Weekly on Sunday
1212 workflow_dispatch :
13-
14- permissions : read-all
13+ # Estate guardrail: cancel superseded runs so re-pushes don't pile up
14+ # queued runs across the estate. Safe here because this workflow only
15+ # performs read-only checks/lint/test/scan with no publish or mutation.
16+ concurrency :
17+ group : ${{ github.workflow }}-${{ github.ref }}
18+ cancel-in-progress : true
19+
20+ permissions :
21+ contents : read
22+ # security-events: read lets the built-in GITHUB_TOKEN query this
23+ # repo's own Dependabot alerts via the Hypatia DependabotAlerts rule
24+ # (DA001-DA004). Without this, `scan_from_path` gets HTTP 403 and
25+ # the rule silently returns no findings.
26+ # See 007-lang/audits/audit-dependabot-automation-gap-2026-04-17.md.
27+ security-events : read
28+ # pull-requests: write lets the advisory "Comment on PR with findings"
29+ # step post its summary. Without it the built-in GITHUB_TOKEN gets
30+ # "Resource not accessible by integration" and (absent continue-on-error)
31+ # hard-fails the scan — exactly what the gate-decoupling design forbids.
32+ pull-requests : write
1533
1634jobs :
1735 scan :
2038
2139 steps :
2240 - name : Checkout repository
23- uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4
41+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
2442 with :
2543 fetch-depth : 0 # Full history for better pattern analysis
2644
@@ -37,23 +55,27 @@ jobs:
3755 fi
3856
3957 - name : Build Hypatia scanner (if needed)
40- working-directory : ${{ env.HOME }}/hypatia
4158 run : |
42- if [ ! -f hypatia-v2 ]; then
43- echo "Building hypatia-v2 scanner..."
44- cd scanner
59+ cd "$HOME/ hypatia"
60+ if [ ! -f hypatia ]; then
61+ echo "Building hypatia scanner..."
4562 mix deps.get
4663 mix escript.build
47- mv hypatia ../hypatia-v2
4864 fi
4965
5066 - name : Run Hypatia scan
5167 id : scan
68+ env :
69+ # Pass the built-in Actions token through to Hypatia so the
70+ # DependabotAlerts rule can query this repo's own alerts.
71+ # For cross-repo scanning (fleet-coordinator scan-supervised),
72+ # a PAT with `security_events` scope is required instead.
73+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
5274 run : |
5375 echo "Scanning repository: ${{ github.repository }}"
5476
55- # Run scanner
56- HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . > hypatia-findings.json
77+ # Run scanner (exits non-zero when findings exist — suppress to continue)
78+ HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia-findings.json || true
5779
5880 # Count findings
5981 FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0)
7597 echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
7698
7799 - name : Upload findings artifact
78- uses : actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
100+ uses : actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
79101 with :
80102 name : hypatia-findings
81103 path : hypatia-findings.json
@@ -194,7 +216,12 @@ jobs:
194216
195217 - name : Comment on PR with findings
196218 if : github.event_name == 'pull_request' && steps.scan.outputs.findings_count > 0
197- uses : actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v7
219+ # Advisory only — posting findings as a PR comment must never gate
220+ # the scan (hypatia#213 gate decoupling). Belt-and-braces alongside
221+ # the pull-requests: write permission above: a token/API hiccup or
222+ # a fork PR (read-only token) skips the comment, not the check.
223+ continue-on-error : true
224+ uses : actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7
198225 with :
199226 script : |
200227 const fs = require('fs');
0 commit comments