Skip to content

fix(ci): Phase-2 fleet submission must not fail the security gate (#5) #17

fix(ci): Phase-2 fleet submission must not fail the security gate (#5)

fix(ci): Phase-2 fleet submission must not fail the security gate (#5) #17

Triggered via push May 16, 2026 13:01
Status Success
Total duration 1h 20m 1s
Artifacts 4
panic-attack assail
5s
panic-attack assail
Hypatia neurosymbolic scan
32s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
6s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
5s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

4 warnings and 2 notices
panic-attack assail
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02, erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Patch Bridge CVE triage
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Deposit findings for gitbot-fleet
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16, actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
panic-attack assail
panic-attack binary not available — skipping assail
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:51fc03850a2a399548117fb0ecb7207040b9461edb11bf1983df3927038cd877
hypatia-findings
161 Bytes
sha256:aba5c1ba5e545e03a0db54800eaddcd1502efbfa2fcb655a05c3e645f3fe992d
panic-attack-findings
171 Bytes
sha256:a566d7bf3cfe299446e16e055034cf89fc1599de045176a02583188b08417239
unified-findings
401 Bytes
sha256:9bb60f1a2715bb712ada78c19c4d09f9f008dd16e730e5eccd9971d6fe9d9190