Skip to content

Commit a219ef5

Browse files
fix(a2ml/actions/validate): use reusable workflows from root instead of duplicates
- codeql.yml: Replace inline implementation with call to ../../../codeql-reusable.yml - governance.yml: Use relative path ../../../governance-reusable.yml instead of external SHA pin - hypatia-scan.yml: Replace custom implementation with call to ../../../hypatia-scan-reusable.yml - instant-sync.yml: Upgrade to match root version with concurrency and proper secrets handling - mirror.yml: Replace inline multi-forge implementation with call to ../../../mirror-reusable.yml - scorecard.yml: Replace inline implementation with call to ../../../scorecard-reusable.yml - scorecard-enforcer.yml: Replace custom implementation with call to ../../../scorecard-reusable.yml - secret-scanner.yml: Replace inline implementation with call to ../../../secret-scanner-reusable.yml Nested directory (a2ml/actions/validate) now uses root reusable workflows. Generated by Mistral Vibe. Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
1 parent 7ec0928 commit a219ef5

8 files changed

Lines changed: 63 additions & 469 deletions

File tree

a2ml/actions/validate/.github/workflows/codeql.yml

Lines changed: 9 additions & 28 deletions
Original file line numberDiff line numberDiff line change
@@ -9,34 +9,15 @@ on:
99
schedule:
1010
- cron: '0 6 * * 1'
1111

12+
concurrency:
13+
group: ${{ github.workflow }}-${{ github.ref }}
14+
cancel-in-progress: false
1215

13-
permissions: read-all
16+
permissions:
17+
contents: read
1418

1519
jobs:
16-
analyze:
17-
runs-on: ubuntu-latest
18-
timeout-minutes: 30
19-
permissions:
20-
contents: read
21-
security-events: write
22-
strategy:
23-
fail-fast: false
24-
matrix:
25-
include:
26-
- language: javascript-typescript
27-
build-mode: none
28-
29-
steps:
30-
- name: Checkout
31-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
32-
33-
- name: Initialize CodeQL
34-
uses: github/codeql-action/init@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1
35-
with:
36-
languages: ${{ matrix.language }}
37-
build-mode: ${{ matrix.build-mode }}
38-
39-
- name: Perform CodeQL Analysis
40-
uses: github/codeql-action/analyze@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1
41-
with:
42-
category: "/language:${{ matrix.language }}"
20+
analyze-js:
21+
uses: ../../../.github/workflows/codeql-reusable.yml
22+
with:
23+
language: javascript-typescript

a2ml/actions/validate/.github/workflows/governance.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,4 +23,4 @@ permissions:
2323

2424
jobs:
2525
governance:
26-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613
26+
uses: ../../../.github/workflows/governance-reusable.yml
Lines changed: 9 additions & 167 deletions
Original file line numberDiff line numberDiff line change
@@ -1,179 +1,21 @@
11
# SPDX-License-Identifier: MPL-2.0
2-
# Hypatia Neurosymbolic CI/CD Security Scan
32
name: Hypatia Security Scan
43

54
on:
65
push:
7-
branches: [ main, master, develop ]
6+
branches: [main, master, develop]
87
pull_request:
9-
branches: [ main, master ]
8+
branches: [main, master]
109
schedule:
11-
- cron: '0 0 * * 0' # Weekly on Sunday
10+
- cron: '0 0 * * 0'
1211
workflow_dispatch:
1312

14-
permissions: read-all
13+
permissions:
14+
actions: read
15+
contents: read
16+
security-events: write
1517

1618
jobs:
1719
scan:
18-
name: Hypatia Neurosymbolic Analysis
19-
runs-on: ubuntu-latest
20-
timeout-minutes: 20
21-
22-
steps:
23-
- name: Checkout repository
24-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
25-
with:
26-
fetch-depth: 0 # Full history for better pattern analysis
27-
28-
- name: Setup Elixir for Hypatia scanner
29-
uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.18.2
30-
with:
31-
elixir-version: '1.18'
32-
otp-version: '27'
33-
34-
- name: Clone Hypatia
35-
run: |
36-
if [ ! -d "$HOME/hypatia" ]; then
37-
git clone https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia"
38-
fi
39-
40-
- name: Build Hypatia scanner (if needed)
41-
working-directory: ${{ env.HOME }}/hypatia
42-
run: |
43-
if [ ! -f hypatia-v2 ]; then
44-
echo "Building hypatia-v2 scanner..."
45-
mix deps.get
46-
mix escript.build
47-
mv hypatia ../hypatia-v2
48-
fi
49-
50-
- name: Run Hypatia scan
51-
id: scan
52-
run: |
53-
echo "Scanning repository: ${{ github.repository }}"
54-
55-
# Run scanner
56-
HYPATIA_FORMAT=json "$HOME/hypatia/hypatia-cli.sh" scan . > hypatia-findings.json
57-
58-
# Count findings
59-
FINDING_COUNT=$(jq '. | length' hypatia-findings.json 2>/dev/null || echo 0)
60-
echo "findings_count=$FINDING_COUNT" >> $GITHUB_OUTPUT
61-
62-
# Extract severity counts
63-
CRITICAL=$(jq '[.[] | select(.severity == "critical")] | length' hypatia-findings.json)
64-
HIGH=$(jq '[.[] | select(.severity == "high")] | length' hypatia-findings.json)
65-
MEDIUM=$(jq '[.[] | select(.severity == "medium")] | length' hypatia-findings.json)
66-
67-
echo "critical=$CRITICAL" >> $GITHUB_OUTPUT
68-
echo "high=$HIGH" >> $GITHUB_OUTPUT
69-
echo "medium=$MEDIUM" >> $GITHUB_OUTPUT
70-
71-
echo "## Hypatia Scan Results" >> $GITHUB_STEP_SUMMARY
72-
echo "- Total findings: $FINDING_COUNT" >> $GITHUB_STEP_SUMMARY
73-
echo "- Critical: $CRITICAL" >> $GITHUB_STEP_SUMMARY
74-
echo "- High: $HIGH" >> $GITHUB_STEP_SUMMARY
75-
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
76-
77-
- name: Upload findings artifact
78-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4
79-
with:
80-
name: hypatia-findings
81-
path: hypatia-findings.json
82-
retention-days: 90
83-
84-
- name: Submit findings to gitbot-fleet (Phase 2)
85-
if: steps.scan.outputs.findings_count > 0
86-
env:
87-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
88-
GITHUB_REPOSITORY: ${{ github.repository }}
89-
GITHUB_SHA: ${{ github.sha }}
90-
run: |
91-
echo "📤 Submitting ${{ steps.scan.outputs.findings_count }} findings to gitbot-fleet..."
92-
93-
# Clone gitbot-fleet to temp directory
94-
FLEET_DIR="/tmp/gitbot-fleet-$$"
95-
git clone https://github.com/hyperpolymath/gitbot-fleet.git "$FLEET_DIR"
96-
97-
# Run submission script
98-
bash "$FLEET_DIR/scripts/submit-finding.sh" hypatia-findings.json
99-
100-
# Cleanup
101-
rm -rf "$FLEET_DIR"
102-
103-
echo "✅ Finding submission complete"
104-
105-
- name: Check for critical issues
106-
if: steps.scan.outputs.critical > 0
107-
run: |
108-
echo "⚠️ Critical security issues found!"
109-
echo "Review hypatia-findings.json for details"
110-
# Don't fail the build yet - just warn
111-
# exit 1
112-
113-
- name: Generate scan report
114-
run: |
115-
cat << EOF > hypatia-report.md
116-
# Hypatia Security Scan Report
117-
118-
**Repository:** ${{ github.repository }}
119-
**Scan Date:** $(date -u +"%Y-%m-%d %H:%M:%S UTC")
120-
**Commit:** ${{ github.sha }}
121-
122-
## Summary
123-
124-
| Severity | Count |
125-
|----------|-------|
126-
| Critical | ${{ steps.scan.outputs.critical }} |
127-
| High | ${{ steps.scan.outputs.high }} |
128-
| Medium | ${{ steps.scan.outputs.medium }} |
129-
| **Total**| ${{ steps.scan.outputs.findings_count }} |
130-
131-
## Next Steps
132-
133-
1. Review findings in the artifact: hypatia-findings.json
134-
2. Auto-fixable issues will be addressed by robot-repo-automaton (Phase 3)
135-
3. Manual review required for complex issues
136-
137-
## Learning
138-
139-
These findings feed Hypatia's learning engine to improve future rules.
140-
141-
---
142-
*Powered by [Hypatia](https://github.com/hyperpolymath/hypatia) - Neurosymbolic CI/CD Intelligence*
143-
EOF
144-
145-
cat hypatia-report.md >> $GITHUB_STEP_SUMMARY
146-
147-
- name: Comment on PR with findings
148-
if: github.event_name == 'pull_request' && steps.scan.outputs.findings_count > 0
149-
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7
150-
with:
151-
script: |
152-
const fs = require('fs');
153-
const findings = JSON.parse(fs.readFileSync('hypatia-findings.json', 'utf8'));
154-
155-
const critical = findings.filter(f => f.severity === 'critical').length;
156-
const high = findings.filter(f => f.severity === 'high').length;
157-
158-
let comment = `## 🔍 Hypatia Security Scan\n\n`;
159-
comment += `**Findings:** ${findings.length} issues detected\n\n`;
160-
comment += `| Severity | Count |\n|----------|-------|\n`;
161-
comment += `| 🔴 Critical | ${critical} |\n`;
162-
comment += `| 🟠 High | ${high} |\n`;
163-
comment += `| 🟡 Medium | ${findings.length - critical - high} |\n\n`;
164-
165-
if (critical > 0) {
166-
comment += `⚠️ **Action Required:** Critical security issues found!\n\n`;
167-
}
168-
169-
comment += `<details><summary>View findings</summary>\n\n`;
170-
comment += `\`\`\`json\n${JSON.stringify(findings.slice(0, 10), null, 2)}\n\`\`\`\n`;
171-
comment += `</details>\n\n`;
172-
comment += `*Powered by Hypatia Neurosymbolic CI/CD Intelligence*`;
173-
174-
github.rest.issues.createComment({
175-
owner: context.repo.owner,
176-
repo: context.repo.repo,
177-
issue_number: context.issue.number,
178-
body: comment
179-
});
20+
uses: ../../../.github/workflows/hypatia-scan-reusable.yml
21+
secrets: inherit

a2ml/actions/validate/.github/workflows/instant-sync.yml

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,15 +8,23 @@ on:
88
release:
99
types: [published]
1010

11+
concurrency:
12+
group: ${{ github.workflow }}-${{ github.ref }}
13+
cancel-in-progress: true
14+
1115
permissions:
16+
actions: read
1217
contents: read
1318

1419
jobs:
1520
dispatch:
21+
timeout-minutes: 10
1622
runs-on: ubuntu-latest
17-
timeout-minutes: 20
23+
env:
24+
FARM_DISPATCH_TOKEN: ${{ secrets.FARM_DISPATCH_TOKEN }}
1825
steps:
1926
- name: Trigger Propagation
27+
if: ${{ env.FARM_DISPATCH_TOKEN != '' }}
2028
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3
2129
with:
2230
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
@@ -30,5 +38,14 @@ jobs:
3038
"forges": ""
3139
}
3240
41+
- name: Skipped (FARM_DISPATCH_TOKEN not configured)
42+
if: ${{ env.FARM_DISPATCH_TOKEN == '' }}
43+
env:
44+
REPO_NAME: ${{ github.event.repository.name }}
45+
run: |
46+
echo "::notice::FARM_DISPATCH_TOKEN secret not configured on ${REPO_NAME}; skipping cross-repo dispatch."
47+
3348
- name: Confirm
34-
run: echo "::notice::Propagation triggered for ${{ github.event.repository.name }}"
49+
env:
50+
REPO_NAME: ${{ github.event.repository.name }}
51+
run: echo "::notice::Propagation triggered for ${REPO_NAME}"

0 commit comments

Comments
 (0)