Skip to content

ci(security): SHA-pin standards/governance-reusable.yml from @main#103

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/sha-pin-standards-governance-reusable-2026-06-01
Jun 1, 2026
Merged

ci(security): SHA-pin standards/governance-reusable.yml from @main#103
hyperpolymath merged 1 commit into
mainfrom
ci/sha-pin-standards-governance-reusable-2026-06-01

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Replaces 2 floating @main refs with 1376eb62 (standards main 2026-06-01) per estate SHA-pin discipline. Salvaged from M1 foreign-WIP triage.

Two governance.yml files invoke a reusable workflow via the floating
@main ref. SHA-pin to 1376eb6251fa9beeaea75241739b1d00dd6b4028
(standards main as of 2026-06-01) to prevent supply-chain drift.

Per estate [SHA-pin discipline] convention; the comment includes the
upstream branch name + date for human-readable bump reference.

Salvaged from the M1 foreign-WIP triage (where the same fix was
queued against an older SHA 861b5e911...).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath merged commit abd5767 into main Jun 1, 2026
1 check passed
@hyperpolymath hyperpolymath deleted the ci/sha-pin-standards-governance-reusable-2026-06-01 branch June 1, 2026 20:58
@github-actions
Copy link
Copy Markdown

github-actions Bot commented Jun 1, 2026

🔍 Hypatia Security Scan

Findings: 133 issues detected

Severity Count
🔴 Critical 10
🟠 High 24
🟡 Medium 99

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "lean-verification.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "rust-cli.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in cflite_batch.yml",
    "type": "missing_timeout_minutes",
    "file": "cflite_batch.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in cflite_pr.yml",
    "type": "missing_timeout_minutes",
    "file": "cflite_pr.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in compilation_tests.yml",
    "type": "missing_timeout_minutes",
    "file": "compilation_tests.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in compilation_tests.yml",
    "type": "missing_timeout_minutes",
    "file": "compilation_tests.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant