Skip to content

chore(ci): bump hypatia-scan-reusable pin off orphan SHA to canonical main#77

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/bump-hypatia-scan-pin-canonical
May 27, 2026
Merged

chore(ci): bump hypatia-scan-reusable pin off orphan SHA to canonical main#77
hyperpolymath merged 1 commit into
mainfrom
claude/bump-hypatia-scan-pin-canonical

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Pure hygiene: hypatia-scan.yml pinned to an orphan PR-branch SHA 97df762 (the pre-squash form of standards#193). File content is identical to canonical squash-merged SHA 915139d and to current standards/main 5eb28d7 (no commits to hypatia-scan-reusable.yml between them).

Bumped to standards/main HEAD per cross-check guidance in standards#220.

Auto-merge SQUASH.

🤖 Generated with Claude Code

… main

hypatia-scan.yml@97df762 is an orphan PR-branch SHA from
before standards#193 squash-merged as 915139d. The reusable file's
content is identical (no commits to hypatia-scan-reusable.yml since
#193), but cross-checks (cf. standards#220) prefer reachability via
standards/main. Pure hygiene; no behavioural change.

Bumped to standards/main HEAD 5eb28d7.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath enabled auto-merge (squash) May 27, 2026 10:33
@sonarqubecloud
Copy link
Copy Markdown

@github-actions
Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 246 issues detected

Severity Count
🔴 Critical 32
🟠 High 120
🟡 Medium 94

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "e2e.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "e2e.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/container-stack/vordr/src/mcp-adapter/src/ipv6_bridge.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/container-stack/vordr/src/mcp-adapter/http-server.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/tests/unit/container_types_test.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/tests/aspect/security_test.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/tests/e2e/container_lifecycle_test.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/tests/property/layer_invariants_test.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/stapeln/stapeln/tests/property/nickel_config_properties_test.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath hyperpolymath merged commit 468cba4 into main May 27, 2026
23 of 25 checks passed
@hyperpolymath hyperpolymath deleted the claude/bump-hypatia-scan-pin-canonical branch May 27, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant