Skip to content

chore(ci): bump hypatia-scan-reusable pin off orphan SHA to canonical main#403

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/bump-hypatia-scan-pin-canonical
May 27, 2026
Merged

chore(ci): bump hypatia-scan-reusable pin off orphan SHA to canonical main#403
hyperpolymath merged 1 commit into
mainfrom
claude/bump-hypatia-scan-pin-canonical

Conversation

@hyperpolymath
Copy link
Copy Markdown
Owner

Pure hygiene: hypatia-scan.yml pinned to an orphan PR-branch SHA 97df762 (the pre-squash form of standards#193). File content is identical to canonical squash-merged SHA 915139d and to current standards/main 5eb28d7 (no commits to hypatia-scan-reusable.yml between them).

Bumped to standards/main HEAD per cross-check guidance in standards#220.

Auto-merge SQUASH.

🤖 Generated with Claude Code

… main

hypatia-scan.yml@97df762 is an orphan PR-branch SHA from
before standards#193 squash-merged as 915139d. The reusable file's
content is identical (no commits to hypatia-scan-reusable.yml since
#193), but cross-checks (cf. standards#220) prefer reachability via
standards/main. Pure hygiene; no behavioural change.

Bumped to standards/main HEAD 5eb28d7.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath hyperpolymath enabled auto-merge (squash) May 27, 2026 10:32
@github-actions
Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 37 issues detected

Severity Count
🔴 Critical 12
🟠 High 13
🟡 Medium 12

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Action actions/checkout@v6 needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action denoland/setup-deno@v2 needs attention",
    "type": "unpinned_action",
    "file": "publish-jsr.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/example/smoke_driver.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/cli.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/lib/compile.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/lib/runner.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/affinescript-deno-test/lib/discover.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/affinescript/affinescript/packages/affine-js/types.d.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath hyperpolymath merged commit 66343f3 into main May 27, 2026
24 checks passed
@hyperpolymath hyperpolymath deleted the claude/bump-hypatia-scan-pin-canonical branch May 27, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant