Skip to content

security-policy.yml: 3 pre-existing failures surfaced once the workflow starts (deferred from #915) #916

Description

@hyperpolymath

Context

security-policy.yml failed at startup on main (startup_failure, zero jobs) because actions.lock lacked taiki-e/install-action@v2.87.24 (#914). #915 relocks it, so on #915's head (ddc77bc2) the workflow runs for the first time since the desync. Three of its jobs fail.

None of the three is caused by #915. That PR changes only actions.lock and the codeql refs, which point at the same commit. They were present on main all along and invisible, because no job started. None is a required context: hypatia main requires only abi-codegen-drift, zig build test (FFI + wire contract), Escript packaging soundness and scan / gitleaks.

Run: https://github.com/hyperpolymath/hypatia/actions/runs/37831914775

1. Rust Dependency Audit: 2 vulnerable advisories in Cargo.lock

cargo audit scanned 486 crates against 1295 advisories and reports:

It also reports 3 warning classes, including proc-macro-error2 unmaintained (RUSTSEC-2026-0173) and event-listener (RUSTSEC-2026-0221). The job correctly fails on its own findings (#849).

Acceptance criteria

  • cargo update (or a direct bump) moves crossbeam-epoch and h2 to patched versions. If a patched h2 is unreachable through the current dependency tree, record the blocking crate and the advisory is ignored in config with a dated reason, not silently.
  • Rust Dependency Audit passes on the PR head.

2. Rust License & Ban Check: cargo-deny cannot parse its config

error[unexpected-value]: expected '["all", "workspace", "transitive", "none"]'
[ERROR] failed to deserialize config from '/home/runner/work/hypatia/hypatia/deny.toml'

There is no deny.toml in the tree. The job's step "Create deny.toml if missing" writes one from a heredoc containing unmaintained = "warn". Current cargo-deny, installed unpinned through taiki-e/install-action with tool: cargo-deny, takes a scope there, not a lint level. So the job dies parsing its own generated config and checks nothing.

Acceptance criteria

  • The [advisories] keys conform to the cargo-deny schema the job installs, for example unmaintained = "workspace". Preferably commit deny.toml to the repo instead of generating it in the workflow.
  • Pin the cargo-deny version (tool: cargo-deny@<x.y.z>), so a schema change arrives as a reviewed bump and not a silent red.
  • Rust License & Ban Check passes, and its report shows advisories, bans, licenses and sources were actually evaluated.

3. Security Status: the orphan-job self-check has no checkout

awk: fatal: cannot open file `.github/workflows/security-policy.yml' for reading: No such file or directory
##[error]Process completed with exit code 2.

The security-status aggregator (from #850 AC4) parses its own workflow file to assert that every job is in its needs: list. The job has no actions/checkout step, so the file is absent and the self-check crashes before it checks anything. Its exit code is 2, not the script's own exit 1. This is a broken guard, not a finding.

Acceptance criteria

  • security-status checks out at least .github/workflows/security-policy.yml, for example a sparse actions/checkout already locked for this workflow.
  • A missing workflow file fails with an explicit ::error::, not an awk crash.
  • Planted control: adding a job outside needs: makes the self-check fail with the orphan message. Removing it makes the self-check pass.
  • Security Status passes once 1 and 2 are fixed.

Notes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions