Context
security-policy.yml failed at startup on main (startup_failure, zero jobs) because actions.lock lacked taiki-e/install-action@v2.87.24 (#914). #915 relocks it, so on #915's head (ddc77bc2) the workflow runs for the first time since the desync. Three of its jobs fail.
None of the three is caused by #915. That PR changes only actions.lock and the codeql refs, which point at the same commit. They were present on main all along and invisible, because no job started. None is a required context: hypatia main requires only abi-codegen-drift, zig build test (FFI + wire contract), Escript packaging soundness and scan / gitleaks.
Run: https://github.com/hyperpolymath/hypatia/actions/runs/37831914775
1. Rust Dependency Audit: 2 vulnerable advisories in Cargo.lock
cargo audit scanned 486 crates against 1295 advisories and reports:
It also reports 3 warning classes, including proc-macro-error2 unmaintained (RUSTSEC-2026-0173) and event-listener (RUSTSEC-2026-0221). The job correctly fails on its own findings (#849).
Acceptance criteria
2. Rust License & Ban Check: cargo-deny cannot parse its config
error[unexpected-value]: expected '["all", "workspace", "transitive", "none"]'
[ERROR] failed to deserialize config from '/home/runner/work/hypatia/hypatia/deny.toml'
There is no deny.toml in the tree. The job's step "Create deny.toml if missing" writes one from a heredoc containing unmaintained = "warn". Current cargo-deny, installed unpinned through taiki-e/install-action with tool: cargo-deny, takes a scope there, not a lint level. So the job dies parsing its own generated config and checks nothing.
Acceptance criteria
3. Security Status: the orphan-job self-check has no checkout
awk: fatal: cannot open file `.github/workflows/security-policy.yml' for reading: No such file or directory
##[error]Process completed with exit code 2.
The security-status aggregator (from #850 AC4) parses its own workflow file to assert that every job is in its needs: list. The job has no actions/checkout step, so the file is absent and the self-check crashes before it checks anything. Its exit code is 2, not the script's own exit 1. This is a broken guard, not a finding.
Acceptance criteria
Notes
Context
security-policy.ymlfailed at startup onmain(startup_failure, zero jobs) becauseactions.locklackedtaiki-e/install-action@v2.87.24(#914). #915 relocks it, so on #915's head (ddc77bc2) the workflow runs for the first time since the desync. Three of its jobs fail.None of the three is caused by #915. That PR changes only
actions.lockand the codeql refs, which point at the same commit. They were present onmainall along and invisible, because no job started. None is a required context: hypatiamainrequires onlyabi-codegen-drift,zig build test (FFI + wire contract),Escript packaging soundnessandscan / gitleaks.Run: https://github.com/hyperpolymath/hypatia/actions/runs/37831914775
1.
Rust Dependency Audit: 2 vulnerable advisories inCargo.lockcargo auditscanned 486 crates against 1295 advisories and reports:crossbeam-epoch: RUSTSEC-2026-0204, an invalid pointer dereference in thefmt::Pointerimpl forAtomic/Shared.h2: RUSTSEC-2026-0258, unbounded empty DATA frames.It also reports 3 warning classes, including
proc-macro-error2unmaintained (RUSTSEC-2026-0173) andevent-listener(RUSTSEC-2026-0221). The job correctly fails on its own findings (#849).Acceptance criteria
cargo update(or a direct bump) movescrossbeam-epochandh2to patched versions. If a patchedh2is unreachable through the current dependency tree, record the blocking crate and the advisory is ignored in config with a dated reason, not silently.Rust Dependency Auditpasses on the PR head.2.
Rust License & Ban Check: cargo-deny cannot parse its configThere is no
deny.tomlin the tree. The job's step "Create deny.toml if missing" writes one from a heredoc containingunmaintained = "warn". Current cargo-deny, installed unpinned throughtaiki-e/install-actionwithtool: cargo-deny, takes a scope there, not a lint level. So the job dies parsing its own generated config and checks nothing.Acceptance criteria
[advisories]keys conform to the cargo-deny schema the job installs, for exampleunmaintained = "workspace". Preferably commitdeny.tomlto the repo instead of generating it in the workflow.tool: cargo-deny@<x.y.z>), so a schema change arrives as a reviewed bump and not a silent red.Rust License & Ban Checkpasses, and its report shows advisories, bans, licenses and sources were actually evaluated.3.
Security Status: the orphan-job self-check has no checkoutThe
security-statusaggregator (from #850 AC4) parses its own workflow file to assert that every job is in itsneeds:list. The job has noactions/checkoutstep, so the file is absent and the self-check crashes before it checks anything. Its exit code is 2, not the script's ownexit 1. This is a broken guard, not a finding.Acceptance criteria
security-statuschecks out at least.github/workflows/security-policy.yml, for example a sparseactions/checkoutalready locked for this workflow.::error::, not an awk crash.needs:makes the self-check fail with the orphan message. Removing it makes the self-check pass.Security Statuspasses once 1 and 2 are fixed.Notes
security-policy.yml. Check the estate's KYAML-conversion preconditions for hypatia before converting that file in the same PR.