From 08b9ed23d1ab7588a1f427fe877cd38b4c0f86df Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 3 Sep 2026 02:55:53 +0100 Subject: [PATCH] fix: the Hypatia gate could never fire -- 2>&1 made it unconditionally vacuous The previous fix closed one route to a falsely-clean findings file. There are two. This closes the second: the scanner AVAILABILITY PROBE. `[ -d "$HOME/hypatia/scanner" ]` is unsatisfiable -- hypatia has no scanner/ directory -- so `ready` was always false, "Run Hypatia scan" was always skipped, and "Create stub findings" wrote a clean `[]`, making the gate unconditionally green. Separately, `${REPO_OWNER}/hypatia` 404s for any owner but hyperpolymath, producing the same silent stub via `2>/dev/null || true` plus continue-on-error. Verified live: on the previous PR's merge run, exactly the three repos carrying these two probe defects reported `Run Hypatia scan = skipped` with `Create stub findings = success`, and no others. - probe `[ -f "$HOME/hypatia/mix.exs" ]`, the file the project has - hardcode hyperpolymath for the hypatia and panic-attack sources - promote the silent ::notice:: to ::error:: so unavailability is visible - drop the vestigial `mv hypatia ../hypatia-v2` (the scan calls hypatia-cli.sh) Unavailability still yields a green check; that pass/fail policy is escalated separately rather than decided here. --- .github/workflows/static-analysis-gate.yml | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml index 7315885..dd90abd 100644 --- a/.github/workflows/static-analysis-gate.yml +++ b/.github/workflows/static-analysis-gate.yml @@ -158,16 +158,21 @@ jobs: continue-on-error: true run: | git clone https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia" 2>/dev/null || true - if [ -d "$HOME/hypatia/scanner" ]; then + # Probe the file hypatia actually has. The previous test was + # `[ -d "$HOME/hypatia/scanner" ]`, but hypatia has NO `scanner/` + # directory, so the test was UNSATISFIABLE: ready was always false, + # "Run Hypatia scan" was always skipped, and the stub step below wrote + # a clean `[]`. That made this gate unconditionally green regardless + # of the code under test. `mix.exs` is hypatia's real project root file. + if [ -f "$HOME/hypatia/mix.exs" ]; then cd "$HOME/hypatia" - if [ ! -f hypatia-v2 ]; then + if [ ! -f hypatia ] && [ ! -f hypatia-v2 ]; then mix deps.get mix escript.build - mv hypatia ../hypatia-v2 fi echo "ready=true" >> "$GITHUB_OUTPUT" else - echo "::notice::Hypatia scanner not available — skipping scan" + echo "::error::Hypatia scanner could not be prepared -- the scan is SKIPPED and this gate enforces NOTHING on this run" echo "ready=false" >> "$GITHUB_OUTPUT" fi