Repository navigation
ci: two pre-existing reds on main — Static Analysis Gate (Hypatia CWE-494 ×2 in setup.sh) and Well-Known Standards (security.txt under www/.well-known, validator reads the root) #117
Description
Activity
- addedbugSomething is broken or behaves incorrectlySomething is broken or behaves incorrectly
on Sep 22, 2026 Correction after re-measuring the merge gate (body updated, criteria 2 and 3 rewritten).
The 33 open Hypatia alerts are not what blocks #116. Its Hypatia check reads "No new alerts in code changed by this pull request", and the 33 alert numbers on the merge ref are exactly the ones open on
main. What cannot pass is thecode_scanningrule itself: it names CodeQL, Hypatia and Scorecard, andscorecard.ymlruns onschedule/workflow_dispatchonly, so a PR ref never carries a Scorecard analysis (merge ref of #116: CodeQL 1, Hypatia 1, Scorecard 0). The ruleset's own history says the same: all 8 pushes tomainin the last month are recorded asbypasswithcode_scanning: fail. Curing the twosetup.shsites therefore does not unblock #116 on its own; the rule needs re-scoping (criterion 3, owner decision D84 on hyperpolymath/standards#787).Well-Known: two validators, one tree, opposite verdicts.
governance / Well-Known (RFC 9116 + RSR)is green on #116 (run 35781569687) whilewellknown-enforcement.ymlsaysNo security.txt found. Fixing either validator alone turns the other red, so criterion 2 now starts with deciding the canonical layout.🤖 Generated with Claude Code
- added a commit that references this issue
on Sep 22, 2026 Criterion 3 is met, measured.
- Owner ruling D84 (Owner decision sheet D1–D293: one answerable place for #637 + #715 + #709 + #658 (superseded by successor — see latest comment) standards#787): the
code_scanningrule of rulesetOptimus-Branch(15402968) was re-scoped 2026-09-22T20:54Z to CodeQL + Hypatia; Scorecard, a default-branch scorer that never analyses a PR ref, was dropped. Nothing else in the ruleset changed (before/after diff: the one tool entry andupdated_at). - docs(type-connections): re-cite the residual receipt at run 35781018563 #116 went from
BLOCKEDtoUNSTABLE(every rule satisfied, one non-required check red) and was squash-merged as86cb69e5with no bypass: rule-suite 4182119358 recordsresult: passwithrequired_signatures,code_scanning,required_status_checks,deletionandpull_requestallpass. The previous 8 pushes tomainwere allbypass.
Still open here: criterion 1 (
setup.sh:144/:156curl-pipe-to-shell, the Hypatia red on every run) and criterion 2 (the two Well-Known validators disagreeing on wheresecurity.txtlives). Criterion 4 is moot: #116 landed through the gate, not over it.🤖 Generated with Claude Code
- Owner ruling D84 (Owner decision sheet D1–D293: one answerable place for #637 + #715 + #709 + #658 (superseded by successor — see latest comment) standards#787): the
Criterion 1 is implemented in #119. Both
just.systems/install.sh | bashcalls are replaced by a pinned just 1.58.0 release, checked with sha256 before install. Thesetup.sh:9comment no longer advertisescurl | sh. Verified: a real download installs, a tampered digest is rejected, and shellcheck is clean.Local re-scan. Main is @86cb69e: 33 findings (1 critical). With #119: 28 (0 critical, 1 high). Scanner: hypatia
fix/comment-line-precision(#883, which stacks on #875), local escript, no Actions minutes used. The critical was RE008 ondependabot-automerge.yml:53, a false positive (the gate already ANDsgithub.event.pull_request.user.login). It is fixed in the rule, hypatia#88310a0f8e. The remaining high isunanchored_heading_regexinrsr-antipattern.yml, which is not in the static gate's critical count.Criteria 2 (the canonical
.well-knownlayout) and 3 (the code_scanning tool list, D84) are owner decisions. They are batched for the owner.🤖 Generated with Claude Code
- addedpriority:p0Critical - drop other workCritical - drop other workscope:repoConfined to this repositoryConfined to this repositorystatus:readyFully specified and ready to be picked upFully specified and ready to be picked up
on Sep 30, 2026 Progress on AC1: #122 (merged as 1afec5b) removes both
curl … | bashsites insetup.sh.justis now installed from pinned release binaries whose SHA-256 is checked before anything runs, and the usage comment no longer advertises the pattern. #119 carried the same tree but was closed, because a CodeRabbit commit on it was unsigned.Still open:
- AC1's green-gate half is not done yet. Hypatia still flags a comment that quotes the old one-liner. That false positive is fixed at source in fix(rules): shell eval/download/tmp rules skip comment lines (C4) hypatia#883 (comment-line precision), which takes effect once the scanner pin moves.
- AC2 (security.txt canonical layout) and AC3 (code_scanning tool list, D84) are not touched by fix(setup): checksum-verified just install instead of curl|bash (CWE-494) #122.
Measured (2026-09-22, main = 1fa506c)
Static Analysis Gate→ jobHypatia neurosymbolic scanis red onmainsince run 35602727566 (2026-09-21) and on every PR since, including the docs-only docs(type-connections): re-cite the residual receipt at run 35781018563 #116 (run 35781568819):[hypatia] Download-and-execute pattern (curl|wget pipe to shell) -- verify integrity before execution (2 occurrences, CWE-494); the stepFail on critical security findingsexits 1. The two live sites aresetup.sh:144andsetup.sh:156, bothcurl -fsSL https://just.systems/install.sh | bash -s -- --to /usr/local/bin(setup.sh:9carries the same pattern inside a comment). The twoHardcoded /tmp/ pathsfindings are warnings and do not fail the job.Well-Known Standards (RFC 9116 + RSR)(.github/workflows/wellknown-enforcement.yml) is red on its 2026-09-22 schedule run 35709252948:No security.txt found. The validator tests.well-known/security.txtandsecurity.txtat the repository root; the file lives atwww/.well-known/security.txt(besideai.txtandhumans.txt). The workflow'spush/pull_requestpaths:filters name only.well-known/**andsecurity.txt, so no PR exercises it and the reds are the schedule runs.Optimus-Branch(15402968) requiresCodeQL,CodeRabbit,SonarCloud Code Analysisandgovernance / Code quality + docs(all green on docs(type-connections): re-cite the residual receipt at run 35781018563 #116; commit signature valid, CodeRabbit approved, 0 unresolved threads) and carries acode_scanningrule naming CodeQL, Hypatia and Scorecard (thresholds all/all).scorecard.ymlruns onscheduleandworkflow_dispatchonly, so no PR ref ever carries a Scorecard analysis (merge ref of docs(type-connections): re-cite the residual receipt at run 35781018563 #116: CodeQL 1, Hypatia 1, Scorecard 0) and the rule cannot pass on any PR. The rule-suite history confirms it: all 8 pushes tomainin the last month (latest1fa506c8,61421562,744d9f58) are recorded asbypassby the owner, each withcode_scanning: fail("Code scanning is waiting for results from CodeQL for the commits …"). The 33 open Hypatia alerts are NOT what blocks docs(type-connections): re-cite the residual receipt at run 35781018563 #116: its check reads "No new alerts in code changed by this pull request", and the 33 alert numbers on the merge ref are exactlymain's.Acceptance criteria
setup.sh:144andsetup.sh:156no longer pipe a network fetch into a shell:justis installed from a pinned release whose checksum is verified before anything executes, or from the distribution package; thesetup.sh:9comment stops advertising the pattern.Static Analysis Gateis green onmainwith zero critical findings inhypatia-findings.json(the warning count is reported, not gated).governance / Well-Known (RFC 9116 + RSR)is green on docs(type-connections): re-cite the residual receipt at run 35781018563 #116 (run 35781569687, stepRFC 9116 security.txt validationsucceeded) whilewellknown-enforcement.ymlreportsNo security.txt found. First decide the canonical layout (root.well-known/security.txtper RFC 9116 §3, or thewww/.well-known/publish tree), then make BOTH validators test that path and extend the workflow'spaths:filters to cover it. Green = aworkflow_dispatchrun ofwellknown-enforcement.ymlsucceeds onmainwhile the governance job stays green on the same commit.code_scanningrule is satisfiable on a PR without bypass: its tool list is re-scoped to the tools that analyse PR refs (CodeQL, Hypatia), Scorecard staying a default-branch scorer, or Scorecard is made to publish results for PR refs. Green = a rule-suite entry for amainpush withresult: pass(notbypass) andcode_scanning: pass. Owner decision D84 on Owner decision sheet D1–D293: one answerable place for #637 + #715 + #709 + #658 (superseded by successor — see latest comment) standards#787.Refs #32, #116.
🤖 Generated with Claude Code