ci: bump Hypatia scan reusable pin to GITHUB_TOKEN fix - #664
ci: bump Hypatia scan reusable pin to GITHUB_TOKEN fix#664hyperpolymath wants to merge 1 commit into
Conversation
Point the scan wrapper at the standards reusable commit that sets GITHUB_TOKEN (HYPATIA_SCAN_PAT || GITHUB_TOKEN) in the scan step, so the Dependabot / code-scanning / secret-scanning alert checks stop emitting "GITHUB_TOKEN not set" warnings. The reusable at this pin also keeps the --exit-zero + always() artifact upload, so findings are published even when the severity gate fails. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01V13sGvHnaeCY5A9fF2QsDm
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedBumps the Hypatia scan reusable workflow pin to resolve missing GITHUB_TOKEN warnings and preserve artifact uploads on failure. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
|
|
Point the scan wrapper at the standards reusable commit that sets GITHUB_TOKEN (HYPATIA_SCAN_PAT || GITHUB_TOKEN) in the scan step, so the Dependabot / code-scanning / secret-scanning alert checks stop emitting "GITHUB_TOKEN not set" warnings. The reusable at this pin also keeps the --exit-zero + always() artifact upload, so findings are published even when the severity gate fails.
Claude-Session: https://claude.ai/code/session_01V13sGvHnaeCY5A9fF2QsDm
Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers