Skip to content

fix(launcher): regenerate game-server-admin launcher with the XDG pid/log ladder #280

fix(launcher): regenerate game-server-admin launcher with the XDG pid/log ladder

fix(launcher): regenerate game-server-admin launcher with the XDG pid/log ladder #280

Triggered via pull request September 30, 2026 14:48
Status Success
Total duration 48s
Artifacts 4

static-analysis-gate.yml

on: pull_request
panic-attack assail
5s
panic-attack assail
Hypatia neurosymbolic scan
31s
Hypatia neurosymbolic scan
Patch Bridge CVE triage
7s
Patch Bridge CVE triage
Deposit findings for gitbot-fleet
9s
Deposit findings for gitbot-fleet
Fit to window
Zoom out
Zoom in

Annotations

1 error, 14 warnings, and 6 notices
Hypatia neurosymbolic scan: .github/workflows/hypatia-scan.yml#L1
[hypatia] workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.
panic-attack assail
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Patch Bridge CVE triage
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/upload-artifact@v4.6.2, erlef/setup-beam@v1.20.4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Hypatia neurosymbolic scan: .github/workflows/static-analysis-gate.yml#L87
[hypatia] workflow .github/workflows/static-analysis-gate.yml:87 step `Emit check annotations` swallows non-zero exit via `|| true` — failures will be masked
Hypatia neurosymbolic scan: .github/workflows/label-triage.yml#L53
[hypatia] job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/boj-build.yml#L24
[hypatia] job in .github/workflows/boj-build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/hypatia-scan.yml#L84
[hypatia] job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/instant-sync.yml#L25
[hypatia] job in .github/workflows/instant-sync.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/release.yml#L120
[hypatia] job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/push-email-notify.yml#L45
[hypatia] job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: .github/workflows/labels.yml#L39
[hypatia] job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring
Hypatia neurosymbolic scan: labels.yml#L1
[hypatia] Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Hypatia neurosymbolic scan: label-triage.yml#L1
[hypatia] Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).
Deposit findings for gitbot-fleet
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/download-artifact@v4.1.8, actions/upload-artifact@v4.6.2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
panic-attack assail
panic-attack binary not available — skipping assail
panic-attack assail
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Patch Bridge CVE triage
panic-attack binary not available — skipping Patch Bridge
Patch Bridge CVE triage
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Hypatia neurosymbolic scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Deposit findings for gitbot-fleet
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
bridge-report
218 Bytes
sha256:ab97ff7b4a118a75c5d71a482c6136a6d63801bc7df28ae753f2e113908c8742
hypatia-findings
1.8 KB
sha256:20c39c2e78a4380cad28eaa3817c471fc7ec274d41f20d8f9ccda44e68022737
panic-attack-findings
171 Bytes
sha256:d38a301a5ec7c643d5c1e872bda37ea5121ae78cb6ddb5fcd1172d639d1bf263
unified-findings
2.05 KB
sha256:a007b586230a374965a6628d860222f88acedfe08edddbc36eeb779853c2cc5a