The tripwire
Refreshing HYPATIA_SCAN_PAT (currently 401ing, shadowing the GITHUB_TOKEN fallback) will make Hypatia's code_scanning_alerts rules (CSA001/CSA002) start emitting in CI. Measured locally with a working token just now: 6 findings, all high, none ackable in principle:
- CSA001 Scorecard TokenPermissions on propagate-hooks.yml (the known alert)
- CSA001 Scorecard BinaryArtifacts x2 (casket-ssg, casket-simple)
- CSA001 Hypatia invalid_actions_lock echo on actions.lock
- CSA001 CodeQL untrusted-checkout on security-gate-pr-target.yml
- CSA002 batch summary
Both blocking gates run apply-baseline.sh on raw JSON (thresholds high + info). These findings echo LIVE alert state; acking them in a static baseline is wrong (they change independently) and creates the circular merge dependency the reusable's own comment warns about (hypatia-scan-reusable.yml:294-300 — the SARIF path already excludes them).
Today it is masked
The dead PAT 401s the alert query, so CI sees 0 CSA findings (same failure mode as the Identify 401). Round 2 verified green on that basis. The moment the PAT is refreshed, both gates go red on CSA.
Options (owner call)
- Exclude
code_scanning_alerts in apply-baseline.sh (match the SARIF renderer's exclusion; needs a test + consumer notice).
- Ack CSA in the baseline with short expiries (churn; fights live state).
- Leave blocking (alerts must be zero — the strictest estate policy; requires clearing Scorecard/CodeQL alerts first).
Recommend option 1. Do not refresh the PAT until this is decided, or expect red gates.
The tripwire
Refreshing
HYPATIA_SCAN_PAT(currently 401ing, shadowing theGITHUB_TOKENfallback) will make Hypatia'scode_scanning_alertsrules (CSA001/CSA002) start emitting in CI. Measured locally with a working token just now: 6 findings, all high, none ackable in principle:Both blocking gates run
apply-baseline.shon raw JSON (thresholds high + info). These findings echo LIVE alert state; acking them in a static baseline is wrong (they change independently) and creates the circular merge dependency the reusable's own comment warns about (hypatia-scan-reusable.yml:294-300 — the SARIF path already excludes them).Today it is masked
The dead PAT 401s the alert query, so CI sees 0 CSA findings (same failure mode as the Identify 401). Round 2 verified green on that basis. The moment the PAT is refreshed, both gates go red on CSA.
Options (owner call)
code_scanning_alertsinapply-baseline.sh(match the SARIF renderer's exclusion; needs a test + consumer notice).Recommend option 1. Do not refresh the PAT until this is decided, or expect red gates.