Skip to content

PAT-refresh tripwire: live HYPATIA_SCAN_PAT will arm 6 unackable CSA findings in both gates #957

Description

@hyperpolymath

The tripwire

Refreshing HYPATIA_SCAN_PAT (currently 401ing, shadowing the GITHUB_TOKEN fallback) will make Hypatia's code_scanning_alerts rules (CSA001/CSA002) start emitting in CI. Measured locally with a working token just now: 6 findings, all high, none ackable in principle:

  • CSA001 Scorecard TokenPermissions on propagate-hooks.yml (the known alert)
  • CSA001 Scorecard BinaryArtifacts x2 (casket-ssg, casket-simple)
  • CSA001 Hypatia invalid_actions_lock echo on actions.lock
  • CSA001 CodeQL untrusted-checkout on security-gate-pr-target.yml
  • CSA002 batch summary

Both blocking gates run apply-baseline.sh on raw JSON (thresholds high + info). These findings echo LIVE alert state; acking them in a static baseline is wrong (they change independently) and creates the circular merge dependency the reusable's own comment warns about (hypatia-scan-reusable.yml:294-300 — the SARIF path already excludes them).

Today it is masked

The dead PAT 401s the alert query, so CI sees 0 CSA findings (same failure mode as the Identify 401). Round 2 verified green on that basis. The moment the PAT is refreshed, both gates go red on CSA.

Options (owner call)

  1. Exclude code_scanning_alerts in apply-baseline.sh (match the SARIF renderer's exclusion; needs a test + consumer notice).
  2. Ack CSA in the baseline with short expiries (churn; fights live state).
  3. Leave blocking (alerts must be zero — the strictest estate policy; requires clearing Scorecard/CodeQL alerts first).

Recommend option 1. Do not refresh the PAT until this is decided, or expect red gates.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions