Commit 4e11cf6
ci: wire hypatia-scan.yml to query own Dependabot alerts
Auto-sweep follow-up to the Hypatia DependabotAlerts severity
floor that landed in verification-ecosystem/hypatia commit
75a36ce (2026-04-17). For the rule to actually return findings,
the per-repo hypatia-scan.yml needs:
- security-events
Without these, scan_from_path returns HTTP 403 and the rule
silently returns no findings.
Cross-ref: 007-lang/audits/audit-dependabot-automation-gap-2026-04-17.md
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent c76d503 commit 4e11cf6
1 file changed
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
16 | 19 | | |
17 | 20 | | |
18 | 21 | | |
| |||
0 commit comments