Commit 44bf52e
ci: wire hypatia-scan.yml to query own Dependabot alerts
Auto-sweep follow-up to the Hypatia DependabotAlerts severity
floor that landed in verification-ecosystem/hypatia commit
75a36ce (2026-04-17). For the rule to actually return findings,
the per-repo hypatia-scan.yml needs:
- security-events
Without these, scan_from_path returns HTTP 403 and the rule
silently returns no findings.
Cross-ref: 007-lang/audits/audit-dependabot-automation-gap-2026-04-17.md
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent d49a209 commit 44bf52e
1 file changed
Lines changed: 3 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 | | |
15 | 18 | | |
16 | 19 | | |
| |||
0 commit comments