Skip to content

Re-arm the hypatia baseline gate: generate .hypatia-baseline.json (152 findings to grandfather + burn down) #314

Description

@hyperpolymath

PR #313 bumped the governance pin past the standards baseline-gate fix. On the current reusable, Validate Hypatia Baseline is skipped because echidna ships no .hypatia-baseline.json — Governance is green, but the gate is disarmed.

To re-arm:

  1. Run the hypatia scanner locally (same invocation as the reusable) and emit the baseline JSON of the current findings: 152 ≥ medium (70 high, 82 medium) as of run 28858381106.
  2. Commit .hypatia-baseline.json at repo root — the gate then fails only on NEW findings above baseline.
  3. Burn down the 70 high findings as a triaged campaign (relates to Split Rust/FFI/proof safety alerts by runtime, memory, proof, and test-only risk #239's split-by-runtime-risk proposal).

🤖 Generated with Claude Code

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationBots, schedulers, dispatch, self-healing, fan-outchoreRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions