What
PR #74 (licence rule: MPL-2.0 for code, CC-BY-SA-4.0 for prose) edits one line in each of Justfile and .machine_readable/contractiles/Justfile: the {{LICENSE}} substitution. Because the PR touches those two files, the Hypatia code-scanning check on its head (a1c7c57, check-run 113593251417) reports their open alerts as "16 new alerts in code changed by this pull request" and fails. The check is not a required context; the only required context on main is scan / gitleaks.
The alerts themselves are older than the PR. On 2026-10-08T23:3xZ, code-scanning/alerts?ref=refs/heads/main and ?ref=refs/pull/74/merge both list the same underlying alerts, with the same numbers:
hypatia/structural_drift/SD024 (error), 7 alerts, #162 to #168, created 2026-09-12. Alert #162 is at Justfile:55: "CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/".
hypatia/content_patterns/npx_in_workflow (warning), #195 (.machine_readable/contractiles/Justfile) and #196 (Justfile), created 2026-09-18: "npx / npm run banned in CI -- use bunx or bun run instead".
hypatia/code_scanning_alerts/CSA001/CSA003 are Hypatia's alerts about those alerts going stale (overdue against its 7-day threshold). It creates them again for each ref it scans, so they carry new numbers on the PR ref (#249 to #264) while #169 to #175 and #207 to #217 remain on main. They go away when the alerts above do.
This is deferred here rather than fixed in #74, under the standing owner ruling (2026-09-15) that a finding outside a PR's change becomes an issue with acceptance criteria, not a merge blocker. #74 changes only licence text.
Acceptance criteria
🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
What
PR #74 (licence rule: MPL-2.0 for code, CC-BY-SA-4.0 for prose) edits one line in each of
Justfileand.machine_readable/contractiles/Justfile: the{{LICENSE}}substitution. Because the PR touches those two files, theHypatiacode-scanning check on its head (a1c7c57, check-run 113593251417) reports their open alerts as "16 new alerts in code changed by this pull request" and fails. The check is not a required context; the only required context onmainisscan / gitleaks.The alerts themselves are older than the PR. On 2026-10-08T23:3xZ,
code-scanning/alerts?ref=refs/heads/mainand?ref=refs/pull/74/mergeboth list the same underlying alerts, with the same numbers:hypatia/structural_drift/SD024(error), 7 alerts, #162 to #168, created 2026-09-12. Alert #162 is atJustfile:55: "CI policy requires a retired descriptile path; align the check with .machine_readable/descriptiles/".hypatia/content_patterns/npx_in_workflow(warning), #195 (.machine_readable/contractiles/Justfile) and #196 (Justfile), created 2026-09-18: "npx /npm runbanned in CI -- usebunxorbun runinstead".hypatia/code_scanning_alerts/CSA001/CSA003are Hypatia's alerts about those alerts going stale (overdue against its 7-day threshold). It creates them again for each ref it scans, so they carry new numbers on the PR ref (#249 to #264) while #169 to #175 and #207 to #217 remain onmain. They go away when the alerts above do.This is deferred here rather than fixed in #74, under the standing owner ruling (2026-09-15) that a finding outside a PR's change becomes an issue with acceptance criteria, not a merge blocker. #74 changes only licence text.
Acceptance criteria
Justfile(and.machine_readable/contractiles/Justfile, if it carries the same check) reads descriptiles from.machine_readable/descriptiles/, not the retired path, and SD024 #162 to #168 close on a fresh default-branch scan. No6a2/path is restored.npx/npm runuses in both Justfiles becomebunx/bun run, and #195 and #196 close.Hypatiacheck on a PR that touches either Justfile concludes success. On the default branch, CSA001/CSA003 alerts about these rules no longer appear.🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf