From f028d1f4acf74b84e526519ba63d02c2b6d068db Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 9 Oct 2026 00:07:27 +0100 Subject: [PATCH 1/2] ci: restore block YAML so the actions-lock gate can read the pins MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit #72 converted the four workflows it edited to KYAML. Governance on main 589e1be then went red in "Actions lockfile verify": standards scripts/check-actions-lock-gate.sh@900c42c (lines 66-68) accepts a pin only as `@<40 hex>` followed by whitespace or end of line, and exempts standards reusables only as an unquoted `uses: hyperpolymath/standards/`. KYAML's `uses: "…@",` fails both, so all four SHA-pinned refs were reported as unpinned (exit 1, which the lock-debt ledger cannot excuse). Block YAML gives the gate's exit 3 (missing lockfile), and hyperpolymath/jaffascript is on the shrink-only lock-allow.txt ledger, so the step passes. The parsed data of all four files is identical to main (yq JSON compare); only the serialisation changes. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf --- .github/workflows/governance.yml | 51 +++++++++------------- .github/workflows/mirror.yml | 65 +++++++++++++--------------- .github/workflows/scorecard.yml | 46 +++++++++----------- .github/workflows/secret-scanner.yml | 40 ++++++++--------- 4 files changed, 86 insertions(+), 116 deletions(-) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 72d41c0..53c097f 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,32 +1,21 @@ # SPDX-License-Identifier: MPL-2.0 -{ - name: "Governance", - on: { - push: { - branches: [ - "main", - "master", - ], - }, - pull_request: { - branches: [ - "main", - "master", - ], - }, - workflow_dispatch: null, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: true, - }, - permissions: { - actions: "read", # required by the reusable workflow (staleness check reads workflow runs) - contents: "read", - }, - jobs: { - governance: { - uses: "hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - }, - }, -} +name: Governance + +on: + push: + branches: [main, master] + pull_request: + branches: [main, master] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + actions: read # required by the reusable workflow (staleness check reads workflow runs) + contents: read + +jobs: + governance: + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index eebb714..8cd4783 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,38 +1,31 @@ # SPDX-License-Identifier: MPL-2.0 # SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell -{ - name: "Mirror to Git Forges", - on: { - push: { - branches: [ - "main", - ], - }, - workflow_dispatch: null, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: false, - }, - permissions: { - actions: "read", # required by the reusable workflow - contents: "read", - }, - jobs: { - mirror: { - uses: "hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - # Each forge job is still gated on vars._MIRROR_ENABLED, inside the - # callee. Explicit secrets map, no secrets: inherit; these seven are the - # callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc. - secrets: { - GITLAB_SSH_KEY: "${{ secrets.GITLAB_SSH_KEY }}", - BITBUCKET_SSH_KEY: "${{ secrets.BITBUCKET_SSH_KEY }}", - CODEBERG_SSH_KEY: "${{ secrets.CODEBERG_SSH_KEY }}", - SOURCEHUT_SSH_KEY: "${{ secrets.SOURCEHUT_SSH_KEY }}", - DISROOT_SSH_KEY: "${{ secrets.DISROOT_SSH_KEY }}", - GITEA_SSH_KEY: "${{ secrets.GITEA_SSH_KEY }}", - RADICLE_KEY: "${{ secrets.RADICLE_KEY }}", - }, - }, - }, -} +name: Mirror to Git Forges + +on: + push: + branches: [main] + workflow_dispatch: + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + +permissions: + actions: read # required by the reusable workflow + contents: read + +jobs: + mirror: + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc + # Each forge job is still gated on vars._MIRROR_ENABLED, inside the + # callee. Explicit secrets map, no secrets: inherit; these seven are the + # callee's complete optional contract at 900c42c70b968e11a2bca04bf0ce050be5c286dc. + secrets: + GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }} + BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }} + CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }} + SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }} + DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }} + GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }} + RADICLE_KEY: ${{ secrets.RADICLE_KEY }} diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index ae8ad02..4004900 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,27 +1,21 @@ # SPDX-License-Identifier: MPL-2.0 -{ - name: "Scorecards supply-chain security", - on: { - branch_protection_rule: null, - schedule: [ - { - cron: "23 4 * * 1", - }, - ], - }, - permissions: "read-all", - jobs: { - analysis: { - uses: "hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - # A job-level map replaces the workflow-level one, so every scope the - # callee's jobs request must be listed here. actions: read is new in the - # callee since 81dbf2dd. No secrets: the callee declares and reads none. - permissions: { - actions: "read", - contents: "read", - security-events: "write", - id-token: "write", - }, - }, - }, -} +name: Scorecards supply-chain security + +on: + branch_protection_rule: + schedule: + - cron: '23 4 * * 1' + +permissions: read-all + +jobs: + analysis: + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc + # A job-level map replaces the workflow-level one, so every scope the + # callee's jobs request must be listed here. actions: read is new in the + # callee since 81dbf2dd. No secrets: the callee declares and reads none. + permissions: + actions: read + contents: read + security-events: write + id-token: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 1f3a824..57740e8 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -8,26 +8,20 @@ # No `secrets:` line, deliberately: the reusable references no secrets # (gitleaks runs as a checksum-verified binary, not gitleaks-action), so # `secrets: inherit` would only hand it every repo and org secret (CWE-250). -{ - name: "Secret Scanner", - on: { - pull_request: null, - push: { - branches: [ - "main", - ], - }, - }, - concurrency: { - group: "${{ github.workflow }}-${{ github.ref }}", - cancel-in-progress: true, - }, - permissions: { - contents: "read", - }, - jobs: { - scan: { - uses: "hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc", - }, - }, -} +name: Secret Scanner + +on: + pull_request: + push: + branches: [main] + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + +permissions: + contents: read + +jobs: + scan: + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@900c42c70b968e11a2bca04bf0ce050be5c286dc From 0bee4f45a5298222a0f53757af4ce8ed8815ceee Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 9 Oct 2026 00:18:26 +0100 Subject: [PATCH 2/2] ci(scorecard): name the workflow-level scope instead of read-all SonarCloud githubactions:S8234 on #73. The analysis job declares its own map, which replaces the workflow-level one, so `read-all` reached no job; `contents: read` states the same effective permissions. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf --- .github/workflows/scorecard.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 4004900..83e700e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -6,7 +6,8 @@ on: schedule: - cron: '23 4 * * 1' -permissions: read-all +permissions: + contents: read jobs: analysis: