Skip to content

ci: pin the standards reusable workflows to #1209's merge (2e12b312) - #78

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/bump-standards-pins-to-1209
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
claude/bump-standards-pins-to-1209

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

This finishes the pin fix that #73 started. It moves the four hyperpolymath/standards reusable-workflow pins from 900c42c7 to 2e12b312, the merge commit of hyperpolymath/standards#1209. That makes governance / Actions lockfile verify pass again; it is red on main (809e521).

Why it is red on main. #73 restored block YAML so the actions-lock gate can read the pins, but it merged with the pins still at 900c42c7. At that SHA the gate step runs under bash -e. A bare bash check-actions-lock-gate.sh followed by rc=$? therefore kills the step when the gate exits 3 (missing-lock debt), before rc is read. The shrink-only ledger, which lists hyperpolymath/jaffascript, never gets the chance to excuse that debt. standards#1209 reads the exit code with || rc=$?, so the ledger is reached.

Changes

  • .github/workflows/governance.yml, mirror.yml, scorecard.yml and secret-scanner.yml: @900c42c70b968e11a2bca04bf0ce050be5c286dc → @2e12b312b529c51f095ce3b22cd35968f5aba898.
  • .github/workflows/mirror.yml:23: the comment naming the SHA at which the seven secrets are "the callee's complete optional contract" now names 2e12b312. mirror-reusable.yml is byte-identical at the two SHAs, so the contract has not changed.

Not changed

  • The workflows stay in block YAML. ci: restore block YAML so the actions-lock gate can read the pins #73 explains why: the actions-lock gate reads pins from block YAML, and that is still true at 2e12b312. Converting these files to KYAML would break the gate again.
  • No actions.lock is added. jaffascript's missing lockfile is ledgered debt in standards .machine_readable/lock-allow.txt. Writing the lockfile and deleting that ledger line is separate work.

📌 New pins

  • Head SHA: ac2edb24bb0287d5595bd4f19e53179947a04821
  • hyperpolymath/standards/.github/workflows/governance-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898
  • hyperpolymath/standards/.github/workflows/mirror-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898
  • hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898
  • hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898

All four resolve to no tag. 2e12b312 is the merge commit of standards#1209 (2026-10-09T00:26:51Z), and git merge-base --is-ancestor 2e12b312 origin/main succeeds in the standards clone, so the pin is on standards main. No lockfile record or container digest changes.

RSR Quality Checklist

Required

  • Tests pass: n/a, no source or test changed. The gate step was replayed locally (see Testing).
  • Code is formatted: n/a. Five SHA strings changed, and actionlint passes on all four files.
  • Linter is clean: actionlint exits 0 on the four edited workflows.
  • No banned language patterns: nothing added.
  • No unsafe blocks: n/a, no Rust changed.
  • No banned functions: n/a, no source or proofs changed.
  • SPDX license headers present: the four edited workflows keep their existing headers. No file is added.
  • No secrets, credentials, or .env files.

As Applicable

  • .machine_readable/*.a2ml: no. A2ML is retired, and the project state is unchanged.
  • Documentation: n/a, no user-facing change.
  • TOPOLOGY.md: n/a.
  • CHANGELOG: not updated, since this is a CI pin bump.
  • New dependencies: none. The four callees are already dependencies; only their SHA moves.
  • ABI/FFI: n/a.

Testing

  • What changed between the two pins: git diff --stat 900c42c7 2e12b312 over the whole standards tree touches three files: governance-reusable.yml (+7/−2, the fix), scripts/apply-tag-ruleset-canon.sh and its test (#1210, not used by callers). The gate's own scripts (check-actions-lock-gate.sh, update-actions-lock.sh) and the ledger lock-allow.txt are identical at both SHAs.

  • Local replay of the gate step. I extracted the step body "Check locked or SHA-pinned actions" from governance-reusable.yml at each SHA with yq. I staged the gate scripts and ledger from the same SHA into .standards-lock/, then ran the body with bash -e (the runner's shell) against a git archive of the caller tree, with GITHUB_REPOSITORY=hyperpolymath/jaffascript.

    Standards SHA Caller tree Ledger Exit Output
    900c42c7 main 809e521 as published 3 MISSING-LOCK DEBT (exit 3), the same error as the red job on main (job 113610554625)
    2e12b312 this branch as published 0 actions-lock debt is LEDGERED for hyperpolymath/jaffascript … 1 of 163 ledgered repositories
    2e12b312 this branch jaffascript's line removed 3 162 ledgered repositories; hyperpolymath/jaffascript is NOT among them

    The first row reproduces the red job on main. The third row shows the replay can still fail, so the pass in the second row comes from the ledger and not from a step that cannot fail.

  • actionlint on the four edited workflows: exit 0.

  • The real check is governance / Actions lockfile verify on this PR's head. Its result is listed under "Red checks" below.

Red checks on this head

Outcome

Merged 2026-10-09T00:46:37Z as 4b6eecd. On main 16fb94a, governance / Actions lockfile verify is SUCCESS (job 113614527134).

  • squabble verify-satisfied hyperpolymath/jaffascript 78 at 00:50:55Z: exit 0, DONE, no agent items.
  • Code scanning: the 52 open alerts on refs/pull/78/merge are all already open on main (61), so PR-minus-main is empty. Planted control: an alert number added only to the PR set is reported.
  • Not done: the full App census. REST was rate-limited again at 00:51:33Z.

As read before merge

Read 2026-10-09T00:5xZ via gh pr checks (GraphQL): 27 pass, 0 fail, 1 pending (governance / Exemption ratchet; it was skipped on main).

  • governance / Actions lockfile verify passes (job 113612786336). The log shows actions-lock debt is LEDGERED for hyperpolymath/jaffascript (missing-lock only, gate exit 3) and 1 of 163 ledgered repositories, the same as row 2 of the replay above.
  • Not yet done: the full App census (paginated check-runs, statuses, reviews, effective rules) and squabble verify-satisfied. GitHub REST rate-limited this session at 00:43Z, and those reads are REST-only.

Screenshots

n/a, no UI change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

#73 restored block YAML so the actions-lock gate can read the pins, but it
merged with the pins still at 900c42c7. At that SHA the gate step runs under
`bash -e`, so the gate's exit 3 (missing-lock debt) kills the step before
`rc=$?` is read, and the ledger that excuses jaffascript never runs.
`governance / Actions lockfile verify` is red on main (809e521) for that
reason.

hyperpolymath/standards#1209 (merge 2e12b312, on standards main) reads the
exit code with `|| rc=$?`. Between 900c42c7 and 2e12b312 only
governance-reusable.yml changed among the four callees; the mirror,
scorecard and secret-scanner reusables are byte-identical, so all four
pins move together and the mirror.yml contract comment is updated to match.
The workflows stay in block YAML (see #73).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f5124c80-e1fd-413c-b64d-b13d4b6a2382
📥 Commits

Reviewing files that changed from the base of the PR and between 809e521 and ac2edb2.

📒 Files selected for processing (4)
  • .github/workflows/governance.yml
  • .github/workflows/mirror.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (8)
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: scan / gitleaks
  • GitHub Check: Hypatia Neurosymbolic Analysis
  • GitHub Check: analyze (actions, none)
🔇 Additional comments (4)
.github/workflows/governance.yml (1)

21-21: LGTM!

.github/workflows/mirror.yml (1)

20-20: LGTM!

Also applies to: 23-23

.github/workflows/scorecard.yml (1)

14-14: LGTM!

.github/workflows/secret-scanner.yml (1)

27-27: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated the versions used by the governance, mirroring, security analysis and secret-scanning workflows.

Walkthrough

Four GitHub Actions workflows now reference reusable workflows at commit 2e12b312b529c51f095ce3b22cd35968f5aba898. The mirror workflow comments also identify this commit. Its explicit secrets mapping and the Scorecards job permissions are unchanged.

Changes

Reusable workflow references

Layer / File(s) Summary
Update reusable workflow references
.github/workflows/governance.yml, .github/workflows/mirror.yml, .github/workflows/scorecard.yml, .github/workflows/secret-scanner.yml
The four jobs now reference the new commit. The mirror workflow comments also identify the new commit; its secrets mapping remains unchanged.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~4 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to ac2ed

The workflows now use the updated pinned revision. No blocking regression is established by the supplied evidence, so the change appears mergeable after ordinary checks.

Architecture Summary

Architecture risk: 🔵 Low · up to ac2ed

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/governance.yml: The governance job’s reusable-workflow reference changed from commit 900c42c70b968e11a2bca04bf0ce050be5c286dc to 2e12b312b529c51f095ce3b22cd35968f5aba898.
  • observed — Modified behavior in .github/workflows/mirror.yml: The mirror job switches the reusable workflow reference from commit 900c42c70b968e11a2bca04bf0ce050be5c286dc to 2e12b312b529c51f095ce3b22cd35968f5aba898; its comments now identify the same new commit for the forge-job gates and seven-secret contract.
  • observed — Modified behavior in .github/workflows/scorecard.yml: The analysis job’s reusable workflow reference changes from commit 900c42c70b968e11a2bca04bf0ce050be5c286dc to 2e12b312b529c51f095ce3b22cd35968f5aba898.
  • observed — Modified behavior in .github/workflows/secret-scanner.yml: The scan job’s reusable workflow reference changes from commit 900c42c70b968e11a2bca04bf0ce050be5c286dc to 2e12b312b529c51f095ce3b22cd35968f5aba898.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check Passed The title clearly identifies the primary change: pinning the standards reusable workflows to the merge commit from issue #1209.
Description check Passed The description follows the required template and provides the summary, changes, rationale, testing details, checklist, and screenshots status. The real governance check result is still unspecified un…
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the workflow pins,
Four paths now share a newer hash.
The mirror notes the same commit,
While secrets keep their former shape.
The rabbit hops, then rests at last.

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 53 issues detected

Severity Count
🔴 Critical 6
🟠 High 20
🟡 Medium 27

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 33,
    "reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": 47,
    "reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": null,
    "reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
    "type": "WH014",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "high"
  },
  {
    "reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 7 day(s) old",
    "type": "CSA001",
    "file": ".github/workflows/labels.yml",
    "action": "review",
    "rule_module": "code_scanning_alerts",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 4b6eecd into main Oct 9, 2026
28 checks passed
@hyperpolymath
hyperpolymath deleted the claude/bump-standards-pins-to-1209 branch October 9, 2026 00:46
hyperpolymath added a commit that referenced this pull request Oct 9, 2026
## Summary

This makes jaffascript's own task runner a **`jaffa` just module**, the
option the owner chose on 2026-10-09.

The repo root held two justfiles: `Justfile` (the RSR template, 1,545
lines) and `justfile` (jaffascript's 29-line runner for `affinescript …
--face jaffa`). As a result:
- A bare `just` in the root failed with `error: multiple candidate
justfiles found … Justfile and justfile` (rc 1).
- A case-insensitive checkout (Windows, macOS) keeps only one of the two
files.
- The recipe names `default`, `run`, `build` and `lint` exist in both
files, so a plain `import` would collide.

A module keeps the two sets of recipes apart. jaffa's recipes now run as
`just jaffa <recipe>`.

## Changes

- **`justfile` → `jaffa.just`** (git sees a rename). Two lines change:
  - The header comment now names the file and how to run it.
- `default` now runs `@just --list jaffa`. It used to run `@just
--list`, which inside a module lists the *root* Justfile's ~100 template
recipes instead of jaffa's own.
- **`Justfile` and `.machine_readable/contractiles/Justfile`** (still
byte-identical, checked with `cmp`): `mod? jaffa "jaffa.just"` plus a
one-line comment, right after the existing `import? "contractile.just"`.
- The module is optional (`mod?`), for the same reason that import is
optional. The contractiles copy sits in a directory without `jaffa.just`
and must still parse.
- The cost: if `jaffa.just` is ever deleted, `just jaffa …` reports an
unknown recipe instead of a missing module file.
- **`README.adoc`**: the "via the justfile" example now reads `just
jaffa run …` / `just jaffa preview …`.
- **`EXPLAINME.adoc`**: the file-table row is now `jaffa.just`, run as
`just jaffa <task>`, and adds `hello`.
- **`.github/CONTRIBUTING.md:18`**: `just check` → `just jaffa check
examples/hello.affine`. The old line could not work: there is no root
`check` recipe, and jaffa's `check` takes a file.
- **`.editorconfig` `[justfile]` → `[*.just]`**, and **`.gitattributes`
`justfile` → `*.just`**. Both now also cover `contractile.just`. On
`main` that file got `text=auto eol=lf` from the catch-all rule; it now
gets `text eol=lf`. Its index and working-tree endings are LF either way
(`git ls-files --eol`: `i/lf w/lf`).

### Not changed

- **`docs/AFFIRMATION.adoc:202-204, 246` and
`docs/affirmations/AFFIRMATION-2026-10-07.adoc:182-184, 218`.** These
signed AFFIRMATIONs say "`just` cannot run here" because of the two
justfiles. Once this merges, that statement describes the repo as it was
when it was signed. Re-affirming is the owner's decision, so agents do
not edit them.
- `.machine_readable/STATE.a2ml` mentions the justfile, but A2ML is
retired, so it is untouched.
- Generic "use `just` (justfile)" lines in
`.machine_readable/ai/.{cline,cursor,windsurf}rules` and
`docs/practice/AI-CONVENTIONS.adoc`, and `ROADMAP.adoc:14` (a completed
item). Each is still true.
- `setup.sh:199` accepts either `Justfile` or `justfile`. `Justfile`
still exists.

## 📌 New pins

- **Head SHA: `900179b45003b4f42179b1145c68c5fabe786189`**
- None. No action `uses:`, `actions.lock`, lockfile or container digest
is added or changed.

## RSR Quality Checklist

### Required

- [ ] Tests pass: n/a, no source or test changed. Each recipe was run
(see Testing).
- [ ] Code is formatted: `just --summary` parses both Justfiles and
`jaffa.just`. There is no separate just formatter gate here.
- [x] Linter is clean: `asciidoctor --failure-level=WARN` passes on both
edited `.adoc` files.
- [x] No banned language patterns: nothing added.
- [ ] No `unsafe` blocks: n/a, no Rust changed.
- [ ] No banned functions: n/a, no source or proofs changed.
- [x] SPDX license headers present: `jaffa.just` keeps `MPL-2.0`. Every
other edited file keeps its existing header.
- [x] No secrets, credentials, or `.env` files.

### As Applicable

- [ ] `.machine_readable/*.a2ml`: no. A2ML is retired.
- [x] Documentation updated: `README.adoc`, `EXPLAINME.adoc`,
`.github/CONTRIBUTING.md`.
- [ ] `TOPOLOGY.md`: n/a.
- [ ] `CHANGELOG`: not updated, because it is a task-runner rename.
- [ ] New dependencies: none.
- [ ] ABI/FFI: n/a.

## Testing

All runs used just 1.56.0 and affinescript 0.1.1, in this worktree at
`900179b`. "Main" means `main` at `809e521`.

| Command | Main | This head |
|---|---|---|
| `just --list` (bare, root) | **rc 1**, `multiple candidate justfiles
found` | rc 0. The listing includes `jaffa ...` |
| `just jaffa` (module `default`) | n/a | rc 0. Lists only the 7 jaffa
recipes |
| `just jaffa check examples/hello.affine` | n/a | rc 0, `Type checking
passed` (runs `affinescript check --face jaffa …`) |
| `just jaffa hello` | `just --justfile justfile hello`: **rc 124**,
`Runtime error: Unhandled effect: println` | **rc 124**, identical |
| `just --justfile .machine_readable/contractiles/Justfile --summary` |
n/a | rc 0 (the `mod?` is skipped there) |
| `just validate-rsr` | only as `just --justfile Justfile validate-rsr`:
rc 1, `MISSING:` the 3 retired `.a2ml` paths | runs bare: rc 1, the same
3 paths. Unchanged; the recipe predates the A2ML retirement |

- **`just jaffa hello` fails on `main` too.** The failure is the
affinescript 0.1.1 interpreter not handling the `println` effect, not
this change. It is reported separately.
- **No conflict with #78:** `git merge-tree --write-tree` of this head
with #78's head (`ac2edb2`) exits 0. Positive control: a planted
conflicting edit to `.github/workflows/governance.yml` makes it exit 1.
- **Docstrings:** standards `.githooks/docstring-scan.sh --range
origin/main..HEAD --check` finds 0 touched functions.

## Red checks on this head

_Filled in once the checks report._

## Screenshots

n/a, no UI change.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant