Repository navigation
ci: pin the standards reusable workflows to #1209's merge (2e12b312) - #78
Conversation
#73 restored block YAML so the actions-lock gate can read the pins, but it merged with the pins still at 900c42c7. At that SHA the gate step runs under `bash -e`, so the gate's exit 3 (missing-lock debt) kills the step before `rc=$?` is read, and the ledger that excuses jaffascript never runs. `governance / Actions lockfile verify` is red on main (809e521) for that reason. hyperpolymath/standards#1209 (merge 2e12b312, on standards main) reads the exit code with `|| rc=$?`. Between 900c42c7 and 2e12b312 only governance-reusable.yml changed among the four callees; the mirror, scorecard and secret-scanner reusables are byte-identical, so all four pins move together and the mirror.yml contract comment is updated to match. The workflows stay in block YAML (see #73). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (8)
🔇 Additional comments (4)
📝 SummarySummary by CodeRabbit
WalkthroughFour GitHub Actions workflows now reference reusable workflows at commit ChangesReusable workflow references
Priority: ⬇️ Low Estimated code review effort: 1 (Trivial) | ~4 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The workflows now use the updated pinned revision. No blocking regression is established by the supplied evidence, so the change appears mergeable after ordinary checks. Architecture SummaryArchitecture risk: 🔵 Low · up to The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency. Changed systems: None identified. Architecture concerns Review detailsBefore / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the workflow pins, Comment |
|
🔍 Hypatia Security ScanFindings: 53 issues detected
View findings[
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"line": 38,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 82,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 52,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 33,
"reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": 47,
"reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "medium"
},
{
"line": null,
"reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
"type": "WH014",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "high"
},
{
"reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 7 day(s) old",
"type": "CSA001",
"file": ".github/workflows/labels.yml",
"action": "review",
"rule_module": "code_scanning_alerts",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
## Summary
This makes jaffascript's own task runner a **`jaffa` just module**, the
option the owner chose on 2026-10-09.
The repo root held two justfiles: `Justfile` (the RSR template, 1,545
lines) and `justfile` (jaffascript's 29-line runner for `affinescript …
--face jaffa`). As a result:
- A bare `just` in the root failed with `error: multiple candidate
justfiles found … Justfile and justfile` (rc 1).
- A case-insensitive checkout (Windows, macOS) keeps only one of the two
files.
- The recipe names `default`, `run`, `build` and `lint` exist in both
files, so a plain `import` would collide.
A module keeps the two sets of recipes apart. jaffa's recipes now run as
`just jaffa <recipe>`.
## Changes
- **`justfile` → `jaffa.just`** (git sees a rename). Two lines change:
- The header comment now names the file and how to run it.
- `default` now runs `@just --list jaffa`. It used to run `@just
--list`, which inside a module lists the *root* Justfile's ~100 template
recipes instead of jaffa's own.
- **`Justfile` and `.machine_readable/contractiles/Justfile`** (still
byte-identical, checked with `cmp`): `mod? jaffa "jaffa.just"` plus a
one-line comment, right after the existing `import? "contractile.just"`.
- The module is optional (`mod?`), for the same reason that import is
optional. The contractiles copy sits in a directory without `jaffa.just`
and must still parse.
- The cost: if `jaffa.just` is ever deleted, `just jaffa …` reports an
unknown recipe instead of a missing module file.
- **`README.adoc`**: the "via the justfile" example now reads `just
jaffa run …` / `just jaffa preview …`.
- **`EXPLAINME.adoc`**: the file-table row is now `jaffa.just`, run as
`just jaffa <task>`, and adds `hello`.
- **`.github/CONTRIBUTING.md:18`**: `just check` → `just jaffa check
examples/hello.affine`. The old line could not work: there is no root
`check` recipe, and jaffa's `check` takes a file.
- **`.editorconfig` `[justfile]` → `[*.just]`**, and **`.gitattributes`
`justfile` → `*.just`**. Both now also cover `contractile.just`. On
`main` that file got `text=auto eol=lf` from the catch-all rule; it now
gets `text eol=lf`. Its index and working-tree endings are LF either way
(`git ls-files --eol`: `i/lf w/lf`).
### Not changed
- **`docs/AFFIRMATION.adoc:202-204, 246` and
`docs/affirmations/AFFIRMATION-2026-10-07.adoc:182-184, 218`.** These
signed AFFIRMATIONs say "`just` cannot run here" because of the two
justfiles. Once this merges, that statement describes the repo as it was
when it was signed. Re-affirming is the owner's decision, so agents do
not edit them.
- `.machine_readable/STATE.a2ml` mentions the justfile, but A2ML is
retired, so it is untouched.
- Generic "use `just` (justfile)" lines in
`.machine_readable/ai/.{cline,cursor,windsurf}rules` and
`docs/practice/AI-CONVENTIONS.adoc`, and `ROADMAP.adoc:14` (a completed
item). Each is still true.
- `setup.sh:199` accepts either `Justfile` or `justfile`. `Justfile`
still exists.
## 📌 New pins
- **Head SHA: `900179b45003b4f42179b1145c68c5fabe786189`**
- None. No action `uses:`, `actions.lock`, lockfile or container digest
is added or changed.
## RSR Quality Checklist
### Required
- [ ] Tests pass: n/a, no source or test changed. Each recipe was run
(see Testing).
- [ ] Code is formatted: `just --summary` parses both Justfiles and
`jaffa.just`. There is no separate just formatter gate here.
- [x] Linter is clean: `asciidoctor --failure-level=WARN` passes on both
edited `.adoc` files.
- [x] No banned language patterns: nothing added.
- [ ] No `unsafe` blocks: n/a, no Rust changed.
- [ ] No banned functions: n/a, no source or proofs changed.
- [x] SPDX license headers present: `jaffa.just` keeps `MPL-2.0`. Every
other edited file keeps its existing header.
- [x] No secrets, credentials, or `.env` files.
### As Applicable
- [ ] `.machine_readable/*.a2ml`: no. A2ML is retired.
- [x] Documentation updated: `README.adoc`, `EXPLAINME.adoc`,
`.github/CONTRIBUTING.md`.
- [ ] `TOPOLOGY.md`: n/a.
- [ ] `CHANGELOG`: not updated, because it is a task-runner rename.
- [ ] New dependencies: none.
- [ ] ABI/FFI: n/a.
## Testing
All runs used just 1.56.0 and affinescript 0.1.1, in this worktree at
`900179b`. "Main" means `main` at `809e521`.
| Command | Main | This head |
|---|---|---|
| `just --list` (bare, root) | **rc 1**, `multiple candidate justfiles
found` | rc 0. The listing includes `jaffa ...` |
| `just jaffa` (module `default`) | n/a | rc 0. Lists only the 7 jaffa
recipes |
| `just jaffa check examples/hello.affine` | n/a | rc 0, `Type checking
passed` (runs `affinescript check --face jaffa …`) |
| `just jaffa hello` | `just --justfile justfile hello`: **rc 124**,
`Runtime error: Unhandled effect: println` | **rc 124**, identical |
| `just --justfile .machine_readable/contractiles/Justfile --summary` |
n/a | rc 0 (the `mod?` is skipped there) |
| `just validate-rsr` | only as `just --justfile Justfile validate-rsr`:
rc 1, `MISSING:` the 3 retired `.a2ml` paths | runs bare: rc 1, the same
3 paths. Unchanged; the recipe predates the A2ML retirement |
- **`just jaffa hello` fails on `main` too.** The failure is the
affinescript 0.1.1 interpreter not handling the `println` effect, not
this change. It is reported separately.
- **No conflict with #78:** `git merge-tree --write-tree` of this head
with #78's head (`ac2edb2`) exits 0. Positive control: a planted
conflicting edit to `.github/workflows/governance.yml` makes it exit 1.
- **Docstrings:** standards `.githooks/docstring-scan.sh --range
origin/main..HEAD --check` finds 0 touched functions.
## Red checks on this head
_Filled in once the checks report._
## Screenshots
n/a, no UI change.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>



Summary
This finishes the pin fix that #73 started. It moves the four
hyperpolymath/standardsreusable-workflow pins from900c42c7to2e12b312, the merge commit of hyperpolymath/standards#1209. That makesgovernance / Actions lockfile verifypass again; it is red onmain(809e521).Why it is red on
main. #73 restored block YAML so the actions-lock gate can read the pins, but it merged with the pins still at900c42c7. At that SHA the gate step runs underbash -e. A barebash check-actions-lock-gate.shfollowed byrc=$?therefore kills the step when the gate exits 3 (missing-lock debt), beforercis read. The shrink-only ledger, which listshyperpolymath/jaffascript, never gets the chance to excuse that debt. standards#1209 reads the exit code with|| rc=$?, so the ledger is reached.Changes
.github/workflows/governance.yml,mirror.yml,scorecard.ymlandsecret-scanner.yml:@900c42c70b968e11a2bca04bf0ce050be5c286dc→@2e12b312b529c51f095ce3b22cd35968f5aba898..github/workflows/mirror.yml:23: the comment naming the SHA at which the seven secrets are "the callee's complete optional contract" now names2e12b312.mirror-reusable.ymlis byte-identical at the two SHAs, so the contract has not changed.Not changed
2e12b312. Converting these files to KYAML would break the gate again.actions.lockis added. jaffascript's missing lockfile is ledgered debt in standards.machine_readable/lock-allow.txt. Writing the lockfile and deleting that ledger line is separate work.📌 New pins
ac2edb24bb0287d5595bd4f19e53179947a04821hyperpolymath/standards/.github/workflows/governance-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898hyperpolymath/standards/.github/workflows/mirror-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@2e12b312b529c51f095ce3b22cd35968f5aba898All four resolve to no tag.
2e12b312is the merge commit of standards#1209 (2026-10-09T00:26:51Z), andgit merge-base --is-ancestor 2e12b312 origin/mainsucceeds in the standards clone, so the pin is on standardsmain. No lockfile record or container digest changes.RSR Quality Checklist
Required
actionlintpasses on all four files.actionlintexits 0 on the four edited workflows.unsafeblocks: n/a, no Rust changed..envfiles.As Applicable
.machine_readable/*.a2ml: no. A2ML is retired, and the project state is unchanged.TOPOLOGY.md: n/a.CHANGELOG: not updated, since this is a CI pin bump.Testing
What changed between the two pins:
git diff --stat 900c42c7 2e12b312over the whole standards tree touches three files:governance-reusable.yml(+7/−2, the fix),scripts/apply-tag-ruleset-canon.shand its test (#1210, not used by callers). The gate's own scripts (check-actions-lock-gate.sh,update-actions-lock.sh) and the ledgerlock-allow.txtare identical at both SHAs.Local replay of the gate step. I extracted the step body "Check locked or SHA-pinned actions" from
governance-reusable.ymlat each SHA withyq. I staged the gate scripts and ledger from the same SHA into.standards-lock/, then ran the body withbash -e(the runner's shell) against agit archiveof the caller tree, withGITHUB_REPOSITORY=hyperpolymath/jaffascript.900c42c7main809e521MISSING-LOCK DEBT (exit 3), the same error as the red job onmain(job 113610554625)2e12b312actions-lock debt is LEDGERED for hyperpolymath/jaffascript … 1 of 163 ledgered repositories2e12b312162 ledgered repositories; hyperpolymath/jaffascript is NOT among themThe first row reproduces the red job on
main. The third row shows the replay can still fail, so the pass in the second row comes from the ledger and not from a step that cannot fail.actionlinton the four edited workflows: exit 0.The real check is
governance / Actions lockfile verifyon this PR's head. Its result is listed under "Red checks" below.Red checks on this head
Outcome
Merged 2026-10-09T00:46:37Z as
4b6eecd. Onmain16fb94a,governance / Actions lockfile verifyis SUCCESS (job 113614527134).squabble verify-satisfied hyperpolymath/jaffascript 78at 00:50:55Z: exit 0, DONE, no agent items.refs/pull/78/mergeare all already open onmain(61), so PR-minus-main is empty. Planted control: an alert number added only to the PR set is reported.As read before merge
Read 2026-10-09T00:5xZ via
gh pr checks(GraphQL): 27 pass, 0 fail, 1 pending (governance / Exemption ratchet; it was skipped onmain).governance / Actions lockfile verifypasses (job 113612786336). The log showsactions-lock debt is LEDGERED for hyperpolymath/jaffascript (missing-lock only, gate exit 3)and1 of 163 ledgered repositories, the same as row 2 of the replay above.squabble verify-satisfied. GitHub REST rate-limited this session at 00:43Z, and those reads are REST-only.Screenshots
n/a, no UI change.
🤖 Generated with Claude Code
https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf