Skip to content

ci: restore block YAML until the gates read KYAML - #26

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/workflow-block-yaml
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/workflow-block-yaml

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

Restores block-style formatting of .github/workflows/comprehensive-quality.yml. #25 removed this repo's duplicate Semgrep scan and, in the same PR, rewrote the file as KYAML. The KYAML form turned two gates red that read only block YAML:

  • governance / Workflow security linter: its duplicate-key check comes from standards@317101e0 (2026-09-14). Flow-document support landed later, in standards 13b872c1 (2026-10-01), so the old copy reads every step's name:/run: as a repeat of the previous one and reports phantom duplicates.
  • lint-workflows (this repo's workflow-linter.yml), where present: it checks for top-level permissions with grep -q "^permissions:". KYAML indents that key inside {, so the check fails although the permissions are declared.

The parsed workflow is unchanged, so behaviour does not change. KYAML conversion waits until both gates read it.

Follow-up to #25.

Type of change

  • 🐛 Bug fix: no code change; this clears CI reds the earlier reformat caused.
  • ✨ New feature: n/a
  • 💥 Breaking change: no
  • 🕳️ Soundness fix: n/a
  • 📖 Documentation: n/a
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance: n/a
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: 54cd2a4c52d193a33b6b1010a0c85f9a0c227761. No pins added or changed.

How has this been verified?

  • yq -o json 'sort_keys(..)' on main @ 96b6620 and on this head: identical data.
  • The current standards duplicate-key checker passes this file. A planted duplicate in a KYAML copy is still caught (rc=1), so the KYAML file was clean and the old checker was wrong.
  • grep -c '^permissions:' = 1 (was 0 in the KYAML form).
  • actionlint: same diagnostics as the pre-ci: remove per-repo Semgrep scan (the Semgrep Code app covers PRs) #25 file.
  • No uses: ref changes, so actions.lock is unaffected.

Checklist

  • My commits are signed (verified G).
  • I ran the project's own checks/tests locally and they pass: the checks above. This is formatting only.
  • New files carry the correct SPDX identifier: n/a, no new files.
  • Docs are updated, and no public claim now overstates what the code does: nothing to update.
  • I have not introduced a soundness hole.

Notes for reviewers

Formatting only. The data-identity check is the whole claim.

Pre-existing reds on main (not caused by this PR)

Each red check on this head, with its most recent conclusion on main (up to 15 commits back). Owner ruling 2026-10-08: these are logged in dev-notes/inbox/findings.md, with no new issues (D273).

Check Latest on main
build failure@3fc4aad
governance / Actions lockfile verify failure@3fc4aad
governance / Check Workflow Staleness failure@3fc4aad
governance / Licence consistency failure@3fc4aad
governance / Well-Known (RFC 9116 + RSR) failure@3fc4aad
governance / Workflow security linter failure@3fc4aad
SonarCloud Code Analysis failure@3fc4aad

Hypatia review threads were answered and resolved: every flagged line exists unchanged on main from before the Semgrep PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM

Undoes the KYAML rewrite that landed with the Semgrep removal. The
parsed workflow is identical to main; only the formatting changes.

The KYAML form turned two gates red that read only block YAML: the
governance duplicate-key check, pinned to standards@317101e0 from before
its flow-document support (13b872c1), and the workflow linter grep for
a column-0 `permissions:` key. Converting waits until both read KYAML.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 31 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 0e0c6829-b59e-4b6d-9f82-ea5871dfaf59
📥 Commits

Reviewing files that changed from the base of the PR and between 96b6620 and 54cd2a4.

📒 Files selected for processing (1)
  • .github/workflows/comprehensive-quality.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@hyperpolymath
hyperpolymath merged commit 3fc4aad into main Oct 8, 2026
22 of 30 checks passed
@hyperpolymath
hyperpolymath deleted the chore/workflow-block-yaml branch October 8, 2026 11:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant