Skip to content

ci: declare least-privilege GITHUB_TOKEN permissions (re-anchors the salvageable delta of #71) - #72

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0dacb-metamanifold-webui
Sep 25, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0dacb-metamanifold-webui

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown

Summary

Re-anchors the one genuinely missing piece of PR #71 onto main, and documents why everything else in that PR is already here in newer form.

Why PR #71 cannot merge (measured, 2026-09-26)

  1. Wrong lineage → mergeable: CONFLICTING (DIRTY). The PR branch is built on the upstream parent's history (JoshuaJewell:main = ecefb1c is an ancestor; the PR = upstream + 3 commits). main here shares only the initial commit 7884553 with it — the exact fork↔upstream divergence documented in docs/integration/conflict-map-2026-09-25.md. A test merge surfaces 38 conflicting files (add/add: ci.yml, ui.yml, package.json, MetaManifold.jl, Execution.jl, tests, docs, binary bun.lock).
  2. Content is ~99% superseded. Of the PR's 319 changed files, 281 are byte-identical with main already (the migration was re-anchored earlier via 0e61f4f and siblings). Net of main, the PR branch has only +398 lines, and after filtering to lines the PR itself authored that main truly lacks:

Changes

  • .github/workflows/ci.yml: top-level permissions: contents: read plus job-level blocks on repo-hygiene and test (cicd-squabbler already declares its own). Mirrors ui.yml, which already has a top-level block, and the fix landed on PR Feat/stipple typed studies UI #71's branch.

Recommendation

Close #71 in favour of this PR (its remaining unique content would regress main); carry any future application changes to JoshuaJewell per the PR template's Base check.

Testing

  • npx js-yaml .github/workflows/ci.yml parses; permissions present at workflow level and on all jobs.
  • scripts/check-spdx.sh OK (291 files), scripts/check-format.sh OK (339 files), scripts/check-lint.sh advisory (bun not installed in sandbox).

Workflow- and job-level `permissions: contents: read` on ci.yml, mirroring the fix the PR #71 author landed on their branch (the two CodeQL 'Workflow does not contain permissions' alerts) and matching what ui.yml already declares.

This is the only line of PR #71's 319-file, +22,662-line change set that main does not already carry in newer or identical form; see the PR body for the full re-anchor analysis.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: ed0c5ef6-14f8-4e44-8d00-4b8e4ffa0c7d

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit e33e10f into main Sep 25, 2026
7 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0dacb-metamanifold-webui branch September 25, 2026 23:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant