ci: declare least-privilege GITHUB_TOKEN permissions (re-anchors the salvageable delta of #71) - #72
Merged
Conversation
Workflow- and job-level `permissions: contents: read` on ci.yml, mirroring the fix the PR #71 author landed on their branch (the two CodeQL 'Workflow does not contain permissions' alerts) and matching what ui.yml already declares. This is the only line of PR #71's 319-file, +22,662-line change set that main does not already carry in newer or identical form; see the PR body for the full re-anchor analysis. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 25, 2026 23:21
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Re-anchors the one genuinely missing piece of PR #71 onto
main, and documents why everything else in that PR is already here in newer form.Why PR #71 cannot merge (measured, 2026-09-26)
mergeable: CONFLICTING(DIRTY). The PR branch is built on the upstream parent's history (JoshuaJewell:main=ecefb1cis an ancestor; the PR = upstream + 3 commits).mainhere shares only the initial commit7884553with it — the exact fork↔upstream divergence documented indocs/integration/conflict-map-2026-09-25.md. A test merge surfaces 38 conflicting files (add/add: ci.yml, ui.yml, package.json, MetaManifold.jl, Execution.jl, tests, docs, binarybun.lock).mainalready (the migration was re-anchored earlier via0e61f4fand siblings). Net ofmain, the PR branch has only +398 lines, and after filtering to lines the PR itself authored thatmaintruly lacks:src/analysis/Execution.jl(124 lines): stub/mock code (“Mock p-value”, “Real implementation would call R…”) — replaced onmainby the real statistics layer (feat(analysis): exact descriptive summaries (catalogue item 1) #57–fix(analysis): read R's NA as missing so parametric fits run #66).mainimplemented exact TSS/CSS/RSS offsets in feat(analysis): exact TSS/CSS/RSS offsets, and no silent substitutions #61.main's (Dependabot keepsmainat checkout v7.0.1 / setup-julia v3.0.2 …).<dialog>withshowModal()(Two overlay modals have no dialog semantics: role="presentation" stands in for a native <dialog> #32), which supplies Escape/role/focus-trap natively.lint_source.jlundeclared-deps, Justfile bootstrap/setup-full, coupling test — all present onmainin deliberately newer forms.6b481a3,eab8ea0), and that piece is whatmainwas still missing.Changes
.github/workflows/ci.yml: top-levelpermissions: contents: readplus job-level blocks onrepo-hygieneandtest(cicd-squabbleralready declares its own). Mirrorsui.yml, which already has a top-level block, and the fix landed on PR Feat/stipple typed studies UI #71's branch.Recommendation
Close #71 in favour of this PR (its remaining unique content would regress
main); carry any future application changes toJoshuaJewellper the PR template's Base check.Testing
npx js-yaml .github/workflows/ci.ymlparses;permissionspresent at workflow level and on all jobs.scripts/check-spdx.shOK (291 files),scripts/check-format.shOK (339 files),scripts/check-lint.shadvisory (bun not installed in sandbox).