fix(ci): satisfy the Actions allow-list so workflows can start (+ provenance probe visibility) - #85
Merged
Merged
Conversation
main was rewritten to a new root (4c2c79e, PR #83) that shares no history with the revision this audit was written against (4a848da), and the audited code moved: Execution.jl +125/-60, estimation.jl +231/-29. ilr_basis.jl, analysis.jl, provenance.jl and bench/ilr_bases/benchmark.jl are byte-identical, so their citations are untouched. Re-verifies all 21 findings against the new tree -- the four headline ones (M3 dead clr_table, M4 redundant copies, N1 mixed healing scales, W1 is_dangerous not updated on :not_run) by reading the new code rather than trusting the old line numbers -- and re-locates every citation into the two files that moved. Also corrects the catalogue for work that landed after the audit: glmGamPoi dispersion is now a pure-Julia port (SUPPORTED_DISPERSION gains "glmgampoi"; only local/mean/pooled remain refused), so estimation.dispersion_refused no longer says "use parametric" for it. Adds three entries: the port itself, its unported spline abundance trend, and its pass-1 fallback; and records in the audit that two pure-Julia kernels now exist, which bears on question 10 without changing the gate (CI still has no verdict on any of this code). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Every workflow run since 2026-09-25 22:19 UTC failed with startup_failure and zero jobs. The run annotations name two enforcement rules, neither of which a running job could ever have reported: * actions must be from a repository owned by hyperpolymath, created by GitHub, verified in the GitHub Marketplace, or match the configured pattern -- julia-actions/setup-julia, julia-actions/cache and julia-actions/julia-processcoverage match none of those; * all actions must be pinned to a full-length commit SHA -- the Proofs workflow still used @v4/@v5 tag refs. Changes, one per violation, with behaviour preserved: * ci/ui/doi: julia-actions/setup-julia replaced by an inline install of the official 1.12.5 binaries, verified against the official checksum file before use; JULIA_VERSION keeps the pin that test/unit/test_install_pins.jl compares against tool_versions.yml and Manifest.toml; * ci/ui/doi: julia-actions/cache replaced by actions/cache at 55cc834 (v6.1.0) over the same depot directories, keyed on the workflow's own Manifest/Project pair; * ci: julia-actions/julia-processcoverage replaced by the equivalent CoverageTools invocation (same default directories, same lcov.info); * proofs: checkout/setup-python/cache/upload-artifact pinned to the commits their existing tags pointed at, so behaviour is unchanged. test/unit/test_install_pins.jl locates the Julia pin by step name now, and a new testset walks every workflow and fails on any action that is not full-SHA-pinned and allow-listed, so a future dependabot bump to a tag or an unverified owner reddens Pkg.test instead of silencing Actions. Validated offline: YAML parse + duplicate-key scan of all four workflows, policy self-check mirroring the new testset, bash -n on every run block, JULIA_VERSION regex against the pin file. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The ExecutionManifest constructor swallowed probe_metamanifold and probe_host failures into OrderedDict(version=>unknown / hostname=>unknown) with no record of the refusal: a manifest that looks probed when it was not. Both catch blocks now emit @warn with the probe name and the error text before writing the placeholder, which is the audit's rule that every fallback stays visible (category: dependency_environment). The placeholder values themselves are unchanged, so the manifest schema and every existing assertion over it are untouched. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 27, 2026 05:16
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 27, 2026
arena-ai-coding-agent Bot
added a commit
that referenced
this pull request
Sep 27, 2026
) Follow-up to #85, which restored workflow startup. With CI alive again, the **Source lint** step (`config/ci/lint_source.jl`) produced its first verdict in two days and failed on two files it had never been able to run against — neither of them touched by #85: 1. **`test/doi/fixtures.jl`** uses the suite aliases `B`/`P`, which are `const` bindings defined in `tests.jl` before `include("fixtures.jl")`. The lint check is deliberately textual and per-file, so an alias supplied by the includer is invisible to it. The three call sites (`B.write_checksums!`, `P.prepare!`, `P.publish!`) now go through `Target.DOIBundles` / `Target.DOIPublications` — the same bindings at runtime (tests.jl defines them from `Target`), legible in isolation. 2. **`test/unit/test_zero_replacement.jl:215`** broadcast `Float64.(parse.(Float64, ...))` — the outer map is an identity (`parse` with a `Float64` target already yields `Float64`), and the `Float64.(` spelling matches the lint's `Module.member` pattern over test files. Removing the outer conversion changes no value. **Validation:** replayed the lint's textual checks (escaped interpolation, adjacent docstrings, bare-alias member refs, the `Float64.( pattern`) over both files — all clean. Julia itself isn't available in this sandbox, so the definitive gate is the CI Source lint step on this PR. **Known-red checks NOT addressed here** (pre-existing, not introduced by this change): repo-hygiene `tsc --noEmit` (frontend, likely #83-era), the stale apt-Agda 2.6.4.3 `Proofs (Agda)` job inside ci.yml (proofs.yml — the real gate — is green), and the DOI contracts job. Co-authored-by: arena-agent <arena-agent@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
Every workflow run on this repository since 2026-09-25 22:19 UTC has failed with
startup_failureand zero jobs — CI has produced no verdict on anything since (the refreshed audit indocs/audit/2026-09-26-memory-numerics-warning-audit.mdrecords the same observation). The run annotations name the cause; two rules, neither reportable by a job that never starts:ci.yml,ui.yml,doi.ymlused the three disallowedjulia-actions/*actions;proofs.ymlused tag refs (@v4/@v5) instead of full SHAs (its annotation from run 36293672919).Dependabot PR #68 (merged 2026-09-25 22:26) was not the cause — it only changed which ref each disallowed action used; the enforcement itself turned on at 22:19 and broke the arena-branch run five minutes before #68 merged.
What changed (behaviour preserved)
julia-actions/setup-juliaJULIA_VERSIONkeeps the pin cross-checked bytest_install_pinsjulia-actions/cacheactions/cache@55cc834(v6.1.0) over the same depot dirs, keyed on each workflow's own Manifest/Projectjulia-actions/julia-processcoverageCoverageToolsrun step (same default dirs, samelcov.info)checkout/setup-python/cache/upload-artifact@v4/@v5Plus two guards so this cannot regress silently:
test/unit/test_install_pins.jlnow locates the Julia pin by step name (JULIA_VERSION=inSet up Julia) and gains a new testset that walks every workflow and fails on any action that is not full-SHA-pinned or not allow-listed — a future dependabot bump to a tag reddensPkg.testinstead of silencing Actions;src/analysis/Execution.jl(the second commit) now@warnbefore writingversion=unknown/hostname=unknownplaceholders — the manifest schema and all existing assertions over it are untouched.Validation done offline
uses:full-SHA + allow-listed owner);bash -non everyrun:block;JULIA_VERSIONregex againstconfig/defaults/tool_versions.yml(1.12.5 = 1.12.5);sha256sum -cand/usr/local/bin/<tool>strings the pin tests assert on are still present.Known remaining (settings-side, not fixable from workflow files)
A run on this branch also reported
Actor is not allowed to trigger Actions workflows(run 36295388349) — the repository's actor allow-list appears to globarena-ai-coding-agent[bot](the[bot]read as a character class), so pushes made by the Arena bot may still be refused even with compliant workflow files. An admin needs to fix that pattern; runs triggered byhyperpolymathshould proceed once this merges.