fix(issues,setup): close #91 and #92; estate propagation runbook - #93
Merged
Merged
Conversation
- bug_report.yml: drop render: shell so every free-text field is the same plain textarea entry type; no content field is required any more (what happened / expected / repro / version all optional). Only the two attestation checkboxes still gate submission. - feature_request.yml: same treatment — all fields optional with a markdown preamble saying so. - add .github/SUPPORT.md — config.yml already references it; routes questions to Discussions and vulnerabilities to private advisories. Fixes #92 Signed-off-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
setup.sh now works straight after clone with only git + curl + bash: it installs just (prebuilt binary from casey/just releases) and the pinned Zig toolchain (tarball + sha256 from the ziglang.org release index, version read from .tool-versions) into a user-local dir — no sudo, cargo/brew/mise demoted to fallbacks — then runs just doctor. Safe to re-run; present tools are untouched. Justfile: 'just setup' no longer gates heal behind a passing doctor (a failing doctor aborted the recipe before the repair could run); both setup and heal delegate to ./setup.sh; doctor now requires Zig 0.15.2 (matching build.zig and mise pins, was 0.13) and lists podman as optional. Docs (SETUP.adoc, README, both quickstarts) name Approach 3 as the zero-prerequisite route and start the AI-assisted prompt from ./setup.sh so 'just: command not found' is unreachable. Fixes #91 Signed-off-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
- docs/ESTATE-PROPAGATION.adoc: owner runbook for rolling the fixed issue forms and check-suite health verification across the hyperpolymath (user) and metadatastician (org) estates — estate .github default health files, per-repo PRs, template-source fix, plus the silent startup_failure failure mode (empty Actions allow-list) and a verification sweep. - scripts/propagate-github-templates.sh: gh-driven dry-run/apply rollout of the canonical issue forms as per-repo PRs. - CHANGELOG.adoc bullets for #91/#92 and these additions; docs/README.md index updated. Signed-off-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 25, 2026 20:37
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 25, 2026
hyperpolymath
added a commit
that referenced
this pull request
Sep 25, 2026
Post-merge residue of #93: replaces the single-iteration label loop in `scripts/propagate-github-templates.sh` (shellcheck SC2043 — the one issue CodeFactor flagged on the #93 squash commit) with a direct best-effort call. No behavioural change. Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 25, 2026
## What Follow-up to #95. Governance on main (f4e49a7) now passes `Check SPDX headers + permissions` ✅ but fails one step later: ``` ::error::1 of 20 action pin(s) DO NOT EXIST upstream. NOT-ANCESTOR hyperpolymath/standards@892497f (compare main → diverged) ``` **Root cause (a real, determinate negative — not a flake):** `892497fe`, the pin on `secret-scanner.yml`'s reusable workflow, is a real commit object but **not an ancestor of `standards/main`** (orphan — squash-merge residue / PR-head lineage). GitHub's resolver only accepts reusable-workflow commits reachable from the default branch, so: - **every Secret Scanner run** (push *and* PR) fails at graph resolution with 0 jobs — the "This run likely failed because of a workflow file issue" rows red on main since at least #93; - the estate's updated pin gate (standards\@main, now run by Governance's linter) determinately fails on it. standards issue #782 documents this class: *four such SHAs (7fdc2705…, **892497fe**…, 46960521…, 5b1d0022…) account for 61 dead workflow-run rows with ZERO alive rows* — aerie's secret-scanner pin is literally one of the named four. ## Fix Repin to `e13e2ea3dbbc9c7815e39c3749b4480514f555a6` — the newest commit on `standards/main` touching the reusable (2026-09-19, standards #867): - **ancestry verified**: `compare/main...e13e2ea3` → `behind` (ancestor) — the same predicate the gate applies; - **strict superset** of the orphan's content: estate gitleaks baseline wiring, full-history gating pass (`fetch-depth: 0` + shallow-assert), `--verbose` findings, repo-local config resolution. Per the gate's own guidance: repin to a merge commit **on** the default branch, never a PR head. ## Verification (local, CI script versions) | Gate | Result | |---|---| | `check-action-pins-resolve.sh` (standards\@main — what CI runs) | ✅ 20/20 | | SPDX + permissions | ✅ | | duplicate keys | ✅ 17 clean | | workflow parse | ✅ 25 | ## Expected effect after merge - **Governance** → green (linter completes: SPDX ✓ → pin-resolve ✓ → dup-workflows ✓). - **Secret Scanner** → schedules jobs for the first time (was unresolvable at graph resolution). Note: Label Triage / Pages / Mirror / SonarQube remain owner-token items (allow-list, secrets) — see `docs/REPO-SETTINGS.adoc` §3/§9. --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Addresses the two remaining open issues and lands the estate propagation instruction.
#92 — issue template has inconsistent entry fields
.github/ISSUE_TEMPLATE/bug_report.yml: removedrender: shellfrom What happened — every free-text field is now the same plain textarea entry type. No content field is required any more (what happened / expected / repro / version all optional); only the two attestation checkboxes still gate submission..github/ISSUE_TEMPLATE/feature_request.yml: all fields optional, same preamble. Irrelevant fields can simply be left blank on both forms..github/SUPPORT.md(the existingconfig.ymlalready referenced it).#91 — dependency installation not guaranteed across setup paths
setup.shrewritten as the guaranteed zero-prerequisite path: with only git + curl + bash it installsjust(prebuilt binary, latest release orJUST_VERSIONpin) and the pinned Zig toolchain (tarball + sha256 from the ziglang.org release index; version read from.tool-versions) into a user-local dir — no sudo; cargo/brew/mise demoted to fallbacks — then runsjust doctor. Safe to re-run.Justfile:just setupno longer gateshealbehind a passingdoctor(a failing doctor aborted the recipe before repair could run);setupandhealdelegate to./setup.sh;doctornow requires Zig 0.15.2 (matching build.zig/mise pins, was 0.13) and lists podman as optional.docs/SETUP.adoc,README.md,QUICKSTART-DEV/USER.adoc) name Approach 3 as the zero-prerequisite route and start the AI-assisted prompt from./setup.sh, sojust: command not foundis unreachable.Estate propagation instruction (follow-on)
docs/ESTATE-PROPAGATION.adoc: owner runbook for rolling the fixed issue forms and check-suite health verification across the hyperpolymath (user) and metadatastician (org) estates — estate.githubdefault health files, per-repo PRs, template-source fix (rsr-template-repo), the silentstartup_failurefailure mode (empty Actions allow-list), and a weekly sweep workflow.scripts/propagate-github-templates.sh: gh-driven--dry-run/--applyrollout of the canonical issue forms as per-repo PRs (owner token needed; not executed by this PR).Testing
setup.sh: end-to-end with stubbed fixtures — installs just + zig, checksum verification, symlink, PATH guidance, doctor hand-off; graceful degradation when ziglang.org is unreachable (manual hint, doctor still runs); idempotent on re-run. Asset naming verified against the live casey/just 1.58.0 release and the ziglang.org download index for 0.16.0 (0.14+ arch-first naming).render:, exactly 2 required items = the attestation pair).Fixes #91
Fixes #92