diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e68b148..096c3e3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,10 +1,21 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# build.yml — SonarQube analysis on pushes to main and on PRs. +# The top-level permissions block is required by the estate workflow +# security linter (standards governance-reusable: SPDX headers + permissions). name: Build + on: push: branches: - main pull_request: types: [opened, synchronize, reopened] + +permissions: + contents: read + jobs: sonarqube: name: SonarQube diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index b97489e..b0f3e00 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -58,7 +58,7 @@ jobs: else echo "## DEED Manifest Validation" >> "$GITHUB_STEP_SUMMARY" echo "" >> "$GITHUB_STEP_SUMMARY" - echo "Scanned **${A2ML_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" + echo "Scanned **${MANIFEST_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" fi # --------------------------------------------------------------------------- @@ -100,7 +100,7 @@ jobs: cat <<'EOF' >> "$GITHUB_STEP_SUMMARY" ## K9 Contract Validation - :warning: **No .a2ml/.deed manifest files found.** Every RSR-compliant repo should have a repo deed (`_chora.deed`) at its root. + :warning: **No K9 contract files found.** Every RSR repo with config files should carry K9 contracts. Generate contracts with: `k9iser generate .` EOF @@ -396,7 +396,7 @@ jobs: | Tool/Format | Status | Notes | |-------------|--------|-------| - | DEED repo deed (`_chora.deed`) | ${A2ML_STATUS} | Required for all RSR repos | + | DEED repo deed (`_chora.deed`) | ${DEED_STATUS} | Required for all RSR repos | | K9 contracts | ${K9_STATUS} | Required for repos with config files | | .editorconfig | ${EC_STATUS} | Required for all repos | | Groove endpoint | ${GROOVE_STATUS} | Required for service repos | diff --git a/tests/idris2/depends.a2ml b/tests/idris2/depends.a2ml index 24f8db5..bc0b870 100644 --- a/tests/idris2/depends.a2ml +++ b/tests/idris2/depends.a2ml @@ -3,6 +3,9 @@ # yields exit 2 (VOID), and VOID propagates: a battery must reclassify any # green downstream of this unit's VOID as VOID. +name = "aerie-idris2-depends" +version = "1.0.0" + [upstream_units] value = "none — self-contained model suite; mirrors src/api/zig/{proof,policy}.zig invariants" diff --git a/tests/idris2/diagnosticity.a2ml b/tests/idris2/diagnosticity.a2ml index e048423..312df0d 100644 --- a/tests/idris2/diagnosticity.a2ml +++ b/tests/idris2/diagnosticity.a2ml @@ -1,6 +1,9 @@ # SPDX-License-Identifier: MPL-2.0 # Diagnosticity contract for the aerie model suite (tests/idris2). +name = "aerie-idris2-diagnosticity" +version = "1.0.0" + [detects] condition = "divergence between the aerie specification models (proof envelope well-formedness, policy-gate monotonicity, longest-prefix route matching) and their stated invariants" defect_class = "spec-model-drift"