Skip to content

fix(ci): repin secret-scanner off orphan SHA - #96

Merged
hyperpolymath merged 3 commits into
mainfrom
arena/01a0da6f-aerie
Sep 25, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
arena/01a0da6f-aerie

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

What

Follow-up to #95. Governance on main (f4e49a7) now passes Check SPDX headers + permissions ✅ but fails one step later:

::error::1 of 20 action pin(s) DO NOT EXIST upstream.
  NOT-ANCESTOR    hyperpolymath/standards@892497fe373744874316710966b81ae6f0ea9e66  (compare main → diverged)

Root cause (a real, determinate negative — not a flake): 892497fe, the pin on secret-scanner.yml's reusable workflow, is a real commit object but not an ancestor of standards/main (orphan — squash-merge residue / PR-head lineage). GitHub's resolver only accepts reusable-workflow commits reachable from the default branch, so:

  • every Secret Scanner run (push and PR) fails at graph resolution with 0 jobs — the "This run likely failed because of a workflow file issue" rows red on main since at least fix(issues,setup): close #91 and #92; estate propagation runbook #93;
  • the estate's updated pin gate (standards@main, now run by Governance's linter) determinately fails on it.

standards issue #782 documents this class: four such SHAs (7fdc2705…, 892497fe…, 46960521…, 5b1d0022…) account for 61 dead workflow-run rows with ZERO alive rows — aerie's secret-scanner pin is literally one of the named four.

Fix

Repin to e13e2ea3dbbc9c7815e39c3749b4480514f555a6 — the newest commit on standards/main touching the reusable (2026-09-19, standards #867):

  • ancestry verified: compare/main...e13e2ea3 → behind (ancestor) — the same predicate the gate applies;
  • strict superset of the orphan's content: estate gitleaks baseline wiring, full-history gating pass (fetch-depth: 0 + shallow-assert), --verbose findings, repo-local config resolution.

Per the gate's own guidance: repin to a merge commit on the default branch, never a PR head.

Verification (local, CI script versions)

Gate Result
check-action-pins-resolve.sh (standards@main — what CI runs) ✅ 20/20
SPDX + permissions ✅
duplicate keys ✅ 17 clean
workflow parse ✅ 25

Expected effect after merge

  • Governance → green (linter completes: SPDX ✓ → pin-resolve ✓ → dup-workflows ✓).
  • Secret Scanner → schedules jobs for the first time (was unresolvable at graph resolution).

Note: Label Triage / Pages / Mirror / SonarQube remain owner-token items (allow-list, secrets) — see docs/REPO-SETTINGS.adoc §3/§9.

hyperpolymath and others added 2 commits September 25, 2026 21:28
Two independent reds on main at cb2b475, both reproduced locally with
the exact pinned tooling before fixing:

- Dogfood Gate "Validate DEED manifests": deed-ecosystem validate-action
  errored on tests/idris2/{depends,diagnosticity}.a2ml — missing
  required identity field. Both are corpus metadata docs (README.adoc);
  add name + version so the validator exits 0 (0 errors, warnings down
  6 → 4, all advisory in non-strict mode).

- Governance "Workflow security linter": .github/workflows/build.yml
  had neither a SPDX header comment block nor a top-level permissions:
  declaration — both required by standards governance-reusable
  (092deda). Add the standard estate header + contents: read.

Drive-bys in the Dogfood summary steps (same failed workflow): the
scorecard row and manifest-count line read the never-set A2ML_STATUS /
A2ML_COUNT instead of DEED_STATUS / MANIFEST_COUNT (empty cells), and
the empty-K9 branch printed the missing-DEED text.

Gates re-run locally after the fix, all green: SPDX+permissions scan,
duplicate-key check (17 workflows clean), workflow parse, action-pin
resolve (20/20 upstream), A2ML validator (0 errors).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The pinned secret-scanner-reusable.yml@892497fe is a real commit object
but NOT an ancestor of hyperpolymath/standards' default branch (compare
main -> diverged). The resolver cannot reach it, so every Secret Scanner
run fails at graph resolution with zero jobs ("workflow file issue" on
both push and PR), and the estate's updated pin gate fails Governance's
"Check action pins resolve upstream" on it: 1 of 20 NOT-ANCESTOR
(standards issue #782 — 61 dead estate rows traced to four such SHAs,
892497fe among them).

Repin to e13e2ea3, the newest commit on standards/main touching the
reusable (2026-09-19, standards #867): verified ancestor
(compare main...sha = behind) and a strict superset of the orphan's
content — estate gitleaks baseline wiring, full-history gating pass,
--verbose findings.

Gates re-run locally against the CI script versions, all green: pin
resolve 20/20 (check-action-pins-resolve.sh from standards@main),
SPDX+permissions, duplicate keys (17 clean), workflow parse.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 8a11daab-bf68-4937-b8ba-0ff1552eb491

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor Author

Why the Actions checks aren't showing on this PR (diagnosis, not a PR defect)

All pull_request-event workflow runs since 2026-09-25 20:37Z complete as startup_failure with 0 jobs (this PR, #95, #94, and the concurrent 01a0da31 branch), while push runs in the same minutes schedule and run normally (0b8d9cb @20:39, cb2b475 @20:49, f4e49a7 @21:30 — Dogfood Gate green on f4e49a7 ✅).

Evidence that this is not a repo/allow-list problem

When Event Workflow files Result
Sep 24 14:04 (aspect-weave) pull_request unchanged jobs ran
Sep 25 14:25 (weave-p2) pull_request unchanged jobs ran
Sep 25 20:37→ pull_request unchanged 0-job startup_failure
Sep 25 20:39 / 20:49 / 21:30 push same workflows jobs ran

A refused uses: in the Actions allow-list would fail both events equally (the resolver is event-agnostic) — push works, so the allow-list is not refusing these actions. Same registered workflow IDs on dead and alive runs (256189032 for Dogfood), so this is not the synthetic/ghost-workflow routing either. Matches the September-2026 platform class of zero-job startup_failure runs (community discussions #207628, #206702, #207492, #207900; corroboration: Z-Solo-King/foundation#263).

What to do

  • Don't read this PR's empty Actions check list as a repo failure — third-party checks (CodeFactor, CodeRabbit, GitGuardian, semgrep, Codeac) are green; mergeStateStatus: CLEAN.
  • If PR checks are needed before merge: push an empty commit / close-reopen to re-trigger, or wait for platform recovery.
  • Verification of this PR's content happens on the push to main after merge (push events currently schedule): expect Governance green (linter passes SPDX → pin-resolve 20/20 → dup-workflows) and Secret Scanner finally scheduling jobs (the orphan pin 892497fe was unreachable from standards/main — now repinned to ancestor e13e2ea3).
  • docs/REPO-SETTINGS.adoc §9's allow-list reading should be re-verified with the owner token (bots get 403 on actions/permissions), but the current PR-event deaths don't match that signature.

@hyperpolymath
hyperpolymath merged commit 16af460 into main Sep 25, 2026
8 of 10 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0da6f-aerie branch September 25, 2026 21:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant