fix(ci): repin secret-scanner off orphan SHA - #96
Conversation
Two independent reds on main at cb2b475, both reproduced locally with the exact pinned tooling before fixing: - Dogfood Gate "Validate DEED manifests": deed-ecosystem validate-action errored on tests/idris2/{depends,diagnosticity}.a2ml — missing required identity field. Both are corpus metadata docs (README.adoc); add name + version so the validator exits 0 (0 errors, warnings down 6 → 4, all advisory in non-strict mode). - Governance "Workflow security linter": .github/workflows/build.yml had neither a SPDX header comment block nor a top-level permissions: declaration — both required by standards governance-reusable (092deda). Add the standard estate header + contents: read. Drive-bys in the Dogfood summary steps (same failed workflow): the scorecard row and manifest-count line read the never-set A2ML_STATUS / A2ML_COUNT instead of DEED_STATUS / MANIFEST_COUNT (empty cells), and the empty-K9 branch printed the missing-DEED text. Gates re-run locally after the fix, all green: SPDX+permissions scan, duplicate-key check (17 workflows clean), workflow parse, action-pin resolve (20/20 upstream), A2ML validator (0 errors). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The pinned secret-scanner-reusable.yml@892497fe is a real commit object
but NOT an ancestor of hyperpolymath/standards' default branch (compare
main -> diverged). The resolver cannot reach it, so every Secret Scanner
run fails at graph resolution with zero jobs ("workflow file issue" on
both push and PR), and the estate's updated pin gate fails Governance's
"Check action pins resolve upstream" on it: 1 of 20 NOT-ANCESTOR
(standards issue #782 — 61 dead estate rows traced to four such SHAs,
892497fe among them).
Repin to e13e2ea3, the newest commit on standards/main touching the
reusable (2026-09-19, standards #867): verified ancestor
(compare main...sha = behind) and a strict superset of the orphan's
content — estate gitleaks baseline wiring, full-history gating pass,
--verbose findings.
Gates re-run locally against the CI script versions, all green: pin
resolve 20/20 (check-action-pins-resolve.sh from standards@main),
SPDX+permissions, duplicate keys (17 clean), workflow parse.
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Why the Actions checks aren't showing on this PR (diagnosis, not a PR defect)All Evidence that this is not a repo/allow-list problem
A refused What to do
|
What
Follow-up to #95. Governance on main (f4e49a7) now passes
Check SPDX headers + permissions✅ but fails one step later:Root cause (a real, determinate negative — not a flake):
892497fe, the pin onsecret-scanner.yml's reusable workflow, is a real commit object but not an ancestor ofstandards/main(orphan — squash-merge residue / PR-head lineage). GitHub's resolver only accepts reusable-workflow commits reachable from the default branch, so:standards issue #782 documents this class: four such SHAs (7fdc2705…, 892497fe…, 46960521…, 5b1d0022…) account for 61 dead workflow-run rows with ZERO alive rows — aerie's secret-scanner pin is literally one of the named four.
Fix
Repin to
e13e2ea3dbbc9c7815e39c3749b4480514f555a6— the newest commit onstandards/maintouching the reusable (2026-09-19, standards #867):compare/main...e13e2ea3→behind(ancestor) — the same predicate the gate applies;fetch-depth: 0+ shallow-assert),--verbosefindings, repo-local config resolution.Per the gate's own guidance: repin to a merge commit on the default branch, never a PR head.
Verification (local, CI script versions)
check-action-pins-resolve.sh(standards@main — what CI runs)Expected effect after merge
Note: Label Triage / Pages / Mirror / SonarQube remain owner-token items (allow-list, secrets) — see
docs/REPO-SETTINGS.adoc§3/§9.