From 3ba17372a90bc773cee486345eb031e5a5e15dc1 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 19:11:26 +0100 Subject: [PATCH 1/3] fix(ci): repoint standards reusables to main HEAD and grant actions:read The governance suite was dying at startup on this repo: scorecard, mirror and secret-scanner each reported 0 jobs and 0 check runs, so main looked green because the gates were ABSENT, not passing. Two causes, both fixed here: 1. Callers sat on older standards pins (7fdc2705, 892497fe) whose reusables request `actions: read`, which the callers did not grant. 2. A job-level `permissions:` block REPLACES the workflow-level map rather than merging with it, so scorecard's job ran with neither `contents: read` nor `actions: read` regardless of the workflow-level grant. All five callers are repointed to standards main HEAD 257869d3 and now grant `actions: read` + `contents: read` at BOTH workflow and job level. Verified: every *-reusable.yml referenced exists at 257869d3. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QMTyDv9CoJo5PfeNzyp519 --- .github/workflows/elixir-ci.yml | 3 ++- .github/workflows/governance.yml | 2 +- .github/workflows/mirror.yml | 3 ++- .github/workflows/scorecard.yml | 5 ++++- .github/workflows/secret-scanner.yml | 4 +++- 5 files changed, 12 insertions(+), 5 deletions(-) diff --git a/.github/workflows/elixir-ci.yml b/.github/workflows/elixir-ci.yml index 20a484c..a6e1bb6 100644 --- a/.github/workflows/elixir-ci.yml +++ b/.github/workflows/elixir-ci.yml @@ -15,11 +15,12 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: elixir-ci: - uses: hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@892497fe373744874316710966b81ae6f0ea9e66 + uses: hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a with: otp-version: "27.2.1" elixir-version: "1.18.2" diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 026822a..158ed04 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -32,4 +32,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fad242d35291de1898242d6737ba02b74a59a2f2 + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 68c4f3d..9bce625 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -7,9 +7,10 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@892497fe373744874316710966b81ae6f0ea9e66 + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b1c4cc9..c736b43 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -7,6 +7,7 @@ on: - cron: '23 4 * * 1' permissions: + actions: read contents: read security-events: write id-token: write @@ -14,7 +15,9 @@ permissions: jobs: analysis: permissions: + actions: read + contents: read security-events: write id-token: write - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 7ccae92..043df99 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -11,11 +11,13 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: scan: permissions: + actions: read contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@892497fe373744874316710966b81ae6f0ea9e66 + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit From 987bd44a27b693bb4c622f9d6aed0a4702d981f5 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 19:17:15 +0100 Subject: [PATCH 2/3] fix(ci): hold governance at fad242d3 until standards#754 lands standards main HEAD (257869d3) cannot be parsed by a caller: its actions.lock is out of sync with governance-reusable.yml after Dependabot PR #746, so a caller pinning it gets HTTP 422 and dies at startup with zero jobs. hyperpolymath/standards#754 resyncs the lockfile. Until it merges, governance stays on fad242d3 - the pin with a verified green 15-job run. The other four callers move to main HEAD, which parses cleanly (mirror verified: 7 jobs, was 0). Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QMTyDv9CoJo5PfeNzyp519 --- .github/workflows/governance.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 158ed04..026822a 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -32,4 +32,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fad242d35291de1898242d6737ba02b74a59a2f2 From b2f3e1e9241b606ef7b4a1de8df89fb45bdd1f50 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 19:21:18 +0100 Subject: [PATCH 3/3] ci(scorecard): add workflow_dispatch so the gate can be verified on demand scorecard.yml triggered only on branch_protection_rule and schedule, so there was no way to prove the startup-failure repair works before merging it. The canonical template caller (proof-burrower, the verified-working control) carries workflow_dispatch; this matches it. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QMTyDv9CoJo5PfeNzyp519 --- .github/workflows/scorecard.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index c736b43..d05b79e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -2,6 +2,7 @@ name: Scorecards supply-chain security on: + workflow_dispatch: branch_protection_rule: schedule: - cron: '23 4 * * 1'