Skip to content

chore(governance): stop declaring repository identity in settings.yml - #329

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/settings-no-identity
Sep 19, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/settings-no-identity

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

probot/settings applies this file on every push to the default branch, so the four identity
keys it declared are instructions, not documentation. The estate has already paid for exactly this:
.github/settings.yml once read name: "{{REPO}}", GitHub collapsed the illegal braces to dashes,
the repository renamed itself to -REPO- on every push, its old URL 404'd, and it was read as a
deleted repository.

This repo still declared name, description, homepage and private.

The repair is convergence on the source of truth, not new content:

  • the header becomes the template's own header, which documents the incident and the rule
    ("THIS FILE MUST NEVER DECLARE REPOSITORY IDENTITY");
  • the four identity keys are removed; everything else is unchanged — same repository settings,
    same 18 labels;
  • repository identity and visibility stay set out of band, once, by the owner.

Verified with the estate's own gate, scripts/check-no-placeholders.sh, whose settings.yml guard
runs in template repos too (that exemption is how the original incident went unseen). On this
branch the guard reports clean.

probot/settings applies this file on every push to the default branch, so `name`,
`description`, `homepage` and `private` here are instructions, not documentation. The estate has
already paid for that: the template carried `name: "{{REPO}}"`, GitHub collapsed the illegal braces
to dashes, the repo renamed itself to `-REPO-` on every push and its old URL 404'd.

This file now matches the template's own header and rule, with the four identity keys removed and
everything else left as it was. Repository identity and visibility are set out of band, once, by
the owner. Enforced by scripts/check-no-placeholders.sh.
@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4cfea0f8-a5b1-453e-9d39-ac384fd40c7c

📥 Commits

Reviewing files that changed from the base of the PR and between 915f1d4 and 5ba0892.

📒 Files selected for processing (1)
  • .github/settings.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (34)
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Security policy checks
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: scan / rust-secrets
  • GitHub Check: scan / shell-secrets
  • GitHub Check: scan / gitleaks
  • GitHub Check: Bridge — node (unit + boot smoke)
  • GitHub Check: Bridge — deno (unit + boot smoke)
  • GitHub Check: Detect relevant changes
  • GitHub Check: Bridge — bun (unit + boot smoke)
  • GitHub Check: Detect relevant changes
  • GitHub Check: Detect relevant changes
  • GitHub Check: Detect relevant changes
  • GitHub Check: Validate K9 contracts
  • GitHub Check: analyze (javascript-typescript, none)
  • GitHub Check: Validate eclexiaiser manifest
  • GitHub Check: Detect relevant changes
  • GitHub Check: Empty-linter (invisible characters)
  • GitHub Check: Validate A2ML manifests
  • GitHub Check: Groove manifest check
  • GitHub Check: Hypatia Neurosymbolic Analysis
  • GitHub Check: Detect relevant changes
  • GitHub Check: Detect relevant changes
  • GitHub Check: Detect relevant changes
  • GitHub Check: SonarQube
🔇 Additional comments (1)
.github/settings.yml (1)

9-44: LGTM!


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Repository identity, visibility, and homepage settings are no longer overwritten automatically on updates.
    • Prevents template-created repositories from being renamed to placeholder values.
    • Download settings are no longer managed through the automated repository configuration.

Walkthrough

The repository settings no longer declare repository identity, visibility, or downloads fields. Comments document out-of-band configuration and the placeholder check.

Changes

Repository settings

Layer / File(s) Summary
Remove managed identity fields
.github/settings.yml
The repository block removes name, description, homepage, private, and has_downloads. It retains operational settings and documents the placeholder validation.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other · Severity of issue fixed: Medium

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the problem, the changes, the preserved settings, and the verification performed. However, it omits the required template sections and the RSR Quality Checklist, including exp… Use the repository template. Add the ## Summary, ## Changes, ## RSR Quality Checklist, ## Testing, and ## Screenshots sections. Complete each applicable checklist item and state when a section does not apply.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: removing repository identity declarations from .github/settings.yml.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the problem, the changes, the preserved settings, and the verification performed. However, it omits the required template sections and the RSR Quality Checklist, including explicit test, formatting, lint, licensing, and security confirmations.

  • Fix all pre-merge checks with AI

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the settings file
Identity fields hop out of style
Placeholders stay away
Pushes behave each day
The repository keeps its name

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 108 issues detected

Severity Count
🔴 Critical 11
🟠 High 16
🟡 Medium 81

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `sonarqube` in build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sonarqube"
  },
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "Job `deploy` in pages-deploy.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "pages-deploy.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.",
    "type": "secret_action_without_presence_gate",
    "file": "instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_secret_presence_gate"
  },
  {
    "reason": "codeql.yml does not list `language: actions` in its matrix, but the repo has workflow files. CodeQL's `actions` language scans workflow YAML for injection and other CI/CD-specific weaknesses — every repo with workflows benefits. Add an entry to `matrix.include` with `language: actions` + `build-mode: none`.",
    "type": "codeql_missing_actions_language",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "fix_recipe": "add_codeql_actions_language"
  },
  {
    "line": 31,
    "reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 45,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 157,
    "reason": "job in .github/workflows/release.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/release.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 48,
    "reason": "job in .github/workflows/publish.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/publish.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit c1c58e3 into main Sep 19, 2026
51 of 56 checks passed
@hyperpolymath
hyperpolymath deleted the chore/settings-no-identity branch September 19, 2026 19:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant