Repository navigation
docs: affirm state at 14386f3e (docs/AFFIRMATION.adoc) - #351
Merged
Merged
Conversation
Add docs/AFFIRMATION.adoc (profile A, evidential), anchored to main at 14386f3, verified 2026-10-07T10:20Z-10:22Z. Affirmed by live run: 68 unit tests (node + bun), node and bun boot smokes, a clean stdio handshake exposing 68 tools / 6 prompts / 7 resources with serverInfo 0.4.7, matching the README. CI evidence: Idris2 type-check, trusted-base audit, readme-derive, gitleaks. Outstanding, stated not hidden: the Justfile does not parse (guix-shell redefined), ffi/zig/src/bench.zig fails on Zig 0.16 (Io.Clock.monotonic), breaking both E2E jobs; 7 non-required reds, all pre-existing; npm latest lags main; version strings disagree; start script uses deno. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
…-tui) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔍 Hypatia Security ScanFindings: 113 issues detected
View findings[
{
"reason": "Job `sonarqube` in build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/build.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sonarqube"
},
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"reason": "Job `deploy` in pages-deploy.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": ".github/workflows/pages-deploy.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "deploy"
},
{
"reason": "Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.",
"type": "secret_action_without_presence_gate",
"file": ".github/workflows/instant-sync.yml",
"action": "peter-evans/repository-dispatch",
"rule_module": "workflow_audit",
"severity": "high",
"fix_recipe": "add_secret_presence_gate"
},
{
"reason": "codeql.yml does not list `language: actions` in its matrix, but the repo has workflow files. CodeQL's `actions` language scans workflow YAML for injection and other CI/CD-specific weaknesses — every repo with workflows benefits. Add an entry to `matrix.include` with `language: actions` + `build-mode: none`.",
"type": "codeql_missing_actions_language",
"file": ".github/workflows/codeql.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"fix_recipe": "add_codeql_actions_language"
},
{
"line": 39,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 46,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 32,
"reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/build.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
},
{
"line": 44,
"reason": "job in .github/workflows/container-publish.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/container-publish.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
9 of 14 tasks
hyperpolymath
added a commit
that referenced
this pull request
Oct 7, 2026
… local run (#352) ## Summary A follow-up to #351, which was squash-merged as `3de2f6ff` before this commit reached its branch. This PR upgrades three rows of `docs/AFFIRMATION.adoc` from **CI evidence** to **affirmed by local run**, using the pinned toolchain. It also records how the affirmation landed. The runs were all made on a cold `git archive` of the same anchor, `14386f3e61cdfd324853cca3a36f5c37192d59d7`, between 10:26:56Z and 10:27:40Z: - Idris2 **0.8.0** (the `.mise.toml` pin, at `tools/opt/idris2-0.8.0`, with `IDRIS2_PREFIX` set so `contrib` resolves). `cd src/abi && idris2 --typecheck boj.ipkg` gave rc 0, **17/17** modules built. - `scripts/typecheck-proofs.sh` gave rc 0, `PASS=1 FAIL=0`. - `scripts/check-trusted-base.sh` gave rc 0: **4 sanctioned class-(J) axioms**, all in `src/abi/Boj/SafetyLemmas.idr`. - Zig **0.16.0** `zig build` in `ffi/zig` gave rc 1 with **13 errors**, all `src/bench.zig: enum 'Io.Clock' has no member named 'monotonic'`, the same as CI. **The anchor doesn't move.** The template's parent check concerns the commit that *introduced* the file. That commit is `3de2f6ff`, whose parent is `14386f3e`, and `git diff --stat 14386f3 3de2f6f` shows only `docs/AFFIRMATION.adoc`. The new "Landing record" note in the file says so. Credit: the boj-server session [bf7923] pointed out the pinned Idris2 install and its `IDRIS2_PREFIX` requirement, and its 10:25Z run matched mine. ## Type of change Documentation only. ## 📌 New pins Head SHA: **`b39db8d103aa6e705db2f246bbef8272ef89a007`**. This PR adds or changes no pins: no action `uses:`, `actions.lock`, lockfile or container digest changes. ## Changes - `docs/AFFIRMATION.adoc`: - The anchor's toolchain row now lists Zig 0.16.0 and Idris2 0.8.0, and the working-tree row describes the cold archive build. - The Idris2 and trusted-base rows are now "affirmed", with the commands and output. - The Zig bench item now cites the local run. - The one-paragraph summary and the one-line quote now describe the pinned Idris2 run. - The verification window ends at 10:27:40Z. - The "Squash-merge note" is replaced by a "Landing record". ## RSR Quality Checklist ### Required - [x] Tests pass. This PR changes no code. The checks it reports were run as described above. - [x] Code is formatted. N/A: no code changed. - [x] Linter is clean. N/A: no code changed. - [x] No banned language patterns. A single AsciiDoc file. - [x] No `unsafe` blocks without `// SAFETY:` comments. N/A: no code changed. - [x] No banned functions. N/A: no code changed. The 4 `believe_me` axioms are the documented `SafetyLemmas` ones, which `check-trusted-base.sh` reports as sanctioned. - [x] SPDX license headers present. The header is unchanged (`CC-BY-SA-4.0`). - [x] No secrets, credentials, or `.env` files included. ### As Applicable - [ ] `.machine_readable/*` updated. N/A: A2ML is retired (D308). - [x] Documentation updated. - [ ] `TOPOLOGY.md` updated. N/A: architecture didn't change. - [ ] `CHANGELOG` updated. N/A: no release. - [ ] New dependencies reviewed. N/A: no dependencies added. - [ ] ABI/FFI changes validated. N/A: ABI and FFI untouched. The file only reports their state. ## Testing - `asciidoctor --failure-level=WARN docs/AFFIRMATION.adoc` returned rc 0. - The commands and outputs are the ones quoted above. The **Reproduce it yourself** section in the file is unchanged. Deferred non-required reds (pre-existing on main): `governance / UUID v7 conformance`, `SonarQube`, the Zig E2E and Bench jobs, `deploy` and `Dependabot` → #338, with acceptance criteria in comment 6035981182. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
docs/AFFIRMATION.adoc(the rsr-template profile A "evidential" affirmation), anchored to main at14386f3e61cdfd324853cca3a36f5c37192d59d7and verified 2026-10-07T10:20:02Z–10:22:34Z. boj-server didn't have one before.What the file records:
boj_*+ 23coord_*), 6 prompts and 7 resources, with serverInfo0.4.7. That matches the README exactly.Justfiledoesn't parse (guix-shellredefined, from refactor(root): move root artefacts to their canonical locations #327), so nojustrecipe runs.ffi/zig/src/bench.zig:27usesIo.Clock.monotonic, which Zig 0.16 removed. That breaks both E2E jobs and the Bench job.latest0.4.7 is behind main: it serves 65/6/6 and reports serverInfo 0.4.0.startscript uses deno._chora.deed.tray/coord-tuilockfiles.Merge timing: the template treats the affirmation as valid only if its anchor is the parent of the commit that lands it. Please squash-merge this before main moves past
14386f3e. If main moves first, the file reads as a draft and I'll re-anchor it.Type of change
Documentation only (a new doc file).
📌 New pins
Head SHA:
5c0eb80cc26b7d10b456155d54db17fc686cc189(merged as3de2f6ff). This PR adds or changes no pins: no actionuses:,actions.lock, lockfile or container digest changes.Changes
docs/AFFIRMATION.adoc.RSR Quality Checklist
Required
just lintcan't run at all on main (the Justfile parse error), as the file records.unsafeblocks without// SAFETY:comments. N/A: no code changed.CC-BY-SA-4.0and SPDX-FileCopyrightText..envfiles included.As Applicable
.machine_readable/*updated. N/A: A2ML is retired (D308), and the file records the leftover A2ML instead of editing it (D313).TOPOLOGY.mdupdated. N/A: architecture didn't change.CHANGELOGupdated. N/A: no release.Testing
asciidoctor --failure-level=WARN docs/AFFIRMATION.adocreturned rc 0, and theboj_*,coord_*and{error, hint}passthroughs render correctly.gh api …/commits/14386f3e…/check-runs --paginate(47 success, 10 skipped, 7 failure). The failures were confirmed identical on the parent0e700c9d.Deferred non-required reds (pre-existing on main, not caused by this PR):
governance / UUID v7 conformanceandSonarQube→ #338. The Zig 0.16Io.Clock.monotonicbreak (both E2E jobs and Bench),deploy, andDependabot→ #338. I'm adding those to #338 in a comment with this PR.🤖 Generated with Claude Code
https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC