From 44140485e0c9b30e64035fdacd7da6d0097bed53 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 19:20:32 +0100 Subject: [PATCH 1/2] fix(ci): revive the startup-dead gates - repoint pins and grant actions:read scorecard, mirror and secret-scanner were dying at startup on this repo: each reported 0 jobs and 0 check runs, so main looked green because the gates were ABSENT, not passing. Two causes, both fixed here: 1. Callers sat on the older standards pin 7fdc2705, whose reusables request `actions: read`, which the callers did not grant. 2. A job-level `permissions:` block REPLACES the workflow-level map rather than merging with it, so a job with its own block ran without `contents: read` or `actions: read` no matter what the top of the file granted. All four affected callers are repointed to standards main HEAD 257869d3 and now grant `actions: read` + `contents: read` at BOTH workflow and job level. governance.yml is deliberately left on fad242d3: standards main HEAD is currently unparseable by callers because its actions.lock is out of sync with governance-reusable.yml after Dependabot #746 (HTTP 422, run dies at startup). hyperpolymath/standards#754 resyncs it; governance moves to HEAD once that lands. Verified on the sibling canary (bofig): mirror went 0 jobs -> 7 jobs. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QMTyDv9CoJo5PfeNzyp519 --- .github/workflows/hypatia-scan.yml | 3 ++- .github/workflows/mirror.yml | 3 ++- .github/workflows/scorecard.yml | 3 ++- .github/workflows/secret-scanner.yml | 4 +++- 4 files changed, 9 insertions(+), 4 deletions(-) diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index fc2b618..a8b568a 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -19,11 +19,12 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read security-events: write pull-requests: write jobs: hypatia: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index b1faf98..9bce625 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -7,9 +7,10 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index ddf6652..a0e0a57 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -10,8 +10,9 @@ permissions: read-all jobs: analysis: - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a permissions: + actions: read contents: read security-events: write id-token: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index d74f680..043df99 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -11,11 +11,13 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: scan: permissions: + actions: read contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a secrets: inherit From 71dc95b3cf1fc995f046d42f55bb0a89ef4b46a2 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 8 Sep 2026 19:21:23 +0100 Subject: [PATCH 2/2] ci(scorecard): add workflow_dispatch so the gate can be verified on demand scorecard.yml triggered only on branch_protection_rule and schedule, so there was no way to prove the startup-failure repair works before merging it. The canonical template caller (proof-burrower, the verified-working control) carries workflow_dispatch; this matches it. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01QMTyDv9CoJo5PfeNzyp519 --- .github/workflows/scorecard.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index a0e0a57..8517ecb 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -2,6 +2,7 @@ name: Scorecards supply-chain security on: + workflow_dispatch: branch_protection_rule: schedule: - cron: '23 4 * * 1'