You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(ci): pin standards reusables to default-branch HEAD (#56)
Re-points this repo's `hyperpolymath/standards` reusable-workflow pins
at the standards default-branch HEAD,
`8f2ee50841e216cd8c192eeb68953118190f105c`.
**This PR makes two changes, not one.** It also widens the top-level
`permissions:` block of 1 workflow file(s). A caller that grants a
reusable **less** than the reusable's own `permissions:` request is
rejected at workflow **startup** — the exact failure this PR exists to
cure — so bumping the pin without this would move the repo from one
silent disappearance to another. The scopes added are not hardcoded:
each reusable's request is read from `8f2ee508` **at sweep time** and
only the genuinely missing scopes are added, at the indent the file
already uses. Only `read`-level scopes are added this way; anything
needing `write` is held for review instead.
**Why this is not a routine version bump.** `uses:
org/repo/.github/workflows/x.yml@<ref>` is resolved at workflow
**startup**, so a bad ref is not a failing job — it is *no job at all*.
This campaign repairs three kinds of drift and does not assume which one
this repo had:
- an **unreachable** sha kills the run before any job is created, so
GitHub reports **no check at all** rather than a failing one: the gate
does not go red, it *disappears*, and `gh pr checks` simply lists fewer
rows. A repo in this state looks greener than one with working gates;
- a **floating** ref such as `@main` runs, but unpinned — the
supply-chain property the estate pins for is absent;
- a **stale but reachable** sha runs the reusable as it was, silently
reintroducing every bug fixed since it.
The refs this repo was actually pinned to, before this PR:
`092dedada188f56c5915f74a5fd40aac093742c3`.
**Expect this PR to surface failures that main does not show.** Those
failures are *revealed, not introduced* — they are the gates resuming
work after being silently absent. The honest comparison is the set of
check **names** emitted here versus on `main`, not pass/fail counts. On
the canary (`hyperpolymath/empty-linter#79`) the governance suite was
absent on main and emitted 25 checks once repaired.
The target is default-branch HEAD resolved at sweep time, never a sha
copied from a plan: a reachable but non-HEAD sha silently reintroduces
every bug fixed since it.
Engine: `.git-private-farm/scripts/smtp-notify-sweep.sh --campaign
campaigns/pin-repair.sh`. Verification for this repo: `files=5 pins=5
perms=1 permlines=1 from=092dedada188f56c5915f74a5fd40aac093742c3
target=8f2ee508 sig=G d693d4e canon=a7325fbdc356 base=main`
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
0 commit comments