From 9bb180722cfad430641cc3c690381d469a699210 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 04:51:24 +0100 Subject: [PATCH 1/3] fix(ci): re-pin standards reusables to lockfile-bearing ref fcb8669 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Caller-side lockfile enforcement requires actions.lock in the CALLED repo at the pinned ref. standards shipped its lockfile in #570 (gates repaired in #571/#572); these callers were still pinned to May-July SHAs whose trees predate it, so all 7 died as startup_failure even after echidna's own lockfile landed (#341). security-scan.yml is untouched: it calls hyperpolymath/panic-attack, which needs its own lockfile before that caller can start. Every new pin verified resolvable via the commits API (the first attempt fabricated a SHA tail — the exact phantom-pin failure mode this estate already measured 112 times). Co-Authored-By: Claude Fable 5 --- .github/workflows/governance.yml | 2 +- .github/workflows/hypatia-scan.yml | 2 +- .github/workflows/main-estate-audit.yml | 93 ++++++++++++++++++++++++ .github/workflows/mirror.yml | 2 +- .github/workflows/rust-ci.yml | 2 +- .github/workflows/scorecard.yml | 2 +- .github/workflows/secret-scanner.yml | 2 +- .github/workflows/spark-theatre-gate.yml | 2 +- 8 files changed, 100 insertions(+), 7 deletions(-) create mode 100755 .github/workflows/main-estate-audit.yml diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 513ad091..6288b175 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -14,4 +14,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 # main 2026-07-07 (baseline-gated hypatia — standards#455/#464/#466) + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 108fa11b..5ef635f7 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -17,5 +17,5 @@ permissions: jobs: hypatia: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@6cd3772824e59c8c9affeab66061e25383544242 + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) secrets: inherit diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml new file mode 100755 index 00000000..ed0d4a2e --- /dev/null +++ b/.github/workflows/main-estate-audit.yml @@ -0,0 +1,93 @@ +# This workflow is managed by gh actions-lock. + +name: Central Estate CI/CD Audit + +on: + push: + branches: [ "main" ] + pull_request: + branches: [ "main" ] + +jobs: + estate-audit: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4.4.0 + + - name: Required Files Gate + uses: hyperpolymath/cicd-suite/actions/required-files-check@main + + - name: Code Hygiene Gate + uses: hyperpolymath/cicd-suite/actions/code-hygiene-check@main + + - name: Manifest Validation Gate + uses: hyperpolymath/cicd-suite/actions/manifest-check@main + + - name: Idris2 ABI Purity Gate + uses: hyperpolymath/cicd-suite/actions/idris2-abi-check@main + + - name: Zig Hexadeca API Gate + uses: hyperpolymath/cicd-suite/actions/zig-hexadeca-check@main + + - name: Contractile Validation Gate + uses: hyperpolymath/cicd-suite/actions/contractile-validation-check@main + + - name: Recipes Set Validation Gate + uses: hyperpolymath/cicd-suite/actions/recipes-set-check@main + + - name: Affirmation Document Gate + uses: hyperpolymath/cicd-suite/actions/affirmation-check@main + + - name: Academic Referencing Gate + uses: hyperpolymath/cicd-suite/actions/referencing-check@main + + - name: Semantic Audit Gate + uses: hyperpolymath/cicd-suite/actions/semantic-audit-check@main + + - name: SPDX License Gate + uses: hyperpolymath/cicd-suite/actions/spdx-license-check@main + + - name: Proof Runner Gate + uses: hyperpolymath/cicd-suite/actions/proof-runner-check@main + + - name: PRAT Testing Gate + uses: hyperpolymath/cicd-suite/actions/prat-check@main + + - name: Panic Attack & Pons Gate + uses: hyperpolymath/cicd-suite/actions/custom-tools-check@main + + - name: WWW & Well-Known Compliance Gate + uses: hyperpolymath/cicd-suite/actions/www-compliance-check@main + + - name: BoJ Cartridge Validation Gate + uses: hyperpolymath/cicd-suite/actions/boj-cartridge-check@main + + - name: Formatting Validation Gate + uses: hyperpolymath/cicd-suite/actions/formatting-check@main + + - name: Accreditations & Badges Gate + uses: hyperpolymath/cicd-suite/actions/badges-check@main + + - name: Metrics Extraction Gate + uses: hyperpolymath/cicd-suite/actions/metrics-check@main + + - name: Linguist & Banned Languages Gate + uses: hyperpolymath/cicd-suite/actions/linguist-check@main + + - name: Test & Benchmarks Dashboard Gate + uses: hyperpolymath/cicd-suite/actions/tests-benches-check@main + + - name: Hosting & Site Status Gate + uses: hyperpolymath/cicd-suite/actions/hosting-check@main + + - name: Git-Sea Analytics Gate + uses: hyperpolymath/cicd-suite/actions/gitsea-check@main + + - name: Trust & Humans Validation Gate + uses: hyperpolymath/cicd-suite/actions/trust-humans-check@main + + - name: Are We UnAPI Gate (Secret Scanning) + uses: hyperpolymath/cicd-suite/actions/secrets-check@main + + - name: Reasonably Good Token Validation Gate + uses: hyperpolymath/cicd-suite/actions/vaulted-tokens-check@main diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index b57dfa47..fb37ed2d 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -20,5 +20,5 @@ permissions: jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236 # main 2026-05-30 (Radicle + Instant-Sync secret-presence gating #305) + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) secrets: inherit diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 288393ba..d4980ca3 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -15,7 +15,7 @@ permissions: jobs: rust-ci: - uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@7c9db0e5909aab77bf11a444ade3b95c1d2b702e # re-pinned 2026-07-01: toolchain-required-input fix (standards#439) # main 2026-05-31 (CI/CD campaigns C001-C005) + uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) with: enable_audit: true enable_coverage: true diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 41e18794..26da2374 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -21,5 +21,5 @@ jobs: security-events: write id-token: write contents: read - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 # main 2026-05-28 (SPDX bump #249) + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) secrets: inherit diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index a4d88925..7b38e6f8 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -19,5 +19,5 @@ jobs: # caller must grant at least that or the run startup-fails. permissions: contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@c65436ee3351cd6b0fa14b142938b195efc77586 # main 2026-05-28 (SPDX bump #249 + pragma/.shell-secrets-ignore fix #236) + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) secrets: inherit diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index bd6bc072..b00c4339 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -16,7 +16,7 @@ permissions: jobs: spark-theatre-gate: - uses: hyperpolymath/standards/.github/workflows/spark-theatre-gate.yml@e03686486e11b662834d7090dffae54c3e96fd59 # main 2026-05-28 (SPDX bump #249) + uses: hyperpolymath/standards/.github/workflows/spark-theatre-gate.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 # main 2026-08-04 (lockfile-bearing ref: actions.lock required by caller-side enforcement, standards#570) with: paths: "." enforce_zero_contract: false From cd68ca3c8651391f4f4190b4ab9cae709e511391 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 04:54:47 +0100 Subject: [PATCH 2/3] fix(ci): lockfile entries for all 8 reusable-caller workflows; drop leaked audit file MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The Governance run banner on this PR reads: 'The following workflows are missing a lockfile: .github/workflows/governance.yml' — enforcement requires EVERY workflow to appear in actions.lock, including pure reusable callers, which gh actions-lock skips. Empty entries added for the 8 callers (same cure as the zero-dep probe in #341). main-estate-audit.yml was untracked scratch swept in by 'git add' — removed from the branch; it references the nonexistent hyperpolymath/cicd-suite repo and lacks an SPDX header (it caused both the Central Estate CI/CD Audit startup_failure and the Workflow Security Linter red on this PR). Co-Authored-By: Claude Fable 5 --- .github/workflows/actions.lock | 8 +++ .github/workflows/main-estate-audit.yml | 93 ------------------------- 2 files changed, 8 insertions(+), 93 deletions(-) delete mode 100755 .github/workflows/main-estate-audit.yml diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 51c1a36c..de1dd8dc 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -43,12 +43,15 @@ workflows: '.github/workflows/ghcr-publish.yml': - 'actions/attest-build-provenance@v4.1.1' - 'actions/checkout@v7.0.1' + '.github/workflows/governance.yml': [] + '.github/workflows/hypatia-scan.yml': [] '.github/workflows/idris2-abi-ci.yml': - 'actions/checkout@v7.0.1' '.github/workflows/live-provers.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/mirror.yml': [] '.github/workflows/mvp-smoke.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' @@ -58,15 +61,20 @@ workflows: - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.0' - 'actions/upload-pages-artifact@v5.0.0' + '.github/workflows/rust-ci.yml': [] '.github/workflows/s4-loop.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - 'swatinem/rust-cache@v2.9.1' - 'taiki-e/install-action@v2.85.3' + '.github/workflows/scorecard.yml': [] + '.github/workflows/secret-scanner.yml': [] + '.github/workflows/security-scan.yml': [] '.github/workflows/server-boot-gate.yml': - 'actions/checkout@v7.0.1' - 'dtolnay/rust-toolchain@stable' - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/spark-theatre-gate.yml': [] '.github/workflows/verification-proofs-cron.yml': - 'actions/checkout@v7.0.1' '.github/workflows/workflow-linter.yml': diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml deleted file mode 100755 index ed0d4a2e..00000000 --- a/.github/workflows/main-estate-audit.yml +++ /dev/null @@ -1,93 +0,0 @@ -# This workflow is managed by gh actions-lock. - -name: Central Estate CI/CD Audit - -on: - push: - branches: [ "main" ] - pull_request: - branches: [ "main" ] - -jobs: - estate-audit: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v4.4.0 - - - name: Required Files Gate - uses: hyperpolymath/cicd-suite/actions/required-files-check@main - - - name: Code Hygiene Gate - uses: hyperpolymath/cicd-suite/actions/code-hygiene-check@main - - - name: Manifest Validation Gate - uses: hyperpolymath/cicd-suite/actions/manifest-check@main - - - name: Idris2 ABI Purity Gate - uses: hyperpolymath/cicd-suite/actions/idris2-abi-check@main - - - name: Zig Hexadeca API Gate - uses: hyperpolymath/cicd-suite/actions/zig-hexadeca-check@main - - - name: Contractile Validation Gate - uses: hyperpolymath/cicd-suite/actions/contractile-validation-check@main - - - name: Recipes Set Validation Gate - uses: hyperpolymath/cicd-suite/actions/recipes-set-check@main - - - name: Affirmation Document Gate - uses: hyperpolymath/cicd-suite/actions/affirmation-check@main - - - name: Academic Referencing Gate - uses: hyperpolymath/cicd-suite/actions/referencing-check@main - - - name: Semantic Audit Gate - uses: hyperpolymath/cicd-suite/actions/semantic-audit-check@main - - - name: SPDX License Gate - uses: hyperpolymath/cicd-suite/actions/spdx-license-check@main - - - name: Proof Runner Gate - uses: hyperpolymath/cicd-suite/actions/proof-runner-check@main - - - name: PRAT Testing Gate - uses: hyperpolymath/cicd-suite/actions/prat-check@main - - - name: Panic Attack & Pons Gate - uses: hyperpolymath/cicd-suite/actions/custom-tools-check@main - - - name: WWW & Well-Known Compliance Gate - uses: hyperpolymath/cicd-suite/actions/www-compliance-check@main - - - name: BoJ Cartridge Validation Gate - uses: hyperpolymath/cicd-suite/actions/boj-cartridge-check@main - - - name: Formatting Validation Gate - uses: hyperpolymath/cicd-suite/actions/formatting-check@main - - - name: Accreditations & Badges Gate - uses: hyperpolymath/cicd-suite/actions/badges-check@main - - - name: Metrics Extraction Gate - uses: hyperpolymath/cicd-suite/actions/metrics-check@main - - - name: Linguist & Banned Languages Gate - uses: hyperpolymath/cicd-suite/actions/linguist-check@main - - - name: Test & Benchmarks Dashboard Gate - uses: hyperpolymath/cicd-suite/actions/tests-benches-check@main - - - name: Hosting & Site Status Gate - uses: hyperpolymath/cicd-suite/actions/hosting-check@main - - - name: Git-Sea Analytics Gate - uses: hyperpolymath/cicd-suite/actions/gitsea-check@main - - - name: Trust & Humans Validation Gate - uses: hyperpolymath/cicd-suite/actions/trust-humans-check@main - - - name: Are We UnAPI Gate (Secret Scanning) - uses: hyperpolymath/cicd-suite/actions/secrets-check@main - - - name: Reasonably Good Token Validation Gate - uses: hyperpolymath/cicd-suite/actions/vaulted-tokens-check@main From 38f5f4dd635b4260db4db7fa3027be5e11f46977 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 05:02:21 +0100 Subject: [PATCH 3/3] fix(ci): grant caller permissions the re-pinned reusables request MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Third enforcement layer surfaced by the re-pin (banner: "The workflow is requesting 'actions: read', but is only allowed 'actions: none'"): a reusable may not request more GITHUB_TOKEN permissions than its caller grants. The fcb8669 reusables request actions: read (governance, hypatia-scan, spark-theatre-gate, mirror, scorecard) and security-events: write (hypatia-scan); the callers still granted the old pins' narrower sets. Proof of the layer: rust-ci and secret-scanner, whose reusables request only contents: read, ran real jobs (5 and 3) on the previous push while these five died. mirror and scorecard are patched proactively — they trigger on push/schedule, so they would have hit the same wall on main. Co-Authored-By: Claude Fable 5 --- .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 3 ++- .github/workflows/mirror.yml | 1 + .github/workflows/scorecard.yml | 1 + .github/workflows/spark-theatre-gate.yml | 1 + 5 files changed, 6 insertions(+), 1 deletion(-) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 6288b175..0d830b6c 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -10,6 +10,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 5ef635f7..91443525 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -12,8 +12,9 @@ on: workflow_dispatch: permissions: + actions: read contents: read - security-events: read + security-events: write jobs: hypatia: diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index fb37ed2d..411141eb 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -16,6 +16,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 26da2374..a5f737e4 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -10,6 +10,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index b00c4339..8915f3b5 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -12,6 +12,7 @@ on: branches: [main, master] permissions: + actions: read contents: read jobs: