Skip to content

Commit feef674

Browse files
Merge branch 'main' into dependabot/github_actions/actions-a0ecfb89c7
2 parents bf5629e + ebe74f1 commit feef674

74 files changed

Lines changed: 2349 additions & 921 deletions

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.claude/CLAUDE.md‎

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -72,11 +72,10 @@ Control (report < 0.85) → Human review required
7272
## Critical Invariants
7373

7474
1. The seven canonical A2ML files (`STATE`, `META`, `ECOSYSTEM`,
75-
`AGENTIC`, `NEUROSYM`, `PLAYBOOK`, `ANCHOR`) live directly under
76-
`.machine_readable/`, per the `A2ML-REPO-TEMPLATE` in
77-
`hyperpolymath/standards`. (Earlier versions of this CLAUDE.md
78-
referenced a `.machine_readable/6scm/` subdir; that layout has been
79-
retired.)
75+
`AGENTIC`, `NEUROSYM`, `PLAYBOOK`, `ANCHOR`) live under
76+
`.machine_readable/descriptiles/`, per the current estate-wide policy.
77+
Earlier direct-under-`.machine_readable/`, `6scm/`, and `6a2/` layouts
78+
are retired and must not be restored.
8079
2. All shell scripts validate untrusted input before use.
8180
3. No hardcoded secrets — use env vars with `${VAR:-}` defaults.
8281
4. Fix scripts must be idempotent (safe to run multiple times).

‎.github/workflows/actions.lock‎

Lines changed: 20 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -10,14 +10,15 @@ workflows:
1010
- 'actions/checkout@v7.0.1'
1111
- 'actions/configure-pages@v6.0.0'
1212
- 'actions/deploy-pages@v5.0.0'
13+
- 'actions/download-artifact@v8.0.1'
1314
- 'actions/upload-pages-artifact@v5.0.0'
1415
- 'haskell-actions/setup@v2.12.0'
1516
'.github/workflows/codeql.yml':
1617
- 'actions/checkout@v7.0.1'
1718
- 'github/codeql-action@v4.37.8'
1819
'.github/workflows/dogfood-gate.yml':
1920
- 'actions/checkout@v7.0.1'
20-
- 'hyperpolymath/a2ml-ecosystem@main'
21+
- 'hyperpolymath/deed-ecosystem@main'
2122
- 'hyperpolymath/k9-ecosystem@main'
2223
'.github/workflows/e2e.yml':
2324
- 'actions/checkout@v7.0.1'
@@ -50,7 +51,11 @@ workflows:
5051
- 'actions/checkout@v7.0.1'
5152
'.github/workflows/rust.yml':
5253
- 'actions/checkout@v7.0.1'
53-
'.github/workflows/scorecard.yml': []
54+
'.github/workflows/scorecard.yml':
55+
- 'actions/checkout@v7.0.1'
56+
- 'actions/upload-artifact@v7.0.1'
57+
- 'github/codeql-action@v4.37.8'
58+
- 'ossf/scorecard-action@v2.4.4'
5459
'.github/workflows/secret-scanner.yml': []
5560
'.github/workflows/supervised-fleet-scan.yml':
5661
- 'actions/checkout@v7.0.1'
@@ -75,6 +80,11 @@ dependencies:
7580
commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128'
7681
owner_id: 44036562
7782
repo_id: 438112499
83+
'actions/download-artifact@v8.0.1':
84+
ref: 'v8.0.1'
85+
commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
86+
owner_id: 44036562
87+
repo_id: 192626254
7888
'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f':
7989
ref: 'v7.0.0'
8090
commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
@@ -107,21 +117,26 @@ dependencies:
107117
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
108118
owner_id: 75048950
109119
repo_id: 623796603
110-
'hyperpolymath/a2ml-ecosystem@main':
120+
'hyperpolymath/deed-ecosystem@main':
111121
ref: 'main'
112-
commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79'
122+
commit: 'sha1-f7a40a4d5cc82b2e73f861119baa6818d77a448d'
113123
owner_id: 6759885
114124
repo_id: 1275649586
115125
'hyperpolymath/k9-ecosystem@main':
116126
ref: 'main'
117-
commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562'
127+
commit: 'sha1-2155aa26a21758f2ba119f61bc7e0e1981c106fb'
118128
owner_id: 6759885
119129
repo_id: 1275650185
120130
'hyperpolymath/smtp-notify-action@v0.2.0':
121131
ref: 'v0.2.0'
122132
commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
123133
owner_id: 6759885
124134
repo_id: 1352485172
135+
'ossf/scorecard-action@v2.4.4':
136+
ref: 'v2.4.4'
137+
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
138+
owner_id: 67707773
139+
repo_id: 421101922
125140
'peter-evans/repository-dispatch@v4.0.1':
126141
ref: 'v4.0.1'
127142
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'

‎.github/workflows/boj-build.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.

‎.github/workflows/casket-pages.yml‎

Lines changed: 104 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,42 +1,41 @@
1-
# SPDX-License-Identifier: MPL-2.0
21
# This workflow is managed by gh actions-lock.
2+
# SPDX-License-Identifier: MPL-2.0
33
# This workflow is managed by gh actions-lock.
44
name: GitHub Pages
55

66
on:
77
push:
88
branches: [main, master]
9+
pull_request:
910
workflow_dispatch:
1011

1112
permissions:
12-
actions: read
1313
contents: read
14-
pages: write
15-
id-token: write
1614

1715
concurrency:
18-
group: "pages"
19-
cancel-in-progress: false
16+
group: "pages-${{ github.event_name }}-${{ github.ref }}"
17+
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
2018

2119
jobs:
2220
build:
23-
runs-on: ubuntu-latest
21+
name: Build Pages artifact
22+
runs-on: ubuntu-24.04
2423
timeout-minutes: 30
24+
permissions:
25+
contents: read
2526
steps:
2627
- name: Checkout
2728
uses: actions/checkout@v7.0.1
29+
with:
30+
persist-credentials: false
2831

2932
- name: Checkout casket-ssg
3033
uses: actions/checkout@v7.0.1
3134
with:
3235
repository: hyperpolymath/casket-ssg
36+
ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b # standalone build; optional liblol bridge
3337
path: .casket-ssg
34-
35-
- name: Setup GHCup
36-
uses: haskell-actions/setup@v2.12.0
37-
with:
38-
ghc-version: '9.8.2'
39-
cabal-version: '3.10'
38+
persist-credentials: false
4039

4140
- name: Cache Cabal
4241
uses: actions/cache@v6.1.0
@@ -47,12 +46,28 @@ jobs:
4746
.casket-ssg/dist-newstyle
4847
key: ${{ runner.os }}-casket-${{ hashFiles('.casket-ssg/casket-ssg.cabal') }}
4948

49+
# Explicitly allowed by repository policy; actions.lock pins its commit.
50+
- name: Select tested Haskell toolchain
51+
uses: haskell-actions/setup@v2.12.0
52+
with:
53+
ghc-version: '9.6.6'
54+
cabal-version: '3.10.3.0'
55+
56+
- name: Prepare runner Haskell toolchain
57+
run: |
58+
set -euo pipefail
59+
ghc --version
60+
cabal --version
61+
cabal update
62+
5063
- name: Build casket-ssg
5164
working-directory: .casket-ssg
52-
run: cabal build
65+
run: cabal build --index-state=2026-09-06T00:00:00Z
5366

5467
- name: Prepare site source
5568
shell: bash
69+
env:
70+
CONTENT_REF: ${{ github.event_name == 'pull_request' && github.sha || github.ref_name }}
5671
run: |
5772
set -euo pipefail
5873
rm -rf .site-src _site
@@ -67,9 +82,9 @@ jobs:
6782
README_URL=""
6883
6984
if [ -f README.md ]; then
70-
README_URL="${REPO_URL}/blob/${{ github.ref_name }}/README.md"
85+
README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.md"
7186
elif [ -f README.adoc ]; then
72-
README_URL="${REPO_URL}/blob/${{ github.ref_name }}/README.adoc"
87+
README_URL="${REPO_URL}/blob/${CONTENT_REF}/README.adoc"
7388
fi
7489
7590
{
@@ -87,7 +102,7 @@ jobs:
87102
echo "- README: [project README](${README_URL})"
88103
fi
89104
if [ -d docs ]; then
90-
echo "- Docs directory: [docs/](${REPO_URL}/tree/${{ github.ref_name }}/docs)"
105+
echo "- Docs directory: [docs/](${REPO_URL}/tree/${CONTENT_REF}/docs)"
91106
fi
92107
echo
93108
echo "Project-specific site content can be added later under site/."
@@ -97,7 +112,7 @@ jobs:
97112
- name: Build site
98113
run: |
99114
mkdir -p _site
100-
cd .casket-ssg && cabal run casket-ssg -- build ../.site-src ../_site
115+
cd .casket-ssg && cabal run --index-state=2026-09-06T00:00:00Z casket-ssg -- build ../.site-src ../_site
101116
touch ../_site/.nojekyll
102117
103118
- name: Setup Pages
@@ -108,13 +123,83 @@ jobs:
108123
with:
109124
path: '_site'
110125

126+
preview:
127+
name: Validate Pages artifact
128+
if: github.event_name == 'pull_request'
129+
runs-on: ubuntu-24.04
130+
needs: build
131+
timeout-minutes: 10
132+
permissions:
133+
actions: read
134+
contents: read
135+
steps:
136+
- name: Download Pages artifact
137+
uses: actions/download-artifact@v8.0.1
138+
with:
139+
name: github-pages
140+
path: .pages-preview
141+
142+
- name: Validate deployable artifact
143+
shell: bash
144+
run: |
145+
set -euo pipefail
146+
147+
artifact=".pages-preview/artifact.tar"
148+
entries_file="${RUNNER_TEMP}/pages-preview-entries.txt"
149+
150+
if [ ! -s "${artifact}" ]; then
151+
echo "::error::Pages artifact is absent or empty"
152+
exit 1
153+
fi
154+
155+
tar -tf "${artifact}" > "${entries_file}"
156+
157+
entry_count=0
158+
has_index=0
159+
while IFS= read -r entry; do
160+
entry_count=$((entry_count + 1))
161+
case "${entry}" in
162+
/*|../*|*/../*|*/..)
163+
echo "::error::Pages artifact contains an unsafe path: ${entry}"
164+
exit 1
165+
;;
166+
index.html|./index.html)
167+
has_index=1
168+
;;
169+
esac
170+
done < "${entries_file}"
171+
172+
if [ "${entry_count}" -eq 0 ]; then
173+
echo "::error::Pages artifact contains no files"
174+
exit 1
175+
fi
176+
177+
if [ "${has_index}" -ne 1 ]; then
178+
echo "::error::Pages artifact contains no index.html"
179+
exit 1
180+
fi
181+
182+
{
183+
echo "### Pages preview artifact"
184+
echo
185+
echo "- Files: ${entry_count}"
186+
echo "- SHA-256: \`$(sha256sum "${artifact}" | awk '{print $1}')\`"
187+
echo "- Production deployment: intentionally deferred until merge"
188+
} >> "${GITHUB_STEP_SUMMARY}"
189+
111190
deploy:
191+
name: Deploy production Pages site
192+
if: github.event_name != 'pull_request'
112193
environment:
113194
name: github-pages
114195
url: ${{ steps.deployment.outputs.page_url }}
115-
runs-on: ubuntu-latest
196+
runs-on: ubuntu-24.04
116197
needs: build
117198
timeout-minutes: 10
199+
permissions:
200+
contents: read
201+
pages: write
202+
id-token: write
118203
steps:
119204
- name: Deploy to GitHub Pages
120205
id: deployment

‎.github/workflows/codeql.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -46,7 +47,7 @@ jobs:
4647
4748
- name: Validate A2ML manifests
4849
if: steps.detect.outputs.count > 0
49-
uses: hyperpolymath/a2ml-ecosystem/validate-action@main
50+
uses: hyperpolymath/deed-ecosystem/validate-action@main
5051
with:
5152
path: '.'
5253
strict: 'false'

‎.github/workflows/e2e.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -21,3 +22,5 @@ jobs:
2122
run: pip install pyyaml --quiet
2223
- name: Run E2E tests
2324
run: bash tests/e2e.sh
25+
- name: Verify canonical descriptile policy repair
26+
run: bash tests/retired-descriptile-policy-test.sh

‎.github/workflows/governance.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -34,4 +35,4 @@ permissions:
3435

3536
jobs:
3637
governance:
37-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd # main 2026-06-27
38+
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540

‎.github/workflows/hypatia-dispatch-intake.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -30,7 +31,7 @@ permissions:
3031

3132
jobs:
3233
hypatia:
33-
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd
34+
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
3435
secrets: inherit
3536
# Total caller-side wall-clock cap for the reusable. Matches
3637
# Hypatia's `missing_timeout_minutes` rule expectation. The scan is

0 commit comments

Comments
 (0)