Skip to content

CI: governance linter calls a missing scripts/update-actions-lock.sh; Allowlist Preflight runs with an empty GH_TOKEN #105

Description

@hyperpolymath

Two governance checks are red on main @ 272d986 with the same errors seen on Dependabot PR #104. Neither is caused by that PR.

check failure
governance / Workflow security linter bash: scripts/update-actions-lock.sh: No such file or directory (exit 127). The step invokes a repo-relative script this repo does not ship (cf. hyperpolymath/standards#930)
governance / Allowlist Preflight GH_TOKEN is empty in the step env, so gh refuses to run, then ERROR: could not read live Actions permissions (exit 3)

Acceptance criteria

  • The linter step no longer calls a missing repo-relative script (self-supplied by the reusable or removed); green on main.
  • Allowlist Preflight receives a token that can read repos/{o}/{r}/actions/permissions, or reports neutral with a reason instead of failing; green or neutral on main.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    choreRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcement

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions