Skip to content

fix(ci): pin standards reusables to default-branch HEAD - #76

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/bump-diverged-standards-pin
Sep 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/bump-diverged-standards-pin

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Re-points this repo's hyperpolymath/standards reusable-workflow pins at the standards default-branch HEAD, 8f2ee50841e216cd8c192eeb68953118190f105c.

Why this is not a routine version bump. uses: org/repo/.github/workflows/x.yml@<ref> is resolved at workflow startup, so a bad ref is not a failing job — it is no job at all. This campaign repairs three kinds of drift and does not assume which one this repo had:

  • an unreachable sha kills the run before any job is created, so GitHub reports no check at all rather than a failing one: the gate does not go red, it disappears, and gh pr checks simply lists fewer rows. A repo in this state looks greener than one with working gates;
  • a floating ref such as @main runs, but unpinned — the supply-chain property the estate pins for is absent;
  • a stale but reachable sha runs the reusable as it was, silently reintroducing every bug fixed since it.

The refs this repo was actually pinned to, before this PR: 84355587cb2a1f86e6882de83514a32db2646e7a main.

Expect this PR to surface failures that main does not show. Those failures are revealed, not introduced — they are the gates resuming work after being silently absent. The honest comparison is the set of check names emitted here versus on main, not pass/fail counts. On the canary (hyperpolymath/empty-linter#79) the governance suite was absent on main and emitted 25 checks once repaired.

The target is default-branch HEAD resolved at sweep time, never a sha copied from a plan: a reachable but non-HEAD sha silently reintroduces every bug fixed since it.

Engine: .git-private-farm/scripts/smtp-notify-sweep.sh --campaign campaigns/pin-repair.sh. Verification for this repo: files=3 pins=3 perms=0 permlines=0 from=84355587cb2a1f86e6882de83514a32db2646e7a,main target=8f2ee508 sig=G e928b07 canon=a7325fbdc356 base=main

🤖 Generated with Claude Code

https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB

This repo's standards reusable pins are re-pointed at the standards default-branch HEAD, resolved live at sweep time. The prior refs are recorded in the verification line below. Three kinds of drift are repaired together and the body does not claim which one this repo had: an UNREACHABLE sha kills the run at workflow STARTUP, so GitHub reports no check at all rather than a failing one and the gate disappears instead of going red; a FLOATING ref (@main) is unpinned supply chain; a merely STALE but reachable sha silently reintroduces every bug fixed since it. files=3 pins=3 perms=0 permlines=0 from=84355587cb2a1f86e6882de83514a32db2646e7a,main target=8f2ee508

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f56796b9-7d08-4a7e-a3af-15f21bb388b2

📥 Commits

Reviewing files that changed from the base of the PR and between d577515 and e928b07.

📒 Files selected for processing (3)
  • .github/workflows/governance.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (17)
  • GitHub Check: Hypatia
  • GitHub Check: Dogfooding compliance summary
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: panic-attack assail
  • GitHub Check: Hypatia neurosymbolic scan
  • GitHub Check: Hypatia Neurosymbolic Analysis
  • GitHub Check: skeleton-drift
  • GitHub Check: github-advanced-security
⚠️ CI failures not shown inline (10)

GitHub Actions: Estate Rules / 0_estate-rules.txt: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run bash scripts/check-root-shape.sh .
 �[36;1mbash scripts/check-root-shape.sh .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 FAIL: 4 root entries are not on the allowlist:
   - .githooks/  (directory)
   - CHANGELOG.adoc
   - CONTRIBUTING.adoc
   - SECURITY.adoc
 Either move them into the appropriate subdirectory, or add a justified
 entry to .machine_readable/root-allow.txt.
 ##[error]Process completed with exit code 1.

GitHub Actions: Estate Rules / estate-rules: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run bash scripts/check-root-shape.sh .
 �[36;1mbash scripts/check-root-shape.sh .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 FAIL: 4 root entries are not on the allowlist:
   - .githooks/  (directory)
   - CHANGELOG.adoc
   - CONTRIBUTING.adoc
   - SECURITY.adoc
 Either move them into the appropriate subdirectory, or add a justified
 entry to .machine_readable/root-allow.txt.
 ##[error]Process completed with exit code 1.

GitHub Actions: OpenSSF Compliance / 0_openssf-compliance.txt: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run SECFILE=""
 �[36;1mSECFILE=""�[0m
 �[36;1m[ -f "SECURITY.md" ] && SECFILE="SECURITY.md"�[0m
 �[36;1m[ -f "SECURITY.adoc" ] && SECFILE="SECURITY.adoc"�[0m
 �[36;1m[ -f ".github/SECURITY.md" ] && SECFILE=".github/SECURITY.md"�[0m
 �[36;1m�[0m
 �[36;1mif [ -z "$SECFILE" ]; then�[0m
 �[36;1m  echo "::error::SECURITY.md (or SECURITY.adoc) is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run SECFILE=""
 �[36;1mSECFILE=""�[0m
 �[36;1m[ -f "SECURITY.md" ] && SECFILE="SECURITY.md"�[0m
 �[36;1m[ -f "SECURITY.adoc" ] && SECFILE="SECURITY.adoc"�[0m
 �[36;1m[ -f ".github/SECURITY.md" ] && SECFILE=".github/SECURITY.md"�[0m
 �[36;1m�[0m
 �[36;1mif [ -z "$SECFILE" ]; then�[0m
 �[36;1m  echo "::error::SECURITY.md (or SECURITY.adoc) is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run if [ ! -f "LICENSE" ] && [ ! -f "LICENSE.txt" ] && [ ! -f "LICENSE.md" ]; then
 �[36;1mif [ ! -f "LICENSE" ] && [ ! -f "LICENSE.txt" ] && [ ! -f "LICENSE.md" ]; then�[0m
 �[36;1m  echo "::error::LICENSE file is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run if [ ! -f "CONTRIBUTING.md" ] && [ ! -f "CONTRIBUTING.adoc" ]; then
 �[36;1mif [ ! -f "CONTRIBUTING.md" ] && [ ! -f "CONTRIBUTING.adoc" ]; then�[0m
 �[36;1m  echo "::error::CONTRIBUTING file is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run if [ ! -f "README.md" ] && [ ! -f "README.adoc" ] && [ ! -f "README.rst" ] && [ ! -f "README.txt" ] && [ ! -f "README" ]; then
 �[36;1mif [ ! -f "README.md" ] && [ ! -f "README.adoc" ] && [ ! -f "README.rst" ] && [ ! -f "README.txt" ] && [ ! -f "README" ]; then�[0m
 �[36;1m  echo "::error::README file is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run if [ ! -d ".machine_readable" ]; then
 �[36;1mif [ ! -d ".machine_readable" ]; then�[0m
 �[36;1m  echo "::error::.machine_readable/ directory is required"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run if [ ! -f "CHANGELOG.md" ] && [ ! -f "CHANGELOG.adoc" ] && [ ! -f "CHANGES.md" ]; then
 �[36;1mif [ ! -f "CHANGELOG.md" ] && [ ! -f "CHANGELOG.adoc" ] && [ ! -f "CHANGES.md" ]; then�[0m
 �[36;1m  echo "::error::CHANGELOG.md is required for OpenSSF Best Practices"�[0m

GitHub Actions: OpenSSF Compliance / openssf-compliance: fix(ci): pin standards reusables to default-branch HEAD

Conclusion: failure

View job details

##[group]Run ERRORS=0
 �[36;1mERRORS=0�[0m
 �[36;1mREQUIRED_FILES=""�[0m
 �[36;1m�[0m
 �[36;1m# Collect all required files that exist�[0m
 �[36;1mfor f in SECURITY.md SECURITY.adoc .github/SECURITY.md LICENSE LICENSE.txt \�[0m
 �[36;1m         CONTRIBUTING.md CONTRIBUTING.adoc README.md README.adoc \�[0m
 �[36;1m         .machine_readable/STATE.a2ml .machine_readable/META.a2ml \�[0m
 �[36;1m         .machine_readable/ECOSYSTEM.a2ml CHANGELOG.md CHANGELOG.adoc; do�[0m
 �[36;1m  [ -f "$f" ] && REQUIRED_FILES="$REQUIRED_FILES $f"�[0m
 �[36;1mdone�[0m
 �[36;1m�[0m
 �[36;1mfor f in $REQUIRED_FILES; do�[0m
 �[36;1m  # Match {{ANYTHING}} placeholder tokens�[0m
 �[36;1m  PLACEHOLDERS=$(grep -cE '\{\{[A-Z_]+\}\}' "$f" 2>/dev/null || true)�[0m
 �[36;1m  if [ "$PLACEHOLDERS" -gt 0 ]; then�[0m
 �[36;1m    echo "::error::$f contains $PLACEHOLDERS unfilled {{PLACEHOLDER}} tokens"�[0m
🔇 Additional comments (3)
.github/workflows/governance.yml (1)

37-37: LGTM!

.github/workflows/scorecard.yml (1)

15-15: LGTM!

.github/workflows/secret-scanner.yml (1)

23-23: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated governance, security scorecard, and secret-scanning workflows to use fixed versions of their shared workflows.
    • Improved the reliability and consistency of automated repository checks.

Walkthrough

Three GitHub Actions workflows now reference reusable workflows at the fixed commit 8f2ee50841e216cd8c192eeb68953118190f105c.

Changes

Reusable workflow pinning

Layer / File(s) Summary
Pin workflow references
.github/workflows/governance.yml, .github/workflows/scorecard.yml, .github/workflows/secret-scanner.yml
The governance, Scorecards, and Secret Scanner jobs now use the shared workflow commit SHA instead of mutable or older references.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Merge Risk: ⚪ Minimal · up to e928b

Governance, Scorecards, and Secret Scanner now use a fixed shared workflow revision, improving reproducibility without an identified current merge risk.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the purpose, affected references, risks, and verification results. However, it omits the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections fr… Update the description to use the repository template. Add the required headings, list the three workflow changes, complete the RSR Quality Checklist, and document testing or state why testing is not applicable. Include screenshots or termi…
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarises the main change: pinning standards reusable workflows to the default-branch HEAD commit.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the purpose, affected references, risks, and verification results. However, it omits the required Summary, Changes, RSR Quality Checklist, Testing, and Screenshots sections from the repository template.

Resolution

Update the description to use the repository template. Add the required headings, list the three workflow changes, complete the RSR Quality Checklist, and document testing or state why testing is not applicable. Include screenshots or terminal output if applicable.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🛠️ Fix failing CI checks
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks each workflow line
Fixed commits now hold the sign
Governance hops in steady light
Scorecards rest on pins so tight
Secret scans run neat and bright

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Sep 9, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 91 issues detected

Severity Count
🔴 Critical 10
🟠 High 21
🟡 Medium 60

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action softprops/action-gh-release@v3.0.3 needs attention",
    "type": "unpinned_action",
    "file": "release.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dependabot-automerge.yml",
    "type": "missing_timeout_minutes",
    "file": "dependabot-automerge.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Coding task failed

The task could not be completed. Open the task for details or retry.

@hyperpolymath
hyperpolymath merged commit 6420d4a into main Sep 9, 2026
32 of 40 checks passed
@coderabbitai

coderabbitai Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

✅ Coding Agent task started: View task and status

The task will inspect the CI failures, validate its fix, and open a stacked fix pull request automatically.

Note: Fixing CI failures is a beta feature and may encounter errors. Expect some limitations and changes as we gather feedback and continue to improve it.

⏭️ 4 check(s) skipped — already failing on `main` (not caused by this PR)
  • GitHub Actions: Estate Rules / 0_estate-rules.txt
  • GitHub Actions: Skeleton Drift / 0_skeleton-drift.txt
  • GitHub Actions: OpenSSF Compliance / 0_openssf-compliance.txt
  • GitHub Actions: Static Analysis Gate / 3_Hypatia neurosymbolic scan.txt

@hyperpolymath
hyperpolymath deleted the fix/bump-diverged-standards-pin branch September 9, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant