Skip to content

fix(ci): repin every dead standards ref to a self-consistent commit - #110

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/e1-complete-pin-repair
Sep 18, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/e1-complete-pin-repair

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Every reusable-workflow ref in this repo pointed at a SHA that is not a commit. Six of the seven distinct dead refs across the estate are BLOB oids -- the generator that wrote them called git hash-object on the reusable workflow FILE where it needed git rev-parse on the commit.

A caller pinned at a non-commit dies at workflow STARTUP: conclusion failure (not startup_failure), ZERO jobs, run name == run path, and neither REST nor GraphQL carries a reason -- only the run page does. A required context whose workflow dies that way never reports at all, so the gate reads as ABSENT rather than failing, and the branch looks clean.

Repinned to da2c748aad55c1a1dcba00b60fe4a35017bc6540.

That SHA is NOT the standards default-branch tip, deliberately. GitHub validates a reusable against the CALLEE repo own .github/workflows/ actions.lock as it exists at that SHA. Dependabot routinely bumps a uses: inside a reusable without regenerating that lock, which makes the newer commit startup-fatal for every caller. Measured across the last 84 standards commits: 43 POISON / 41 SELF-CONSISTENT, alternating. Capability is not monotonic in time, so "bump to HEAD" is the wrong reflex; the tip (317101e0) is itself POISON on four refs. da2c748aad55 is the newest commit that validates against its own lock, and all six reusables this estate calls exist there.

Rows repaired in this repo:
mirror.yml -> mirror-reusable.yml

Claude-Session: https://claude.ai/code/session_01WgqXnnNWBkiKMyUeLqzcuN

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 2 commits September 15, 2026 09:58
Every reusable-workflow ref in this repo pointed at a SHA that is not a
commit. Six of the seven distinct dead refs across the estate are BLOB
oids -- the generator that wrote them called `git hash-object` on the
reusable workflow FILE where it needed `git rev-parse` on the commit.

A caller pinned at a non-commit dies at workflow STARTUP: conclusion
`failure` (not `startup_failure`), ZERO jobs, run name == run path, and
neither REST nor GraphQL carries a reason -- only the run page does. A
required context whose workflow dies that way never reports at all, so
the gate reads as ABSENT rather than failing, and the branch looks clean.

Repinned to da2c748aad55c1a1dcba00b60fe4a35017bc6540.

That SHA is NOT the standards default-branch tip, deliberately. GitHub
validates a reusable against the CALLEE repo own .github/workflows/
actions.lock as it exists at that SHA. Dependabot routinely bumps a
`uses:` inside a reusable without regenerating that lock, which makes the
newer commit startup-fatal for every caller. Measured across the last 84
standards commits: 43 POISON / 41 SELF-CONSISTENT, alternating. Capability
is not monotonic in time, so "bump to HEAD" is the wrong reflex; the tip
(317101e0) is itself POISON on four refs. da2c748aad55 is the newest commit that
validates against its own lock, and all six reusables this estate calls
exist there.

Rows repaired in this repo:
  mirror.yml                   -> mirror-reusable.yml

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01WgqXnnNWBkiKMyUeLqzcuN
@hyperpolymath
hyperpolymath merged commit 2c0ed97 into main Sep 18, 2026
8 checks passed
@coderabbitai

coderabbitai Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath deleted the fix/e1-complete-pin-repair branch September 18, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant