Repository navigation
Commit a695e37
ci: restore block YAML until the gates read KYAML (#1207)
## Summary
Restores block-style formatting of `.github/workflows/ci-pipeline.yml`.
#1205 removed this repo's duplicate Semgrep scan and, in the same PR,
rewrote the file as KYAML. The KYAML form turned two gates red that read
only block YAML:
- **governance / Workflow security linter**: its duplicate-key check
comes from standards@317101e0 (2026-09-14). Flow-document support landed
later, in standards 13b872c (2026-10-01), so the old copy reads every
step's `name:`/`run:` as a repeat of the previous one and reports
phantom duplicates.
- **lint-workflows** (this repo's `workflow-linter.yml`), where present:
it checks for top-level permissions with `grep -q "^permissions:"`.
KYAML indents that key inside `{`, so the check fails although the
permissions are declared.
The parsed workflow is unchanged, so behaviour does not change. KYAML
conversion waits until both gates read it.
Follow-up to #1205.
## Type of change
- [ ] 🐛 Bug fix: no code change; this clears CI reds the earlier
reformat caused.
- [ ] ✨ New feature: n/a
- [ ] 💥 Breaking change: no
- [ ] 🕳️ Soundness fix: n/a
- [ ] 📖 Documentation: n/a
- [x] 🧹 Refactor / tech debt (behaviour-preserving)
- [ ] ⚡ Performance: n/a
- [x] 🔧 Build / CI / tooling
## 📌 New pins
Head SHA: **`8fd1efea3d2513ec39e2f70a8c8d7904ab20919b`**. No pins added
or changed.
## How has this been verified?
- `yq -o json 'sort_keys(..)'` on `main` @ `bbcc722b` and on this head:
**identical data**.
- The current standards duplicate-key checker passes this file. A
planted duplicate in a KYAML copy is still caught (rc=1), so the KYAML
file was clean and the old checker was wrong.
- `grep -c '^permissions:'` = 1 (was 0 in the KYAML form).
- `actionlint`: same diagnostics as the pre-#1205 file.
- No `uses:` ref changes, so `actions.lock` is unaffected.
## Checklist
- [x] My commits are **signed** (verified `G`).
- [x] I ran the project's own checks/tests locally and they pass: the
checks above. This is formatting only.
- [ ] New files carry the correct SPDX identifier: n/a, no new files.
- [x] Docs are updated, and no public claim now overstates what the code
does: nothing to update.
- [x] I have not introduced a soundness hole.
## Notes for reviewers
Formatting only. The data-identity check is the whole claim.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>1 parent bbcc722 commit a695e37
1 file changed
Lines changed: 1028 additions & 460 deletions
0 commit comments