Skip to content

Commit a695e37

Browse files
ci: restore block YAML until the gates read KYAML (#1207)
## Summary Restores block-style formatting of `.github/workflows/ci-pipeline.yml`. #1205 removed this repo's duplicate Semgrep scan and, in the same PR, rewrote the file as KYAML. The KYAML form turned two gates red that read only block YAML: - **governance / Workflow security linter**: its duplicate-key check comes from standards@317101e0 (2026-09-14). Flow-document support landed later, in standards 13b872c (2026-10-01), so the old copy reads every step's `name:`/`run:` as a repeat of the previous one and reports phantom duplicates. - **lint-workflows** (this repo's `workflow-linter.yml`), where present: it checks for top-level permissions with `grep -q "^permissions:"`. KYAML indents that key inside `{`, so the check fails although the permissions are declared. The parsed workflow is unchanged, so behaviour does not change. KYAML conversion waits until both gates read it. Follow-up to #1205. ## Type of change - [ ] 🐛 Bug fix: no code change; this clears CI reds the earlier reformat caused. - [ ] ✨ New feature: n/a - [ ] 💥 Breaking change: no - [ ] 🕳️ Soundness fix: n/a - [ ] 📖 Documentation: n/a - [x] 🧹 Refactor / tech debt (behaviour-preserving) - [ ] ⚡ Performance: n/a - [x] 🔧 Build / CI / tooling ## 📌 New pins Head SHA: **`8fd1efea3d2513ec39e2f70a8c8d7904ab20919b`**. No pins added or changed. ## How has this been verified? - `yq -o json 'sort_keys(..)'` on `main` @ `bbcc722b` and on this head: **identical data**. - The current standards duplicate-key checker passes this file. A planted duplicate in a KYAML copy is still caught (rc=1), so the KYAML file was clean and the old checker was wrong. - `grep -c '^permissions:'` = 1 (was 0 in the KYAML form). - `actionlint`: same diagnostics as the pre-#1205 file. - No `uses:` ref changes, so `actions.lock` is unaffected. ## Checklist - [x] My commits are **signed** (verified `G`). - [x] I ran the project's own checks/tests locally and they pass: the checks above. This is formatting only. - [ ] New files carry the correct SPDX identifier: n/a, no new files. - [x] Docs are updated, and no public claim now overstates what the code does: nothing to update. - [x] I have not introduced a soundness hole. ## Notes for reviewers Formatting only. The data-identity check is the whole claim. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_013aSu89DNALjTYHBvA6FcoM Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
1 parent bbcc722 commit a695e37

1 file changed

Lines changed: 1028 additions & 460 deletions

File tree

0 commit comments

Comments
 (0)