Skip to content

KYAML step 6/6 — workflows, only if step 4 rules them in scope #1025

Description

@hyperpolymath

Step 6 of 6 in the KYAML adoption order fixed by 3-practice/YAML-POLICY.adoc §5.
Blocked by #1024, and gated on the #1023 ruling admitting workflows at all.

Work

Workflows (9,261) — only if step 4 ruled them in scope.

Gate (§5)

Additionally: Dependabot and gh actions-lock either emit KYAML or their
drift is explicitly accepted in writing. Unresolved, this step does not start.

Acceptance criteria

  • KYAML step 4/6 — decide KYAML scope on the evidence (owner ruling) #1023 ruled workflows in scope. Absent that ruling this issue stays shut.
  • Dependabot's emitted YAML: either KYAML, or its drift accepted in writing.
  • gh actions-lock's emitted YAML: same disposition, in writing.
  • gh actions-lock's extractor is tested against flow-style mappings
    before any workflow is converted. It reads step-level uses:; if it cannot
    see them in KYAML, a converted workflow loses its lock coverage and a
    workflow absent from actions.lock dies at startup with jobs=0.
  • actionlint accepts the converted form, or its replacement does.
  • Every converted workflow is verified to have runjobs >= 1 plus an
    executed-step marker, per the KYAML step 1/6 — probe whether GitHub Actions parses a KYAML workflow #1020 method. A green square is not a pass,
    and a startup death is not an honest red.
  • Converted in reversible batches, never estate-wide in one commit.

🤖 Generated with Claude Code

https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions