Finding
scripts/check-ts-allowlist.deno.js retirement is at phase 2, still open
(task #59). Debtfile.a2ml:91 measured 269 affected repos.
Source: developer/.claude/checkpoints/2026-09-22-pipeline-delivery-summary.md §7-9.
The trap that makes this non-trivial
The helper cannot simply be deleted. It has no live reference at HEAD — the shell
replacement scripts/check-ts-allowlist.sh is now wired in — but 11 of the last 12
governance-reusable.yml revisions invoke it three times each, against today's
scripts/ directory. Callers pinned to those older SHAs fetch the helper at that
moment, so deleting it breaks them.
"No live reference at HEAD" is the wrong question. The right one is: which ref do
consumers pin?
Acceptance criteria
Decision sheet: #787
Finding
scripts/check-ts-allowlist.deno.jsretirement is at phase 2, still open(task #59).
Debtfile.a2ml:91measured 269 affected repos.Source:
developer/.claude/checkpoints/2026-09-22-pipeline-delivery-summary.md§7-9.The trap that makes this non-trivial
The helper cannot simply be deleted. It has no live reference at HEAD — the shell
replacement
scripts/check-ts-allowlist.shis now wired in — but 11 of the last 12governance-reusable.ymlrevisions invoke it three times each, against today'sscripts/directory. Callers pinned to those older SHAs fetch the helper at thatmoment, so deleting it breaks them.
"No live reference at HEAD" is the wrong question. The right one is: which ref do
consumers pin?
Acceptance criteria
governance-reusable.ymlSHAs that callers actually pin isenumerated via
gh apion default branchescheck-ts-allowlist.deno.jsis recordedinvokes it — or callers are bumped first and that bump is verified landed
bash scripts/tests/check-ts-allowlist-test.shstays green (18/18)Decision sheet: #787