Skip to content

check-ts-allowlist.deno.js cannot be deleted: 11 of the last 12 governance revisions still invoke it #925

Description

@hyperpolymath

Finding

scripts/check-ts-allowlist.deno.js retirement is at phase 2, still open
(task #59). Debtfile.a2ml:91 measured 269 affected repos.

Source: developer/.claude/checkpoints/2026-09-22-pipeline-delivery-summary.md §7-9.

The trap that makes this non-trivial

The helper cannot simply be deleted. It has no live reference at HEAD — the shell
replacement scripts/check-ts-allowlist.sh is now wired in — but 11 of the last 12
governance-reusable.yml revisions invoke it three times each
, against today's
scripts/ directory. Callers pinned to those older SHAs fetch the helper at that
moment, so deleting it breaks them.

"No live reference at HEAD" is the wrong question. The right one is: which ref do
consumers pin?

Acceptance criteria

  • The set of governance-reusable.yml SHAs that callers actually pin is
    enumerated via gh api on default branches
  • For each, whether it invokes check-ts-allowlist.deno.js is recorded
  • The helper is removed only once no pinned caller reaches a revision that
    invokes it — or callers are bumped first and that bump is verified landed
  • The 269-repo figure is re-measured before action (dated 2026-09-22)
  • bash scripts/tests/check-ts-allowlist-test.sh stays green (18/18)

Decision sheet: #787

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions