ci(hypatia): fix workflow floor (upload-artifact SHA + setup-beam v1.24.0 + env.HOME) - #37
Merged
Merged
Conversation
…24.0 + env.HOME)
Three independent CI bugs in hypatia-scan.yml that block every consumer of the RSR template floor (echo-types#30 hit all three).
1. actions/upload-artifact pinned to non-existent SHA 65c79d7f...
resolved (canonical v4 SHA) -> ea165f8d65b6e75b540449e92b4886f43607fa02
2. erlef/setup-beam v1.18.2 doesn't support ubuntu-24 (runner image).
bumped -> v1.24.0 (fc68ffb9...)
3. working-directory used ${{ env.HOME }} which expands to empty in
GH Actions context. Switched to shell cd \C:\Users\USER/hypatia` inside
the run script.
This was referenced Sep 9, 2026
hyperpolymath
added a commit
that referenced
this pull request
Sep 12, 2026
Adds `open-pull-requests-limit` to Dependabot update blocks that had no cap, following the estate per-ecosystem cap doctrine (task #37). No other line in the file is touched. Claude-Session: https://claude.ai/code/session_011eQ7hibx92N7fBDtwgReWk <!-- SPDX-License-Identifier: CC-BY-SA-4.0 Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk> --> ## Summary <!-- What does this PR do, and why? --> Closes # ## Type of change - [ ] 🐛 Bug fix (non-breaking change that fixes an issue) - [ ] ✨ New feature (non-breaking change that adds functionality) - [ ] 💥 Breaking change (would change existing behaviour) - [ ] 🕳️ Soundness fix (fixes a checker/proof false-negative) - [ ] 📖 Documentation - [ ] 🧹 Refactor / tech debt (behaviour-preserving) - [ ] ⚡ Performance - [ ] 🔧 Build / CI / tooling ## How has this been verified? <!-- Establish ground truth: which tool did you RUN, and what did it report? Don't cite a status doc — cite the command and its output. --> ## Checklist - [ ] My commits are **signed** (`git commit -S`). - [ ] I ran the project's own checks/tests locally and they pass. - [ ] New files carry the correct `SPDX-License-Identifier` (code/config `MPL-2.0`, prose `CC-BY-SA-4.0`); I did not relicense existing files. - [ ] Docs are updated, and no public claim now overstates what the code does. - [ ] I have not introduced a soundness hole (or I have flagged where I might have). ## Notes for reviewers <!-- Anything that needs special attention, follow-up, or context. --> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 22, 2026
…37) (#979) > **Stacked on #978.** Base is `fix/scorecard-codeql-4380` so this PR shows **only** the docs-gate diff; it auto-retargets to `main` when #978 merges. **Merge #978 first.** ## The defect `check-docs-presence.sh` searched **only the repository root** for CONTRIBUTING, while estate repos have been deliberately relocating the file to `.github/` — the location GitHub itself auto-discovers. From `launch-scaffolder` `d426ea4d`: > the estate canonical location is `.github/CONTRIBUTING.md`, which GitHub auto-discovers So the gate asked *"is there a CONTRIBUTING at the repo root?"* while its consumers had been told to answer *"is there a CONTRIBUTING GitHub can find?"* — a guard asking a different question than its consumer, and the gate lost. ## Census — 516 local clones, 2026-09-22 | location | repos | |---|---| | root | 401 | | `.github/` | 96 | | `docs/` | 1 | | **none anywhere** | **94** | **19 unique repos** were being reported missing a document they demonstrably have, against **94 genuine misses**. For scale, the script's own header records a 2026-07-21 measurement over 412 real repo-root callers: README 0/412 missing, LICENSE 0/412, CONTRIBUTING **54/412**. This **widens WHERE the gate looks without widening WHAT it asks** — the 94 still block. ## Second defect, same file The failure message named only the root locations, so it prescribed a cure **narrower than the code accepts**. Surfaced only by reading the negative control's *output* rather than just its exit code. Same class as #930. ## Tests Four new accept cases — **one per added path**, because a single `.github/CONTRIBUTING.md` case would pass even if only that one path had been added — plus an **anti-overreach** case proving a CONTRIBUTING at an undiscoverable depth (`src/internal/`) still **BLOCKS**. That last one guards against a future "fix" by recursive `find`, which would silently pass all 94 genuinely-missing repos. Suite **29/29**. ## Mutants killed Both leave the pre-existing cases green, so detection is *attributable*: | mutant | result | |---|---| | gate fully reverted to root-only | 25 passed, **4 failed** — exactly the new accept cases | | only `.github/CONTRIBUTING.md` added | 26 passed, **3 failed** — each path individually load-bearing | ## Real-world controls | repo | rc | meaning | |---|---|---| | `launch-scaffolder` | 0 | the repo issue #37 reported missing | | `standards` itself | 0 | via `3-practice/` | | `cicd-suite` | 1 | genuine miss, message correct | ## ⚠ This does not close launch-scaffolder#37 by itself `launch-scaffolder`'s governance job runs this script from its **pinned** `standards` SHA, so it will not see the fix until that pin is bumped. Its `ec-linux-amd64` failure is a separate pre-existing cause and the job conclusion will not flip on this change alone — verify the CONTRIBUTING sub-check by name in the log. Refs hyperpolymath/launch-scaffolder#37, #930 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01WPSJ7fBhVAMcpSffCBWUDo --------- Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three independent CI bugs in
.github/workflows/hypatia-scan.ymlthat block every consumer of the RSR template floor (echo-types#30 hit all three before merge).actions/upload-artifactpinned to non-existent SHA65c79d7f...->ea165f8d65b6e75b540449e92b4886f43607fa02(canonicalv4)erlef/setup-beam@v1.18.2errors on ubuntu-24 runner image (Tried to map a target OS from env. variable 'ImageOS' (got ubuntu24), but failed) ->v1.24.0(fc68ffb9...)working-directory:${{ env.HOME }}/hypatia` resolves to `/hypatia` (env.HOME is unset in GH Actions context). Switched to `cd `\C:\Users\USER/hypatiainside the run script.There is also a separate scanner-exit-1 vs
set -edesign issue (the workflow comment# Warn but don't failintends non-blocking) — out of scope for this PR.