Skip to content

chore(www): migrate root .well-known/ to www/.well-known/ - #851

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/well-known-to-www
Sep 18, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/well-known-to-www

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Refs rsr-template-repo#119 (stage 5).

Moves the root .well-known/ bundle to the canonical www/.well-known/.
Pure rename, no content change.

Opened and merged directly because this repository's ruleset for main requires changes to go through a pull request. The branch was produced by scripts/sweep-wellknown.sh and verified as an exact rename.

@hyperpolymath
hyperpolymath merged commit a8a2bde into main Sep 18, 2026
@hyperpolymath
hyperpolymath deleted the chore/well-known-to-www branch September 18, 2026 15:29
@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped as selected files did not have any reviewable changes.

💤 Files selected but had no reviewable changes (4)
  • www/.well-known/ai.txt
  • www/.well-known/badges/registry.a2ml
  • www/.well-known/humans.txt
  • www/.well-known/security.txt
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5d487d96-f2dc-44d3-a40f-63a253a2bf47

📥 Commits

Reviewing files that changed from the base of the PR and between 950bbbc and 5ea4219.

📒 Files selected for processing (4)
  • www/.well-known/ai.txt
  • www/.well-known/badges/registry.a2ml
  • www/.well-known/humans.txt
  • www/.well-known/security.txt

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

hyperpolymath added a commit that referenced this pull request Sep 22, 2026
Round 3. #954 merged as 9c256b6 (with its 3 known failures); this PR
carries the two fixes that landed after the merge, rebased onto
main+9c256b67 (+#948, +#952):

1. **Standards map integrity** (`www` unmapped since #851, `SECURITY.md`
unmapped since the #947 squash, `.well-known` entry stale since #851):
replace with `www/` + `SECURITY.md` entries, entry_count 122 -> 123. All
5 assertions pass locally.
2. **Both Hypatia gates**: the real scanner emits `invalid_actions_lock`
TWICE (verified by building Hypatia locally and scanning this tree):
`workflow_audit` (acked in round 2) and WH004 standalone (`rule_module
workflow_hardening`, full path — acked here, 211 -> 212, same #951 root
cause).

Also verified by local full-fidelity scan (194 findings, token-enabled):
the only unacknowledged findings are CI-invisible (git-state dirty-tree
+ code-scanning-alert echoes that need a live PAT — see #957 for the
PAT-refresh tripwire). #948/#952 introduce zero new findings.

Local battery: debt run 0 breached, map rc=0, uses-lock clean, registry
in sync, both ratchets OK, gate keeps nothing CI-visible.

Co-authored-by: hyperpolymath <hyperpolymath@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant