Skip to content

fix(ci): close the governance gate — SPDX, permissions, SHA pins, reusable bump - #62

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/governance-gate-sweep
Jul 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/governance-gate-sweep

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The governance gate is all-jobs-must-pass, so these ship as one commit;
individually none of them turns the repo green.

  • SPDX line-1 header and a top-level permissions: block on every
    workflow file (the two Workflow security linter checks).
  • Every uses: tag reference resolved to a full 40-hex commit SHA. This
    satisfies the linter and also the repository's own
    sha_pinning_required Actions policy, which refuses @v4 at parse
    time — a refusal that produces no check run at all.
  • hypatia-scan.yml now grants security-events: write. This is not
    cosmetic and is not separable from the pin bump below: at HEAD the
    reusable declares security-events: write where the old pin declared
    read, and a called workflow cannot escalate beyond its caller's
    grant. Bumping the pin without this would fail at parse time.
  • The three reusables watched by the staleness gate (governance,
    hypatia-scan, scorecard) advanced to standards HEAD, which is 62
    commits ahead of the false-green cache fix and includes the
    deny-list-negative fix from standards#524.

mirror-reusable and secret-scanner-reusable are deliberately left on
their current pins: the staleness gate does not watch them, so they are
not holding anything red, and bumping them carries unrelated risk.

Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com

…sable bump

The governance gate is all-jobs-must-pass, so these ship as one commit;
individually none of them turns the repo green.

* SPDX line-1 header and a top-level `permissions:` block on every
  workflow file (the two `Workflow security linter` checks).
* Every `uses:` tag reference resolved to a full 40-hex commit SHA. This
  satisfies the linter and also the repository's own
  `sha_pinning_required` Actions policy, which refuses `@v4` at parse
  time — a refusal that produces no check run at all.
* `hypatia-scan.yml` now grants `security-events: write`. This is not
  cosmetic and is not separable from the pin bump below: at HEAD the
  reusable declares `security-events: write` where the old pin declared
  `read`, and a called workflow cannot escalate beyond its caller's
  grant. Bumping the pin without this would fail at parse time.
* The three reusables watched by the staleness gate (governance,
  hypatia-scan, scorecard) advanced to standards HEAD, which is 62
  commits ahead of the false-green cache fix and includes the
  deny-list-negative fix from standards#524.

`mirror-reusable` and `secret-scanner-reusable` are deliberately left on
their current pins: the staleness gate does not watch them, so they are
not holding anything red, and bumping them carries unrelated risk.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath marked this pull request as ready for review July 21, 2026 20:50
@hyperpolymath
hyperpolymath merged commit 8f84111 into main Jul 21, 2026
24 of 25 checks passed
@hyperpolymath
hyperpolymath deleted the fix/governance-gate-sweep branch July 21, 2026 20:52
@hyperpolymath hyperpolymath added cicd CI/CD: workflows, actions, lockfiles, pins, runners, release gates and removed ci labels Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cicd CI/CD: workflows, actions, lockfiles, pins, runners, release gates config

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant