Commit c0f409b
Fix: repair config parse errors and unblock main-branch CI (#93)
Audit items A (pure config fixes) and B (diagnose + repair what's
fixable in-repo).
Closes #82
Closes #83
Closes #84
Closes #85
Closes #86
Closes #87
Closes #88
## A — config repairs
- **#82** `praxis/SymbolicEngine/graphql/package.json`: removed trailing
comma → parses; unblocks ESLint-based tools (Codeac) repo-wide.
- **#83** `journal-theme/.github/renovate.json`: removed the one
trailing comma → parses.
- **#84** `journal-theme/Cargo.toml`: merged the duplicate
`[dependencies.web-sys]` into a single entry with the union of 10
features; `tomllib` parse clean (cargo not available in audit sandbox).
- **#85** `sinople-theme/.github/workflows/codeql.yml`: repaired the
broken matrix (orphaned `build-mode: none` lines).
**Parse gate:** all 228 tracked `*.json`/`*.yml`/`*.yaml`/`*.toml` files
now parse (sole skip: `praxis/plugin/config/example-manifest.yml`,
Symfony `!php/const` by design).
## B — CI failure triage
- **#86 (governance/Workflow security linter)**: re-pinned
`governance-reusable` to `28f7a2cb` (the standards commit that ships
`scripts/update-actions-lock.sh`; exit 127 was its absence).
`actions.lock` updated: `haskell-actions/setup` drift → v2.12.1
(annotated tag peels to `0f8e8c99…`, verified via API).
- **#87 (governance/Allowlist Preflight)**: exit 3 = the reusable's
policy fetch is unauthenticated and 404s. Passes `HYPATIA_SCAN_PAT`
through as `policy-token` (same secret as hypatia-scan — already
required by the allowlist checker). **Owner action after merge:** add
repo secret `HYPATIA_SCAN_PAT` if not present.
- **#88 (scan/rust-secrets)**: the single finding is
`wharf-core/src/crypto.rs` deliberate ECDH scalar bytes — annotated with
`// scanner-allow: rust-secrets` (rescan clean). The stale comment in
`secret-scanner.yml` claiming `pull-requests: write` + `actions: read`
are required was wrong — the wrapper only needs `contents: read`;
comment rewritten. (PR-triggered Secret Scanner runs still say "Actor is
not allowed to trigger Actions workflows" — that is the known bot-actor
restriction on `pull_request_target`-adjacent triggers, not a
permissions-block problem; post-merge runs on main are the real signal.)
## B — needs owner config, no code change (#89 left open)
All four mirrors fail at the push step (checkout + ssh-agent succeed;
keys are loaded):
- **mirror-bitbucket**: register `BITBUCKET_SSH_KEY.pub` as a **write**
deploy key on the Bitbucket repo (current key has read-only/no access).
- **mirror-disroot**: register `DISROOT_SSH_KEY.pub` as a write deploy
key on the Gitea repo at git.disroot.org.
- **mirror-codeberg**: register `CODEBERG_SSH_KEY.pub` as a write deploy
key on Codeberg.
- **mirror-gitea**: host `127.0.0.1:3000` comes from `vars.GITEA_HOST` —
set it to the real Gitea host (with scheme/port); also register
`GITEA_SSH_KEY.pub` as a write deploy key there.
- Optional: set `vars.BITBUCKET_SSH_FINGERPRINT` /
`CODEBERG_SSH_FINGERPRINT` / `DISROOT_SSH_FINGERPRINT` to the public-key
fingerprints for auditability.
## B — Codeac (#90, tracked separately, not auto-closed here)
Failing every run because ESLint 8.57.1 crashed on the invalid JSON
fixed in #82 (plus occasional analysis timeouts). With thresholds
unconfigured Codeac reports SUCCESS for any finished analysis, so this
PR is the in-repo fix; verification happens on the post-merge run of
main. If it still fails, the alternative is disabling the GitHub App —
CodeFactor/Semgrep/GitGuardian/Hypatia/gitleaks already cover the
ground.
---------
Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>1 parent b12065e commit c0f409b
8 files changed
Lines changed: 21 additions & 20 deletions
File tree
- .github/workflows
- journal-theme
- .github
- praxis/SymbolicEngine/graphql
- project-wharf/crates/wharf-core/src
- sinople-theme/.github/workflows
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
63 | | - | |
64 | | - | |
65 | | - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
14 | 14 | | |
15 | 15 | | |
16 | 16 | | |
17 | | - | |
18 | | - | |
19 | | - | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
20 | 22 | | |
21 | 23 | | |
22 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
65 | | - | |
| 65 | + | |
66 | 66 | | |
67 | 67 | | |
68 | 68 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| 26 | + | |
| 27 | + | |
26 | 28 | | |
27 | 29 | | |
28 | 30 | | |
29 | 31 | | |
30 | 32 | | |
31 | 33 | | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | 34 | | |
41 | 35 | | |
42 | 36 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
825 | 825 | | |
826 | 826 | | |
827 | 827 | | |
828 | | - | |
| 828 | + | |
| 829 | + | |
829 | 830 | | |
830 | 831 | | |
831 | 832 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
0 commit comments