Skip to content

Commit d920aeb

Browse files
fix(ci): restore workflows from startup_failure — re-pin standards reusables to da2c748a and reconcile actions.lock
Every workflow on main has startup_failed since c0f409b (zero jobs, no logs, no check runs). Two compounding causes: 1. governance.yml pinned governance-reusable.yml@28f7a2cb — a SHA that does not exist in hyperpolymath/standards (PR #93 followed issue #86's suggested SHA, which is unresolvable; the only standards pin that matters is the estate pin). 2. .github/workflows/actions.lock had drifted inconsistent: the five standards-reusable callers carried empty lock entries while their workflows use hyperpolymath/standards@ pins, and dependencies kept nine orphan entries from retired pins. The estate enforces the lock natively, keyed by workflow path — a pin the lock does not vouch for is rejected before any job runs (startup_failure, no check run). Align with rsr-template-repo (the estate reference, green on these exact pins): - Re-pin governance / hypatia-scan / mirror / scorecard / secret-scanner reusables to da2c748a — the single estate pin; it contains the standards consumer-side governance fixes (#684/#686 behind issue #86), the advisory live-policy split (#87), and the post-#500 secret scanner. - mirror.yml: explicit 7-secret map (Hypatia WH008) instead of secrets: inherit. - scorecard.yml: job-level permission cap (contents: read, security-events: write, id-token: write) per template. - governance.yml: keep the HYPATIA_SCAN_PAT passthrough (optional secret declared by the reusable at da2c748a). - actions.lock: declare the standards pin under the five callers, add the standards@da2c748a dependency entry with its 11 transitive pins, drop the orphaned denoland/setup-deno entry, refresh editorconfig-checker to the da2c748a closure (51f63319). Closure verified: 16 workflows, 16 entries, 30 dependencies, no orphans, no undeclared pins. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
1 parent db19b12 commit d920aeb

6 files changed

Lines changed: 105 additions & 38 deletions

File tree

‎.github/workflows/actions.lock‎

Lines changed: 45 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -12,8 +12,10 @@ workflows:
1212
- 'actions/deploy-pages@v5.0.1'
1313
- 'actions/upload-pages-artifact@v5.0.0'
1414
- 'haskell-actions/setup@v2.12.1'
15-
'.github/workflows/governance.yml': []
16-
'.github/workflows/hypatia-scan.yml': []
15+
'.github/workflows/governance.yml':
16+
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
17+
'.github/workflows/hypatia-scan.yml':
18+
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
1719
'.github/workflows/instant-sync.yml':
1820
- 'peter-evans/repository-dispatch@v4.0.1'
1921
'.github/workflows/journal-theme-php-standards.yml':
@@ -27,7 +29,8 @@ workflows:
2729
- 'dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87'
2830
'.github/workflows/label-triage.yml': []
2931
'.github/workflows/labels.yml': []
30-
'.github/workflows/mirror.yml': []
32+
'.github/workflows/mirror.yml':
33+
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
3134
'.github/workflows/pages.yml':
3235
- 'actions/checkout@v7.0.1'
3336
- 'actions/deploy-pages@v5.0.1'
@@ -41,8 +44,10 @@ workflows:
4144
- 'dtolnay/rust-toolchain@d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3'
4245
'.github/workflows/push-email-notify.yml':
4346
- 'hyperpolymath/smtp-notify-action@v0.3.0'
44-
'.github/workflows/scorecard.yml': []
45-
'.github/workflows/secret-scanner.yml': []
47+
'.github/workflows/scorecard.yml':
48+
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
49+
'.github/workflows/secret-scanner.yml':
50+
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
4651
dependencies:
4752
'actions/cache@v6.1.0':
4853
ref: 'v6.1.0'
@@ -86,6 +91,23 @@ dependencies:
8691
commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be'
8792
owner_id: 6759885
8893
repo_id: 1352485172
94+
'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540':
95+
ref: 'da2c748aad55c1a1dcba00b60fe4a35017bc6540'
96+
commit: 'sha1-da2c748aad55c1a1dcba00b60fe4a35017bc6540'
97+
owner_id: 6759885
98+
repo_id: 1116521501
99+
uses:
100+
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
101+
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
102+
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
103+
- 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
104+
- 'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393'
105+
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
106+
- 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938'
107+
- 'goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406'
108+
- 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc'
109+
- 'Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
110+
- 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555'
89111
'peter-evans/repository-dispatch@v4.0.1':
90112
ref: 'v4.0.1'
91113
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
@@ -106,26 +128,31 @@ dependencies:
106128
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
107129
owner_id: 44036562
108130
repo_id: 192625955
109-
'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed':
110-
ref: 'v2.0.5'
111-
commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
112-
owner_id: 42048915
113-
repo_id: 356423100
114131
'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772':
115132
ref: 'stable'
116133
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
117134
owner_id: 1940490
118135
repo_id: 260749683
119-
'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c':
120-
ref: 'v2.2.0'
121-
commit: 'sha1-840e866d93b8e032123c23bac69dece044d4d84c'
136+
'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393':
137+
ref: '51f63319f592f97930c73d9c46184d20bd206393'
138+
commit: 'sha1-51f63319f592f97930c73d9c46184d20bd206393'
122139
owner_id: 26415196
123140
repo_id: 297874902
124141
'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124':
125142
ref: 'v1.24.1'
126143
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
127144
owner_id: 47606891
128145
repo_id: 331103973
146+
'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938':
147+
ref: 'cdf488f595d80d6e07e03d4674febd5ab45fa938'
148+
commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938'
149+
owner_id: 9919
150+
repo_id: 259445878
151+
'goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406':
152+
ref: 'abea47f85e598557f500fa1fd2ab7464fcb39406'
153+
commit: 'sha1-abea47f85e598557f500fa1fd2ab7464fcb39406'
154+
owner_id: 1006268
155+
repo_id: 212984112
129156
'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc':
130157
ref: 'v2.4.4'
131158
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
@@ -166,6 +193,11 @@ dependencies:
166193
commit: 'sha1-d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3'
167194
owner_id: 1940490
168195
repo_id: 260749683
196+
'Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6':
197+
ref: '6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
198+
commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
199+
owner_id: 580492
200+
repo_id: 298565987
169201
'Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5':
170202
ref: 'v2'
171203
commit: 'sha1-779680da715d629ac1d338a641029a2f4372abb5'

‎.github/workflows/governance.yml‎

Lines changed: 10 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
# This workflow is managed by gh actions-lock.
22
# SPDX-License-Identifier: MPL-2.0
3-
# This workflow is managed by gh actions-lock.
43
name: Governance
54

65
on:
@@ -10,14 +9,20 @@ on:
109
branches: [main, master]
1110
workflow_dispatch:
1211

12+
concurrency:
13+
group: ${{ github.workflow }}-${{ github.ref }}
14+
cancel-in-progress: true
1315
permissions:
14-
actions: read
16+
actions: read # required by the reusable workflow (staleness check reads workflow runs)
1517
contents: read
1618

1719
jobs:
1820
governance:
19-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a
21+
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
22+
# Optional credentialed live-policy audit. governance-reusable@da2c748
23+
# declares HYPATIA_SCAN_PAT (fine-grained PAT, Administration: read) as an
24+
# optional secret: without it the "Live Actions policy (credentialed
25+
# advisory)" job reports a notice instead of running; with it, the live
26+
# check actually executes. Passing an absent secret is a no-op.
2027
secrets:
21-
# Optional credentialed live-policy audit ("Live Actions policy"
22-
# advisory job). Absent secret => advisory notice, not a red run.
2328
HYPATIA_SCAN_PAT: ${{ secrets.HYPATIA_SCAN_PAT }}

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
# This workflow is managed by gh actions-lock.
22
# SPDX-License-Identifier: MPL-2.0
3-
# This workflow is managed by gh actions-lock.
43
name: Hypatia Security Scan
54

65
on:
@@ -12,11 +11,19 @@ on:
1211
- cron: '0 0 * * 0'
1312
workflow_dispatch:
1413

14+
concurrency:
15+
group: ${{ github.workflow }}-${{ github.ref }}
16+
cancel-in-progress: true
1517
permissions:
16-
actions: read
18+
actions: read # required by the reusable workflow (staleness check reads workflow runs)
1719
contents: read
20+
# MUST be `write`, not `read`. hypatia-scan-reusable.yml declares
21+
# `security-events: write` so it can upload SARIF. A called workflow may
22+
# never request more than its caller grants: if it does, GitHub rejects the
23+
# run at startup, before any job is created — `startup_failure`, zero jobs,
24+
# and `gh run view --log-failed` returns "log not found" (standards#451).
1825
security-events: write
1926

2027
jobs:
2128
hypatia:
22-
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
29+
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540

‎.github/workflows/mirror.yml‎

Lines changed: 18 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,29 @@
11
# This workflow is managed by gh actions-lock.
22
# SPDX-License-Identifier: MPL-2.0
3-
# This workflow is managed by gh actions-lock.
43
name: Mirror to Git Forges
54
on:
65
push:
76
branches: [main]
87
workflow_dispatch:
8+
concurrency:
9+
group: ${{ github.workflow }}-${{ github.ref }}
10+
cancel-in-progress: false
911
permissions:
10-
actions: read
12+
actions: read # required by the reusable workflow (staleness check reads workflow runs)
1113
contents: read
1214
jobs:
1315
mirror:
14-
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d5fe075a50ab3ce4f41614d66ed77f152fda134f
15-
secrets: inherit
16+
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
17+
# Explicit secrets map — no `secrets: inherit` (Hypatia WH008, alert #131).
18+
# All seven are the callee's complete optional contract (standards
19+
# mirror-reusable.yml@da2c748); behaviour is unchanged, future secrets
20+
# are no longer shared implicitly. Forge selection is per-repo via the
21+
# <FORGE>_MIRROR_ENABLED Actions variables.
22+
secrets:
23+
GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }}
24+
BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }}
25+
CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }}
26+
SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }}
27+
DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }}
28+
GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }}
29+
RADICLE_KEY: ${{ secrets.RADICLE_KEY }}

‎.github/workflows/scorecard.yml‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,10 @@
11
# This workflow is managed by gh actions-lock.
22
# SPDX-License-Identifier: MPL-2.0
3-
# This workflow is managed by gh actions-lock.
43
name: Scorecard
54

65
on:
76
schedule:
8-
- cron: "0 0 * * 0"
7+
- cron: '0 0 * * 0'
98
push:
109
branches: [main, master]
1110
workflow_dispatch:
@@ -15,11 +14,18 @@ concurrency:
1514
cancel-in-progress: true
1615

1716
permissions:
18-
actions: read
17+
actions: read # required by the reusable workflow (staleness check reads workflow runs)
1918
contents: read
20-
security-events: write
21-
id-token: write
2219

2320
jobs:
2421
scorecard:
25-
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
22+
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
23+
# Reusable called-workflow permissions are CAPPED by the caller's grants;
24+
# without security-events: write here the scorecard SARIF upload fails with
25+
# startup_failure (hypatia WF018). id-token: write enables OIDC publish.
26+
# The reusable's job self-gates on non-pull_request events, so only
27+
# default-branch publication receives OIDC.
28+
permissions:
29+
contents: read
30+
security-events: write
31+
id-token: write
Lines changed: 10 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
# This workflow is managed by gh actions-lock.
22
# SPDX-License-Identifier: MPL-2.0
3-
# This workflow is managed by gh actions-lock.
43
name: Secret Scanner
54
on:
65
pull_request:
@@ -14,12 +13,16 @@ permissions:
1413
contents: read
1514
jobs:
1615
scan:
17-
# The pinned reusable (post-standards-#500) needs only `contents: read`:
18-
# its gitleaks job runs a pinned checksum-verified binary and posts no PR
19-
# comments, so the old `pull-requests: write` + `actions: read` caller
20-
# guidance is obsolete (see the PERMISSIONS note in the reusable itself).
21-
# A job-level block REPLACES the workflow-level one for this job.
16+
# The reusable (post-standards-#500) needs only `contents: read` for its
17+
# own scans: its gitleaks job runs a pinned checksum-verified binary and
18+
# posts no PR comments, so the old `pull-requests: write` caller guidance
19+
# is obsolete. This job-level block REPLACES the workflow-level one for
20+
# this job — it is the cap GitHub applies to the called workflow.
2221
permissions:
2322
contents: read
24-
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
23+
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
24+
# `secrets: inherit` is required by the callee's contract
25+
# (secret-scanner-reusable.yml@da2c748): without it the inner
26+
# `secrets.GITHUB_TOKEN` reference resolves empty and gitleaks falls back
27+
# to anonymous mode (rate-limited; misses some PRs).
2528
secrets: inherit

0 commit comments

Comments
 (0)