Skip to content

Ci: promote project workflows to root + strip dead praxis manifest entries - #94

Merged
arena-ai-coding-agent[bot] merged 6 commits into
mainfrom
arena/01a0da72-wordpress-tools
Sep 25, 2026
Merged

arena-ai-coding-agent[bot] merged 6 commits into
mainfrom
arena/01a0da72-wordpress-tools

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

Audit items C5 and C6 (both approaches confirmed with the repo owner before changing anything).

Closes #91
Closes #92

C5 — dead manifest entries (#91)

praxis/SymbolicEngine/dashboard/package.json and swarm/package.json referenced TS sources deleted in the language purge (2966736). Stripped the unresolvable main / types / bin and scripts that point at missing files; kept test/format (which resolve tooling-side). The packages remain as honest config shells (full delete is a separate decision tracked upstream in standards#662).

C6 — promote useful project workflows to root (#92)

Only root .github/workflows/ runs in this repository — 104 nested copies are inert. The four worth running are promoted (git mv + adapted):

New root workflow From What it runs
project-wharf-rust-ci.yml project-wharf/.github/workflows/rust-ci.yml cargo fmt/clippy/test + cargo-audit + tarpaulin coverage
journal-theme-rust-ci.yml journal-theme/.github/workflows/rust-ci.yml rustfmt/clippy/test/release for the wasm crate
journal-theme-php-standards.yml journal-theme/.github/workflows/php-standards.yml phpcs + phpstan + PHP/WP compat matrix + theme-check
plugin-conflict-mapper-php.yml plugin-conflict-mapper/.github/workflows/php.yml composer validate + install

Each was adapted to run from root: unique name:, on: scoped with paths: (<project>/** + its own workflow file), defaults.run.working-directory: <project>, and a top-level permissions: block (required by the standards SPDX/permissions gate). Workspace-relative upload-artifact/cache paths were prefixed accordingly, and one unresolvable pin (actions/upload-artifact@ea165f8d…, fabricated 40-hex) was repinned to bbbca2dd… (v7.0.0). .github/workflows/actions.lock covers every uses: pin of the promoted files (closure verified).

Promotion recommendation rationale: project-wharf (real Rust workspace with tests) and journal-theme (theme with composer tooling + wasm crate) are the projects with genuine checkable builds; plugin-conflict-mapper gets cheap composer validation. All pins pass the actions allowlist (dtolnay/rust-toolchain, Swatinem/rust-cache, shivammathur/setup-php are all sanctioned).

Not promoted (left in place as upstream reference): praxis test.yml/verification.yml (actions-rs/* is forbidden by the allowlist and they reference standalone-root layout), php-aegis php-lint.yml (expects a phpunit/phpstan/src layout that does not match), the five php-security.yml copies (mostly || true greps — green but useless), rescript-deno-ci.yml (purged languages), release/ghcr/slsa publish workflows (need secrets), and estate boilerplate (governance, mirror, scorecard, secret-scanner, hypatia-scan, instant-sync, jekyll-gh-pages, casket-pages, codeql, cflite) already covered at root.

Validation: all 229 tracked json/yml/yaml/toml parse (sole skip: Symfony !php/const example manifest); actions.lock coverage closure OK (16 workflows, 27 entries); check-allowed-actions.sh 0 gaps; duplicate-key check clean; SPDX + permissions headers present on every root workflow.

hyperpolymath and others added 6 commits September 25, 2026 22:04
…matrix

- praxis/SymbolicEngine/graphql/package.json: drop trailing comma (invalid JSON)
- journal-theme/.github/renovate.json: drop trailing comma (invalid JSON)
- journal-theme/Cargo.toml: merge duplicate [dependencies.web-sys] into one entry (union of features)
- sinople-theme/.github/workflows/codeql.yml: fix broken build-mode matrix

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…ns.lock)

- wharf-core crypto.rs: scanner-allow pragma for deliberate ECDH scalar bytes
  (the sole rust-secrets finding; contents:read is the only scanner requirement)
- secret-scanner.yml: replace stale comment claiming pull-requests:write +
  actions:read are required (they are not)
- governance.yml: pin governance-reusable to 28f7a2cb (fixes update-actions-lock
  127) and pass through HYPATIA_SCAN_PAT (fixes Allowlist Preflight policy fetch)
- actions.lock: haskell-actions/setup drift -> v2.12.1 (peels to 0f8e8c99)

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…ackages

The language purge (2966736) deleted the TS sources these entries pointed at;
drop unresolvable main/types/bin/scripts so the manifests are honest config shells.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Only root .github/workflows/ runs in this repository; 104 nested copies are
inert upstream reference. Promote the four useful ones (git mv + adapt):
- project-wharf rust-ci -> project-wharf-rust-ci.yml (cargo fmt/clippy/test + audit)
- journal-theme rust-ci -> journal-theme-rust-ci.yml (wasm crate checks)
- journal-theme php-standards -> journal-theme-php-standards.yml (phpcs/phpstan/
  compat/theme-check); repinned unresolvable upload-artifact@ea165f8d to v7.0.0
- plugin-conflict-mapper php.yml -> plugin-conflict-mapper-php.yml (composer)

Each gets a unique name, on: paths scoping (project/** + its own workflow file),
defaults.run.working-directory, and a permissions block (required by the
standards SPDX/permissions gate). actions.lock covers every uses: pin.
Remaining nested workflows stay in place as upstream reference (see #92).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…orm is invalid YAML)

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@arena-ai-coding-agent
arena-ai-coding-agent Bot merged commit db19b12 into main Sep 25, 2026
4 checks passed
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: c9e08496-ff9b-464e-a2a5-44fdeba2adda

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@arena-ai-coding-agent
arena-ai-coding-agent Bot deleted the arena/01a0da72-wordpress-tools branch September 25, 2026 22:06
arena-ai-coding-agent Bot pushed a commit that referenced this pull request Sep 26, 2026
…dards closure)

Probe runs on this branch established the real root cause of the mass
startup_failure: the triggering actor. GitHub's error annotation on the
startup_failed runs reads 'Actor is not allowed to trigger Actions
workflows' — arena-ai-coding-agent[bot] (which authored/merged PRs #93
and #94 and files issues) is not permitted to trigger Actions anywhere
in the org (same signature on rsr-template-repo's 2026-09-24 PR runs).
Dependabot- and owner-actor runs on the same commits succeed.

The file-side defects this PR fixes are real but narrower: the
nonexistent governance pin (28f7a2cb), the pre-#684/#686 governance
pin, and the actions.lock drift. The 9-pin standards closure is the
exact union of the five called reusables' step-level actions at
da2c748a (verified against the standards tree at that commit; the
template's 11-pin list covers rust-ci-reusable, which this repo does
not call).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent Bot pushed a commit that referenced this pull request Sep 26, 2026
…concile actions.lock

Completes the audit remediation that PR #93 began. PR #93's re-pin
followed issue #86's suggested SHA (28f7a2cb) verbatim — a commit that
does not exist in hyperpolymath/standards (GET .../commits/28f7a2cb →
422), which would startup-fail Governance even with an allowed actor.
The previous pin (84355587, 2026-08-27) also predates the standards
fixes behind issues #86/#87: #684 (consumer-side lock verifier),
#686 (native actions.lock resolution), and the credentialed-advisory
live-policy split.

Aligns all five standards-calling workflows with rsr-template-repo
(the estate reference) and cicd-squabbler's green caller shapes:

- governance / hypatia-scan / mirror / scorecard / secret-scanner:
  pin da2c748a — the single estate pin; concurrency groups; explicit
  7-secret map for mirror (Hypatia WH008); job-level permission cap
  for scorecard; security-events: write kept for hypatia (SARIF,
  standards#451); HYPATIA_SCAN_PAT passthrough kept for governance
  (optional secret declared at this pin — enables the advisory
  live-policy job when configured).
- actions.lock: declares hyperpolymath/standards@da2c748a under the
  five callers; adds the standards dependency entry with the exact
  9-pin transitive closure (the union of the five called reusables'
  step-level actions at da2c748a, verified against the standards tree;
  the template's 11-pin closure additionally covers rust-ci-reusable,
  which this repo does not call); drops the orphaned
  denoland/setup-deno entry; refreshes editorconfig-checker to the
  da2c748a closure (51f63319).

Offline validation: every added pin resolves on GitHub; lock closure
exact (16 workflows, 16 entries, 28 dependencies, no orphans, no
undeclared pins); all 16 workflow files parse.

Root cause of the wider CI outage (all workflows startup_failure with
zero jobs since c0f409b) is NOT file-level: the run-page annotation
reads 'Actor is not allowed to trigger Actions workflows' — the
arena-ai-coding-agent[bot] App that merged PRs #93/#94 cannot trigger
Actions org-wide (owner-actor runs on the same commits succeed;
Dependabot runs succeed; rsr-template-repo shows the same signature).
Tracked as issue #96 with the evidence table — needs an owner-side
setting change or owner-actor re-runs to verify.

Closes #86, closes #87, closes #88, closes #90, closes #91, closes #92

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath added a commit that referenced this pull request Sep 26, 2026
…usables to da2c748a and reconcile actions.lock (#95)

## What broke

Every workflow on `main` has **startup_failed since c0f409b** (PR #93):
zero jobs, no logs, no check runs — invisible to `gh pr checks`, visible
only via `gh run list --json conclusion`. Two compounding causes:

1. **Dead pin.** `governance.yml` pinned
`governance-reusable.yml@28f7a2cb…` — a SHA that **does not exist** in
`hyperpolymath/standards` (PR #93 followed issue #86's suggested SHA
verbatim; it is unresolvable, which alone startup-fails Governance).
2. **actions.lock drift.** The five standards-reusable callers
(`governance`, `hypatia-scan`, `mirror`, `scorecard`, `secret-scanner`)
carried **empty lock entries** while their workflows `uses:`
`hyperpolymath/standards@…` pins, and `dependencies` kept **nine orphan
entries** from retired pins (including `denoland/setup-deno`). The
estate enforces the lockfile natively, keyed by workflow path — a pin
the lock does not vouch for is rejected before any job runs
(`startup_failure`, no check run), per the enforcement semantics
documented in `labels.yml` / `label-triage.yml`.

## Fix — align with rsr-template-repo (the estate reference, green on
these exact pins)

| Workflow | Change |
|---|---|
| governance.yml | pin → `da2c748a`; concurrency block; keeps the
`HYPATIA_SCAN_PAT` passthrough (optional secret declared by the reusable
at that pin — enables the "Live Actions policy (credentialed advisory)"
job when configured) |
| hypatia-scan.yml | pin → `da2c748a`; concurrency; keeps
`security-events: write` (SARIF upload, standards#451) |
| mirror.yml | pin → `da2c748a`; explicit 7-secret map instead of
`secrets: inherit` (Hypatia WH008); concurrency |
| scorecard.yml | pin → `da2c748a`; job-level permission cap (`contents:
read`, `security-events: write`, `id-token: write`) per template |
| secret-scanner.yml | pin → `da2c748a`; keeps `secrets: inherit` (the
callee's documented GITHUB_TOKEN contract) |
| actions.lock | declares the standards pin under the five callers; adds
the `standards@da2c748a` dependency entry with its 11 transitive pins;
drops the orphaned `denoland/setup-deno` entry; refreshes
`editorconfig-checker` to the da2c748a closure (`51f63319`) |

`da2c748a` is the single estate pin used by rsr-template-repo for
**all** standards reusables; it postdates the standards fixes named in
issue #86 (#684 consumer-side lock verifier, #686 native lock
resolution) and the advisory live-policy split named in issue #87. Every
pin added here was verified to resolve on GitHub, and the lock closure
was verified locally: **16 workflows, 16 entries, 30 dependencies, no
orphans, no undeclared pins.**

## Issue status

- Closes #86 (governance security-linter exit 127 — completed correctly:
PR #93's re-pin targeted a nonexistent SHA; this PR pins the real one)
- Closes #87 (live-policy fail-closed — da2c748a has the advisory split;
secrets passthrough preserved)
- Closes #88 (fixed by #93 — `scanner-allow` pragma at `crypto.rs:828` +
rewritten secret-scanner comment, both verified in-tree)
- Closes #90 (Codeac green since #93 — the A1 JSON fix removed the
ESLint crash; "Codeac analyze results" passed on #93 and #94)
- Closes #91, #92 (fixed by #94 — dead praxis manifests stripped; useful
workflows promoted; issues left stale-open because commit-message closes
don't trigger)
- #89 (mirror pushes) remains **owner-side configuration**: the public
halves of `BITBUCKET_SSH_KEY` / `DISROOT_SSH_KEY` / `CODEBERG_SSH_KEY` /
`GITEA_SSH_KEY` still need registering as write deploy keys on the
target forges (or set the four `*_MIRROR_ENABLED` variables to `false`).
The workflow side is now aligned with the estate contract (explicit
secrets map).

Closes #86
Closes #87
Closes #88
Closes #90
Closes #91
Closes #92

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant