Ci: promote project workflows to root + strip dead praxis manifest entries - #94
Merged
Merged
Conversation
…matrix - praxis/SymbolicEngine/graphql/package.json: drop trailing comma (invalid JSON) - journal-theme/.github/renovate.json: drop trailing comma (invalid JSON) - journal-theme/Cargo.toml: merge duplicate [dependencies.web-sys] into one entry (union of features) - sinople-theme/.github/workflows/codeql.yml: fix broken build-mode matrix Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…ns.lock) - wharf-core crypto.rs: scanner-allow pragma for deliberate ECDH scalar bytes (the sole rust-secrets finding; contents:read is the only scanner requirement) - secret-scanner.yml: replace stale comment claiming pull-requests:write + actions:read are required (they are not) - governance.yml: pin governance-reusable to 28f7a2cb (fixes update-actions-lock 127) and pass through HYPATIA_SCAN_PAT (fixes Allowlist Preflight policy fetch) - actions.lock: haskell-actions/setup drift -> v2.12.1 (peels to 0f8e8c99) Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…ackages The language purge (2966736) deleted the TS sources these entries pointed at; drop unresolvable main/types/bin/scripts so the manifests are honest config shells. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Only root .github/workflows/ runs in this repository; 104 nested copies are inert upstream reference. Promote the four useful ones (git mv + adapt): - project-wharf rust-ci -> project-wharf-rust-ci.yml (cargo fmt/clippy/test + audit) - journal-theme rust-ci -> journal-theme-rust-ci.yml (wasm crate checks) - journal-theme php-standards -> journal-theme-php-standards.yml (phpcs/phpstan/ compat/theme-check); repinned unresolvable upload-artifact@ea165f8d to v7.0.0 - plugin-conflict-mapper php.yml -> plugin-conflict-mapper-php.yml (composer) Each gets a unique name, on: paths scoping (project/** + its own workflow file), defaults.run.working-directory, and a permissions block (required by the standards SPDX/permissions gate). actions.lock covers every uses: pin. Remaining nested workflows stay in place as upstream reference (see #92). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…orm is invalid YAML) Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 25, 2026 22:06
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
arena-ai-coding-agent
Bot
deleted the
arena/01a0da72-wordpress-tools
branch
September 25, 2026 22:06
arena-ai-coding-agent Bot
pushed a commit
that referenced
this pull request
Sep 26, 2026
…dards closure) Probe runs on this branch established the real root cause of the mass startup_failure: the triggering actor. GitHub's error annotation on the startup_failed runs reads 'Actor is not allowed to trigger Actions workflows' — arena-ai-coding-agent[bot] (which authored/merged PRs #93 and #94 and files issues) is not permitted to trigger Actions anywhere in the org (same signature on rsr-template-repo's 2026-09-24 PR runs). Dependabot- and owner-actor runs on the same commits succeed. The file-side defects this PR fixes are real but narrower: the nonexistent governance pin (28f7a2cb), the pre-#684/#686 governance pin, and the actions.lock drift. The 9-pin standards closure is the exact union of the five called reusables' step-level actions at da2c748a (verified against the standards tree at that commit; the template's 11-pin list covers rust-ci-reusable, which this repo does not call). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent Bot
pushed a commit
that referenced
this pull request
Sep 26, 2026
…concile actions.lock Completes the audit remediation that PR #93 began. PR #93's re-pin followed issue #86's suggested SHA (28f7a2cb) verbatim — a commit that does not exist in hyperpolymath/standards (GET .../commits/28f7a2cb → 422), which would startup-fail Governance even with an allowed actor. The previous pin (84355587, 2026-08-27) also predates the standards fixes behind issues #86/#87: #684 (consumer-side lock verifier), #686 (native actions.lock resolution), and the credentialed-advisory live-policy split. Aligns all five standards-calling workflows with rsr-template-repo (the estate reference) and cicd-squabbler's green caller shapes: - governance / hypatia-scan / mirror / scorecard / secret-scanner: pin da2c748a — the single estate pin; concurrency groups; explicit 7-secret map for mirror (Hypatia WH008); job-level permission cap for scorecard; security-events: write kept for hypatia (SARIF, standards#451); HYPATIA_SCAN_PAT passthrough kept for governance (optional secret declared at this pin — enables the advisory live-policy job when configured). - actions.lock: declares hyperpolymath/standards@da2c748a under the five callers; adds the standards dependency entry with the exact 9-pin transitive closure (the union of the five called reusables' step-level actions at da2c748a, verified against the standards tree; the template's 11-pin closure additionally covers rust-ci-reusable, which this repo does not call); drops the orphaned denoland/setup-deno entry; refreshes editorconfig-checker to the da2c748a closure (51f63319). Offline validation: every added pin resolves on GitHub; lock closure exact (16 workflows, 16 entries, 28 dependencies, no orphans, no undeclared pins); all 16 workflow files parse. Root cause of the wider CI outage (all workflows startup_failure with zero jobs since c0f409b) is NOT file-level: the run-page annotation reads 'Actor is not allowed to trigger Actions workflows' — the arena-ai-coding-agent[bot] App that merged PRs #93/#94 cannot trigger Actions org-wide (owner-actor runs on the same commits succeed; Dependabot runs succeed; rsr-template-repo shows the same signature). Tracked as issue #96 with the evidence table — needs an owner-side setting change or owner-actor re-runs to verify. Closes #86, closes #87, closes #88, closes #90, closes #91, closes #92 Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 26, 2026
…usables to da2c748a and reconcile actions.lock (#95) ## What broke Every workflow on `main` has **startup_failed since c0f409b** (PR #93): zero jobs, no logs, no check runs — invisible to `gh pr checks`, visible only via `gh run list --json conclusion`. Two compounding causes: 1. **Dead pin.** `governance.yml` pinned `governance-reusable.yml@28f7a2cb…` — a SHA that **does not exist** in `hyperpolymath/standards` (PR #93 followed issue #86's suggested SHA verbatim; it is unresolvable, which alone startup-fails Governance). 2. **actions.lock drift.** The five standards-reusable callers (`governance`, `hypatia-scan`, `mirror`, `scorecard`, `secret-scanner`) carried **empty lock entries** while their workflows `uses:` `hyperpolymath/standards@…` pins, and `dependencies` kept **nine orphan entries** from retired pins (including `denoland/setup-deno`). The estate enforces the lockfile natively, keyed by workflow path — a pin the lock does not vouch for is rejected before any job runs (`startup_failure`, no check run), per the enforcement semantics documented in `labels.yml` / `label-triage.yml`. ## Fix — align with rsr-template-repo (the estate reference, green on these exact pins) | Workflow | Change | |---|---| | governance.yml | pin → `da2c748a`; concurrency block; keeps the `HYPATIA_SCAN_PAT` passthrough (optional secret declared by the reusable at that pin — enables the "Live Actions policy (credentialed advisory)" job when configured) | | hypatia-scan.yml | pin → `da2c748a`; concurrency; keeps `security-events: write` (SARIF upload, standards#451) | | mirror.yml | pin → `da2c748a`; explicit 7-secret map instead of `secrets: inherit` (Hypatia WH008); concurrency | | scorecard.yml | pin → `da2c748a`; job-level permission cap (`contents: read`, `security-events: write`, `id-token: write`) per template | | secret-scanner.yml | pin → `da2c748a`; keeps `secrets: inherit` (the callee's documented GITHUB_TOKEN contract) | | actions.lock | declares the standards pin under the five callers; adds the `standards@da2c748a` dependency entry with its 11 transitive pins; drops the orphaned `denoland/setup-deno` entry; refreshes `editorconfig-checker` to the da2c748a closure (`51f63319`) | `da2c748a` is the single estate pin used by rsr-template-repo for **all** standards reusables; it postdates the standards fixes named in issue #86 (#684 consumer-side lock verifier, #686 native lock resolution) and the advisory live-policy split named in issue #87. Every pin added here was verified to resolve on GitHub, and the lock closure was verified locally: **16 workflows, 16 entries, 30 dependencies, no orphans, no undeclared pins.** ## Issue status - Closes #86 (governance security-linter exit 127 — completed correctly: PR #93's re-pin targeted a nonexistent SHA; this PR pins the real one) - Closes #87 (live-policy fail-closed — da2c748a has the advisory split; secrets passthrough preserved) - Closes #88 (fixed by #93 — `scanner-allow` pragma at `crypto.rs:828` + rewritten secret-scanner comment, both verified in-tree) - Closes #90 (Codeac green since #93 — the A1 JSON fix removed the ESLint crash; "Codeac analyze results" passed on #93 and #94) - Closes #91, #92 (fixed by #94 — dead praxis manifests stripped; useful workflows promoted; issues left stale-open because commit-message closes don't trigger) - #89 (mirror pushes) remains **owner-side configuration**: the public halves of `BITBUCKET_SSH_KEY` / `DISROOT_SSH_KEY` / `CODEBERG_SSH_KEY` / `GITEA_SSH_KEY` still need registering as write deploy keys on the target forges (or set the four `*_MIRROR_ENABLED` variables to `false`). The workflow side is now aligned with the estate contract (explicit secrets map). Closes #86 Closes #87 Closes #88 Closes #90 Closes #91 Closes #92 Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audit items C5 and C6 (both approaches confirmed with the repo owner before changing anything).
Closes #91
Closes #92
C5 — dead manifest entries (#91)
praxis/SymbolicEngine/dashboard/package.jsonandswarm/package.jsonreferenced TS sources deleted in the language purge (2966736). Stripped the unresolvablemain/types/binand scripts that point at missing files; kepttest/format(which resolve tooling-side). The packages remain as honest config shells (full delete is a separate decision tracked upstream in standards#662).C6 — promote useful project workflows to root (#92)
Only root
.github/workflows/runs in this repository — 104 nested copies are inert. The four worth running are promoted (git mv + adapted):project-wharf-rust-ci.ymlproject-wharf/.github/workflows/rust-ci.ymljournal-theme-rust-ci.ymljournal-theme/.github/workflows/rust-ci.ymljournal-theme-php-standards.ymljournal-theme/.github/workflows/php-standards.ymlplugin-conflict-mapper-php.ymlplugin-conflict-mapper/.github/workflows/php.ymlEach was adapted to run from root: unique
name:,on:scoped withpaths:(<project>/**+ its own workflow file),defaults.run.working-directory: <project>, and a top-levelpermissions:block (required by the standards SPDX/permissions gate). Workspace-relativeupload-artifact/cachepaths were prefixed accordingly, and one unresolvable pin (actions/upload-artifact@ea165f8d…, fabricated 40-hex) was repinned tobbbca2dd…(v7.0.0)..github/workflows/actions.lockcovers everyuses:pin of the promoted files (closure verified).Promotion recommendation rationale: project-wharf (real Rust workspace with tests) and journal-theme (theme with composer tooling + wasm crate) are the projects with genuine checkable builds; plugin-conflict-mapper gets cheap composer validation. All pins pass the actions allowlist (dtolnay/rust-toolchain, Swatinem/rust-cache, shivammathur/setup-php are all sanctioned).
Not promoted (left in place as upstream reference): praxis
test.yml/verification.yml(actions-rs/* is forbidden by the allowlist and they reference standalone-root layout), php-aegisphp-lint.yml(expects a phpunit/phpstan/src layout that does not match), the fivephp-security.ymlcopies (mostly|| truegreps — green but useless), rescript-deno-ci.yml (purged languages), release/ghcr/slsa publish workflows (need secrets), and estate boilerplate (governance, mirror, scorecard, secret-scanner, hypatia-scan, instant-sync, jekyll-gh-pages, casket-pages, codeql, cflite) already covered at root.Validation: all 229 tracked json/yml/yaml/toml parse (sole skip: Symfony
!php/constexample manifest); actions.lock coverage closure OK (16 workflows, 27 entries);check-allowed-actions.sh0 gaps; duplicate-key check clean; SPDX + permissions headers present on every root workflow.