Skip to content

fix(ci): restore workflows from startup_failure — re-pin standards reusables to da2c748a and reconcile actions.lock - #95

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0df21-wordpress-tools
Sep 26, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0df21-wordpress-tools

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

What broke

Every workflow on main has startup_failed since c0f409b (PR #93): zero jobs, no logs, no check runs — invisible to gh pr checks, visible only via gh run list --json conclusion. Two compounding causes:

  1. Dead pin. governance.yml pinned governance-reusable.yml@28f7a2cb… — a SHA that does not exist in hyperpolymath/standards (PR Fix: repair config parse errors and unblock main-branch CI #93 followed issue B1: governance / Workflow security linter fails (exit 127) — pin predates standards #684/#686 #86's suggested SHA verbatim; it is unresolvable, which alone startup-fails Governance).
  2. actions.lock drift. The five standards-reusable callers (governance, hypatia-scan, mirror, scorecard, secret-scanner) carried empty lock entries while their workflows uses: hyperpolymath/standards@… pins, and dependencies kept nine orphan entries from retired pins (including denoland/setup-deno). The estate enforces the lockfile natively, keyed by workflow path — a pin the lock does not vouch for is rejected before any job runs (startup_failure, no check run), per the enforcement semantics documented in labels.yml / label-triage.yml.

Fix — align with rsr-template-repo (the estate reference, green on these exact pins)

Workflow Change
governance.yml pin → da2c748a; concurrency block; keeps the HYPATIA_SCAN_PAT passthrough (optional secret declared by the reusable at that pin — enables the "Live Actions policy (credentialed advisory)" job when configured)
hypatia-scan.yml pin → da2c748a; concurrency; keeps security-events: write (SARIF upload, standards#451)
mirror.yml pin → da2c748a; explicit 7-secret map instead of secrets: inherit (Hypatia WH008); concurrency
scorecard.yml pin → da2c748a; job-level permission cap (contents: read, security-events: write, id-token: write) per template
secret-scanner.yml pin → da2c748a; keeps secrets: inherit (the callee's documented GITHUB_TOKEN contract)
actions.lock declares the standards pin under the five callers; adds the standards@da2c748a dependency entry with its 11 transitive pins; drops the orphaned denoland/setup-deno entry; refreshes editorconfig-checker to the da2c748a closure (51f63319)

da2c748a is the single estate pin used by rsr-template-repo for all standards reusables; it postdates the standards fixes named in issue #86 (#684 consumer-side lock verifier, #686 native lock resolution) and the advisory live-policy split named in issue #87. Every pin added here was verified to resolve on GitHub, and the lock closure was verified locally: 16 workflows, 16 entries, 30 dependencies, no orphans, no undeclared pins.

Issue status

Closes #86
Closes #87
Closes #88
Closes #90
Closes #91
Closes #92

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 7adcf854-ea1f-4e8b-a3d7-60425d044517

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…concile actions.lock

Completes the audit remediation that PR #93 began. PR #93's re-pin
followed issue #86's suggested SHA (28f7a2cb) verbatim — a commit that
does not exist in hyperpolymath/standards (GET .../commits/28f7a2cb →
422), which would startup-fail Governance even with an allowed actor.
The previous pin (84355587, 2026-08-27) also predates the standards
fixes behind issues #86/#87: #684 (consumer-side lock verifier),
#686 (native actions.lock resolution), and the credentialed-advisory
live-policy split.

Aligns all five standards-calling workflows with rsr-template-repo
(the estate reference) and cicd-squabbler's green caller shapes:

- governance / hypatia-scan / mirror / scorecard / secret-scanner:
  pin da2c748a — the single estate pin; concurrency groups; explicit
  7-secret map for mirror (Hypatia WH008); job-level permission cap
  for scorecard; security-events: write kept for hypatia (SARIF,
  standards#451); HYPATIA_SCAN_PAT passthrough kept for governance
  (optional secret declared at this pin — enables the advisory
  live-policy job when configured).
- actions.lock: declares hyperpolymath/standards@da2c748a under the
  five callers; adds the standards dependency entry with the exact
  9-pin transitive closure (the union of the five called reusables'
  step-level actions at da2c748a, verified against the standards tree;
  the template's 11-pin closure additionally covers rust-ci-reusable,
  which this repo does not call); drops the orphaned
  denoland/setup-deno entry; refreshes editorconfig-checker to the
  da2c748a closure (51f63319).

Offline validation: every added pin resolves on GitHub; lock closure
exact (16 workflows, 16 entries, 28 dependencies, no orphans, no
undeclared pins); all 16 workflow files parse.

Root cause of the wider CI outage (all workflows startup_failure with
zero jobs since c0f409b) is NOT file-level: the run-page annotation
reads 'Actor is not allowed to trigger Actions workflows' — the
arena-ai-coding-agent[bot] App that merged PRs #93/#94 cannot trigger
Actions org-wide (owner-actor runs on the same commits succeed;
Dependabot runs succeed; rsr-template-repo shows the same signature).
Tracked as issue #96 with the evidence table — needs an owner-side
setting change or owner-actor re-runs to verify.

Closes #86, closes #87, closes #88, closes #90, closes #91, closes #92

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@arena-ai-coding-agent
arena-ai-coding-agent Bot force-pushed the arena/01a0df21-wordpress-tools branch from 8a37d21 to d7de6c5 Compare September 26, 2026 19:48
@hyperpolymath
hyperpolymath merged commit d8b1c8c into main Sep 26, 2026
9 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0df21-wordpress-tools branch September 26, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment