fix(ci): restore reachable standards workflow pins #118
governance.yml
on: pull_request
governance
/
Check Workflow Staleness
7s
governance
/
Allowlist Preflight
8s
governance
/
Live Actions policy (credentialed advisory)
6s
governance
/
...
/
package anti-pattern policy
6s
governance
/
Guix packaging policy (Nix retired)
8s
governance
/
Security policy checks
6s
governance
/
Code quality + docs
7s
governance
/
Well-Known (RFC 9116 + RSR)
5s
governance
/
Workflow security linter
6s
governance
/
Actions lockfile verify
9s
governance
/
Trusted-base reduction policy
42s
governance
/
Licence consistency
11s
governance
/
Exemption ratchet
9s
governance
/
Debt ratchet
9s
governance
/
Validate Hypatia Baseline
3s
Annotations
4 errors, 2 warnings, and 1 notice
|
governance / Workflow security linter
Process completed with exit code 1.
|
|
governance / Workflow security linter:
.github/workflows/workflow-linter.yml#L0
workflow does not parse; an unloaded workflow produces no check run
|
|
governance / Workflow security linter:
.github/workflows/cargo-audit.yml#L0
workflow does not parse; an unloaded workflow produces no check run
|
|
governance / Code quality + docs
Error: The binary 'ec-linux-amd64*' not found
|
|
governance / Live Actions policy (credentialed advisory)
Live Actions policy was not evaluated: HYPATIA_SCAN_PAT was not supplied by the caller. The separate tree allowlist gate still ran.
|
|
governance / Actions lockfile verify
actions-lock gate: no .github/workflows/actions.lock. All refs are SHA-pinned, but the lockfile becomes REQUIRED on 2026-10-01 (today is 2026-09-04). Run scripts/update-actions-lock.sh.
|
|
governance / Guix packaging policy (Nix retired)
Guix is the estate primary; a sealed container is the accepted escape hatch for the not-in-Guix / non-free tail.
|