Inventory: 47 reusable workflows (blocked 3, partial-runtime 1, runtime-proven 41, unverified 2).
Only runtime-proven means an observed successful workflow_call run for
the current workflow digest. Every other row is explicit debt; static
validation and skipped jobs are not runtime evidence.
| Workflow | Criticality | Status | Risk | Barrier | Required capability | Handoff |
|---|---|---|---|---|---|---|
.github/workflows/actionlint.yml |
required-gate |
runtime-proven |
— |
— |
— | — |
.github/workflows/benchmark-compare.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/benchmark.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/clusterfuzzlite.yml |
supporting |
unverified |
high |
specialized-harness |
OSS-Fuzz-shaped .clusterfuzzlite build image and executable fuzz target. | issue |
.github/workflows/container-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/coverage-gate.yml |
required-gate |
runtime-proven |
— |
— |
— | — |
.github/workflows/cpp-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/cross-platform-smoke.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/dart-flutter-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/docs-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/docs-quality.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/dotnet-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/fuzzing.yml |
supporting |
unverified |
high |
specialized-harness |
Rust nightly cargo-fuzz project with an executable fuzz target. | issue |
.github/workflows/gate.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/go-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/grype-scan.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/hadolint-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/iac-scan.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/java-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/kotlin-android-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/monorepo-changed-paths.yml |
required-gate |
runtime-proven |
— |
— |
— | — |
.github/workflows/mutation-testing.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/node-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/osv-scan.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/pr-hygiene.yml |
required-gate |
partial-runtime |
high |
event-context |
Isolated stale issue/PR population where every mutation and restoration can be scoped and observed. | issue |
.github/workflows/private-static.yml |
required-gate |
runtime-proven |
— |
— |
— | — |
.github/workflows/public-codeql.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/public-dependency-review.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/public-scorecard-analysis.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/public-scorecard-json.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/public-scorecard.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/python-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/qt-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/r-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/release-promotion-gate.yml |
release |
blocked |
critical |
external-authority |
GitHub-verified maintainer signing identity, private control-plane read authority, exact promotion record, numeric tag and protected release environment. | issue |
.github/workflows/release-supply-chain-free.yml |
release |
blocked |
critical |
destructive-release |
Dedicated disposable repository where publishing and deleting a unique release/tag cannot affect consumers or protected project history. | issue |
.github/workflows/release-supply-chain.yml |
release |
blocked |
critical |
destructive-release |
Dedicated disposable public repository authorized for release publication and irreversible Sigstore transparency-log attestations. | issue |
.github/workflows/rust-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/rust-supply-chain.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/secret-scan.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/semgrep-ci.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/sql-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/swift-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/terraform-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/web-ci.yml |
supporting |
runtime-proven |
— |
— |
— | — |
.github/workflows/zizmor-no-sarif.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
.github/workflows/zizmor-sarif.yml |
security-blocking |
runtime-proven |
— |
— |
— | — |
Generated from catalog/runtime-coverage.yml.