These reds on main (ba373a8) were present before #399 and are identical on its head (cf51b64). #399 fixes only CodeQL, which moves from startup_failure to success.
| Check context |
Workflow |
State on main and on #399 |
Dependency audit |
Cargo Audit |
failure |
governance / Workflow security linter |
Governance |
failure |
governance / Validate Hypatia Baseline |
Governance |
failure (baseline re-arm tracked in #314) |
lint-workflows |
Workflow Security Linter |
failure |
| (no check-run: dies at startup) |
Rust CI, MVP Smoke (Best Effort), Agda Meta-Checker |
startup_failure |
The startup failures match the 3 error findings that gh actions-lock --no-fix still reports on #399's head. They are in the agda-meta-checker, mvp-smoke and s4-loop lock entries, where the lock and the workflow refs disagree.
Acceptance criteria
🤖 Generated with Claude Code
These reds on
main(ba373a8) were present before #399 and are identical on its head (cf51b64). #399 fixes only CodeQL, which moves fromstartup_failuretosuccess.Dependency auditgovernance / Workflow security lintergovernance / Validate Hypatia Baselinelint-workflowsstartup_failureThe startup failures match the 3
errorfindings thatgh actions-lock --no-fixstill reports on #399's head. They are in theagda-meta-checker,mvp-smokeands4-looplock entries, where the lock and the workflow refs disagree.Acceptance criteria
gh actions-lock --no-fix --jsonreports 0errorfindings. Fix the lock by hand; never use write mode, which corrupts local action refs.main.Dependency audit,governance / Workflow security linterandlint-workflowsare each green, or each remaining finding has its own issue.governance / Validate Hypatia Baselineresolved via Re-arm the hypatia baseline gate: generate .hypatia-baseline.json (152 findings to grandfather + burn down) #314.🤖 Generated with Claude Code