diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index bfad513..62fb8be 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -5,11 +5,11 @@ version: 'v0.0.2' workflows: '.github/workflows/cflite_batch.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63' + - 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' - 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1' '.github/workflows/cflite_pr.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63' + - 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' - 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1' '.github/workflows/checker-scaling.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' @@ -17,7 +17,7 @@ workflows: - 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de' '.github/workflows/codeql.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63' + - 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' '.github/workflows/coverage.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' @@ -25,7 +25,7 @@ workflows: '.github/workflows/governance.yml': - 'hyperpolymath/standards@9e9513b11fff182b08cf8cd6c9c2272460636586' '.github/workflows/hypatia-scan.yml': - - 'hyperpolymath/standards@469605210e767ee94d1c7a9c13cb6a1d0a78cad1' + - 'hyperpolymath/standards@9e9513b11fff182b08cf8cd6c9c2272460636586' '.github/workflows/label-triage.yml': [] '.github/workflows/labels.yml': [] '.github/workflows/lock-sync-gate.yml': [] @@ -111,9 +111,9 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 - 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63': + 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2': ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' owner_id: 9919 repo_id: 259445878 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938': @@ -157,17 +157,6 @@ dependencies: - 'github/codeql-action@f205ea1c3313d32999d8d6a48b4f6530d4437b38' - 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc' - 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555' - 'hyperpolymath/standards@469605210e767ee94d1c7a9c13cb6a1d0a78cad1': - ref: '469605210e767ee94d1c7a9c13cb6a1d0a78cad1' - commit: 'sha1-469605210e767ee94d1c7a9c13cb6a1d0a78cad1' - owner_id: 6759885 - repo_id: 1116521501 - uses: - - 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9' - - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' - - 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124' - - 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938' 'hyperpolymath/standards@84355587cb2a1f86e6882de83514a32db2646e7a': ref: '84355587cb2a1f86e6882de83514a32db2646e7a' commit: 'sha1-84355587cb2a1f86e6882de83514a32db2646e7a' @@ -188,8 +177,10 @@ dependencies: uses: - 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9' - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' + - 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' - 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c' - 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124' + - 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938' 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc': ref: 'v2.4.4' commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc' diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 0335a36..f1264c4 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -21,6 +21,6 @@ permissions: jobs: hypatia: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@469605210e767ee94d1c7a9c13cb6a1d0a78cad1 + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@9e9513b11fff182b08cf8cd6c9c2272460636586 with: block-on-high: true diff --git a/docs/handoff/issue-207-governance-triage.adoc b/docs/handoff/issue-207-governance-triage.adoc new file mode 100644 index 0000000..7e0c6d9 --- /dev/null +++ b/docs/handoff/issue-207-governance-triage.adoc @@ -0,0 +1,52 @@ +// SPDX-License-Identifier: MPL-2.0 += Issue #207: governance check triage +:revdate: 2026-09-28 + +== Evidence and determination + +Both checks are red on `main` at `5b3a1fde10db4cb379d2022d24409ce9deb3aa10`: +https://github.com/hyperpolymath/my-lang/actions/runs/36444014532[Governance run]. +These are existing base-branch defects, not regressions introduced by this repair. + +* `governance / Check Workflow Staleness`: *fix*, not retire or exempt. + https://github.com/hyperpolymath/my-lang/actions/runs/36444014532/job/109001501889[Job evidence] + identifies Hypatia's Standards pin `469605210e767ee94d1c7a9c13cb6a1d0a78cad1` + as unreachable from Standards main. +* `governance / Workflow security linter`: *fix*, not retire or exempt. + https://github.com/hyperpolymath/my-lang/actions/runs/36444014532/job/109001502084[Job evidence] + fails at upstream pin resolution. Running the canonical resolver locally + reproduces `NOT-ANCESTOR` for the same pin (compare result: diverged). + +== Repair + +Repin Hypatia to `9e9513b11fff182b08cf8cd6c9c2272460636586`, the published +Standards revision already used by governance. GitHub's compare API confirms +it is an ancestor of Standards main. Its Hypatia reusable accepts the existing +`block-on-high` input; keep that input true and retain existing permissions. + +Reconcile `actions.lock` with the new pin, including the combined transitive +requirements of governance and Hypatia at this revision. Also reconcile the +three existing CodeQL workflow entries with their actual `2892aa5...` pin; +main's lock still recorded `b96794f...`. No CodeQL workflow is changed. + +No checks are removed, demoted, skipped, or given an exemption. No required-check +settings are changed. The older Scorecard pin produces an existing advisory +notice, not either failing check's cause; leave it outside this repair. + +== Validation and closure + +Local validation after the repair: + +* Canonical `check-action-pins-resolve.sh`: all eight unique verifiable pins pass. +* `check-workflow-staleness.sh` from the exact governance revision, with full + Standards history and that revision as expected SHA: passes. +* `git diff --check`: passes. + +Local execution of `scripts/check-lock-sync.sh` is blocked by missing GNU awk; +package downloads failed. Installation of `gh actions-lock` also failed because +the release download endpoint returned EOF. The lock reconciliation is manual; +the authoritative lock checks must run in CI before merge. + +Keep issue #207 open until both named checks pass on the PR and subsequently +on the default branch. Local component passes are not a claim that the complete +Workflow security linter job, or default-branch acceptance criteria, are green.