Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 8 additions & 17 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -5,27 +5,27 @@ version: 'v0.0.2'
workflows:
'.github/workflows/cflite_batch.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63'
- 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
- 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1'
'.github/workflows/cflite_pr.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63'
- 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
- 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1'
'.github/workflows/checker-scaling.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
'.github/workflows/codeql.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63'
- 'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
'.github/workflows/coverage.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
'.github/workflows/governance.yml':
- 'hyperpolymath/standards@9e9513b11fff182b08cf8cd6c9c2272460636586'
'.github/workflows/hypatia-scan.yml':
- 'hyperpolymath/standards@469605210e767ee94d1c7a9c13cb6a1d0a78cad1'
- 'hyperpolymath/standards@9e9513b11fff182b08cf8cd6c9c2272460636586'
'.github/workflows/label-triage.yml': []
'.github/workflows/labels.yml': []
'.github/workflows/lock-sync-gate.yml': []
Expand Down Expand Up @@ -111,9 +111,9 @@ dependencies:
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
owner_id: 47606891
repo_id: 331103973
'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63':
'github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2':
ref: 'v4.38.0'
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938':
Expand Down Expand Up @@ -157,17 +157,6 @@ dependencies:
- 'github/codeql-action@f205ea1c3313d32999d8d6a48b4f6530d4437b38'
- 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc'
- 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555'
'hyperpolymath/standards@469605210e767ee94d1c7a9c13cb6a1d0a78cad1':
ref: '469605210e767ee94d1c7a9c13cb6a1d0a78cad1'
commit: 'sha1-469605210e767ee94d1c7a9c13cb6a1d0a78cad1'
owner_id: 6759885
repo_id: 1116521501
uses:
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
- 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938'
'hyperpolymath/standards@84355587cb2a1f86e6882de83514a32db2646e7a':
ref: '84355587cb2a1f86e6882de83514a32db2646e7a'
commit: 'sha1-84355587cb2a1f86e6882de83514a32db2646e7a'
Expand All @@ -188,8 +177,10 @@ dependencies:
uses:
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
- 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938'
'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc':
ref: 'v2.4.4'
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@ permissions:

jobs:
hypatia:
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@469605210e767ee94d1c7a9c13cb6a1d0a78cad1
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@9e9513b11fff182b08cf8cd6c9c2272460636586
with:
block-on-high: true
52 changes: 52 additions & 0 deletions docs/handoff/issue-207-governance-triage.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
// SPDX-License-Identifier: MPL-2.0
= Issue #207: governance check triage
:revdate: 2026-09-28

== Evidence and determination

Both checks are red on `main` at `5b3a1fde10db4cb379d2022d24409ce9deb3aa10`:
https://github.com/hyperpolymath/my-lang/actions/runs/36444014532[Governance run].
These are existing base-branch defects, not regressions introduced by this repair.

* `governance / Check Workflow Staleness`: *fix*, not retire or exempt.
https://github.com/hyperpolymath/my-lang/actions/runs/36444014532/job/109001501889[Job evidence]
identifies Hypatia's Standards pin `469605210e767ee94d1c7a9c13cb6a1d0a78cad1`
as unreachable from Standards main.
* `governance / Workflow security linter`: *fix*, not retire or exempt.
https://github.com/hyperpolymath/my-lang/actions/runs/36444014532/job/109001502084[Job evidence]
fails at upstream pin resolution. Running the canonical resolver locally
reproduces `NOT-ANCESTOR` for the same pin (compare result: diverged).

== Repair

Repin Hypatia to `9e9513b11fff182b08cf8cd6c9c2272460636586`, the published
Standards revision already used by governance. GitHub's compare API confirms
it is an ancestor of Standards main. Its Hypatia reusable accepts the existing
`block-on-high` input; keep that input true and retain existing permissions.

Reconcile `actions.lock` with the new pin, including the combined transitive
requirements of governance and Hypatia at this revision. Also reconcile the
three existing CodeQL workflow entries with their actual `2892aa5...` pin;
main's lock still recorded `b96794f...`. No CodeQL workflow is changed.

No checks are removed, demoted, skipped, or given an exemption. No required-check
settings are changed. The older Scorecard pin produces an existing advisory
notice, not either failing check's cause; leave it outside this repair.

== Validation and closure

Local validation after the repair:

* Canonical `check-action-pins-resolve.sh`: all eight unique verifiable pins pass.
* `check-workflow-staleness.sh` from the exact governance revision, with full
Standards history and that revision as expected SHA: passes.
* `git diff --check`: passes.

Local execution of `scripts/check-lock-sync.sh` is blocked by missing GNU awk;
package downloads failed. Installation of `gh actions-lock` also failed because
the release download endpoint returned EOF. The lock reconciliation is manual;
the authoritative lock checks must run in CI before merge.

Keep issue #207 open until both named checks pass on the PR and subsequently
on the default branch. Local component passes are not a claim that the complete
Workflow security linter job, or default-branch acceptance criteria, are green.