fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure - #100
Conversation
…e startup_failure) Dependabot grouped bump #94 (codeql-action v4.38.0 -> v4.38.1) correlates 1:1 with every codeql.yml / hypatia-scan.yml run failing at startup (0 jobs dispatched, no runner error) from 2026-09-22 03:06 UTC. The same pattern reproduces estate-wide: RED vexometer codeql @v4.38.1 tag startup_failure since 09-21 RED hypatia codeql @1c5b675 (4.38.1) startup_failure since 09-22 RED rsr-template codeql @1c5b675 (4.38.1) startup_failure since 09-15 RED nexia-list codeql @v4.38.1 tag startup_failure since 09-22 GREEN affinescript codeql @v4.38.0 tag pass 09-21 GREEN boj-server codeql @v4.38.0/4.34 pass 09-21 GREEN deed-ecosystem codeql @b96794f0 SHA pass 09-21 Controlled probes (byte-replicas of the failing files under new paths on a scratch branch) DO start, so the file content is valid per se; the v4.38.1 release (tag AND its commit SHA) is being refused at workflow startup on every default-branch-evaluated run. Fully reversible fix: pin to the last green release v4.38.0 by SHA (matches deed-ecosystem, satisfies the repo's sha-pinning policy) until 4.38.1 is cleared. Also fixes governance "Workflow security linter" failure: actions.lock referenced codeql-action@v4.38.0 with no matching uses: entry (drift introduced by dependabot, which does not regenerate the lock). Lock re-keyed to the SHA pin used here. Dependabot guard added: ignore github/codeql-action 4.38.1 so the daily actions group cannot re-merge the broken bump tonight.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (26)
|
| Layer / File(s) | Summary |
|---|---|
Pin CodeQL workflow actions .github/workflows/codeql.yml, .github/workflows/hypatia-scan.yml |
The CodeQL initialisation, analysis, and SARIF upload actions now use commit b96794f015dfd88f77b49b1c93e0fa7110f94c63, annotated as v4.38.0. |
Ignore the rejected Dependabot version .github/dependabot.yml |
Dependabot ignores github/codeql-action version 4.38.1. A comment records the workflow-startup validation failure. |
Priority: ➖ Normal
Estimated code review effort: 1 (Trivial) | ~5 minutes
Change: Bug fix
Merge Risk: ⚪ Minimal · up to ae838
CodeQL and Hypatia remain pinned to v4.38.0, avoiding the reported startup failure with no actionable merge-blocking risk remaining.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly identifies the rollback to the v4.38.0 SHA pin and the CodeQL/Hypatia startup failure it addresses. |
| Description check | ✅ Passed | The description directly explains the v4.38.1 rollback, the startup failure, the Dependabot ignore rule, and the related workflow changes. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit pins the actions tight
At v4.38.0, clear and bright
Dependabot skips the faulty trail
The workflows start without that veil
Three small changes keep the checks in sight
Comment @coderabbitai help to get the list of available commands.
|
🔍 Hypatia Security ScanFindings: 70 issues detected
View findings[
{
"reason": "Required workflow `scorecard.yml` is absent from .github/workflows/. The estate baseline expects it; without it this repository is unscanned for whatever that workflow covers, and its absence is silent — no job fails, because no job runs.",
"type": "missing_workflow",
"file": "scorecard.yml",
"action": "create",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
"type": "download_then_run",
"file": "ui-ci.yml",
"action": "verify_download_integrity",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "boj-build.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "trigger-boj"
},
{
"reason": "Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "build"
},
{
"reason": "Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "deploy"
},
{
"reason": "Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "codeql.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "analyze"
},
{
"reason": "Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "a2ml-validate"
},
{
"reason": "Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "dogfood-summary"
},
{
"reason": "Job `k9-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "k9-validate"
},
{
"reason": "Job `scan` in hypatia-scan.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "hypatia-scan.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "scan"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
…ypassed in #101) (#104) ## Summary PR #101 proved (within ~1h of #100 landing) that the `versions: ["4.38.1"]` ignore rule does **not** stop dependabot from re-raising the blocked bump: it swapped `b96794f0` (v4.38.0 commit, green) for `1c5b675` (the **v4.38.1 commit**, estate-blocked) in SHA form today, while copying my inline "4.38.1 blocked" warning comment verbatim. `1c5b675` fails workflow startup on hypatia and rsr-template proven — merging #101 would have re-broken CodeQL + Hypatia tonight. #101 is closed with a warning comment. This PR upgrades the defence to an **unconditional hold** on `github/codeql-action` (no `versions` key = all updates ignored) until upstream clears 4.38.1 or a newer release is verified green. Comment documents why the versions-scoped rule failed so nobody "tidies" it back. ## Follow-ups outside this PR - Same hold needed in the **standards** canonical dependabot config so other estate repos don't take the SHA-form re-bump either — part of the estate rollback batch. - **Estate alert**: any repo whose dependabot merged the actions group since ~Sep-15 may already have the broken ref (vexometer + hypatia + rsr-template confirmed red). Co-authored-by: Arena Agent <agent@arena.ai>
… to un-startup-kill CI Root cause of the estate-wide startup_failure that killed every workflow on the previous attempt: github/codeql-action v4.38.1 (1c5b675) is rejected by GitHub's workflow-startup validation — any workflow naming it dies at startup with zero jobs. Dependabot #105 bumped codeql.yml/oikosbot.yml to v4.38.1 while leaving actions.lock at v4.38.0, so main inherited both the startup-kill and a lock drift. Changes - codeql.yml (init/analyze) and oikosbot.yml (upload-sarif): pinned to the v4.38.0 SHA b96794f015dfd88f77b49b1c93e0fa7110f94c63, matching the estate rollback precedent (hyperpolymath/nexia-list#100, hyperpolymath/standards#973/#978). persist-credentials: false retained. - .github/dependabot.yml: full hold on github/codeql-action until upstream clears 4.38.1 or a newer release verifies green (a versions-only rule was bypassed by dependabot re-bumping in SHA form elsewhere in the estate). - actions.lock resynced to the workflow YAML (all four lock-sync clauses): * codeql/oikosbot entries -> v4.38.0 SHA form with a dependencies record * coverage.yml plain drift closed: codecov-action v7.1.0 -> v7.1.1 (303a32d, nested github-script use re-verified upstream) and taiki-e/install-action v2.87.13 -> v2.87.17 (94c31af, no nested uses) * pruned the stale slsa-github-generator chain retired by the #91 release rewrite (slsa records + orphaned softprops/upload-artifact leaves) Verified locally: faithful port of scripts/check-lock-sync.sh passes all clauses; every workflow + lockfile + dependabot.yml parses; workflow-linter SPDX/permissions checks pass; zero references to v4.38.1/1c5b675 outside hold comments. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
… — un-startup-kill CI (#107) ## Summary Follow-up to #106. That PR landed the #102 conflict resolution but inherited Dependabot #105's broken state: `github/codeql-action` bumped to **v4.38.1**, a version under an **estate-wide hold** because GitHub's workflow-startup validation rejects it — any workflow naming it dies at startup with zero jobs (hyperpolymath/nexia-list#100, hyperpolymath/standards#973/#978). This is what caused the `startup_failure`s observed while #106 was being verified, and it is still killing **Coverage**, **OikosBot**, and reddening **Governance / Actions lockfile verify** + **Lock Sync Gate** on main. ## Changes - `codeql.yml` (init/analyze) and `oikosbot.yml` (upload-sarif): pinned to the **v4.38.0 SHA** `b96794f` per the estate rollback precedent; `persist-credentials: false` retained. - `.github/dependabot.yml`: full hold on `github/codeql-action` until upstream clears 4.38.1 or a newer release verifies green (the estate measured that a `versions: ["4.38.1"]` rule gets bypassed when dependabot re-raises in SHA form). - `actions.lock` resynced to the workflow YAML (all four `check-lock-sync.sh` clauses): - codeql/oikosbot entries → v4.38.0 SHA form with a matching `dependencies:` record - plain drift closed: `codecov-action` v7.1.0 → v7.1.1 (`303a32d`, nested `github-script` use re-verified upstream) and `taiki-e/install-action` v2.87.13 → v2.87.17 (`94c31af`, no nested uses) - pruned the stale `slsa-github-generator` chain retired by the #91 release rewrite ## Testing - Faithful local port of `scripts/check-lock-sync.sh`: all clauses pass (locked incl. job-level reusable refs, no orphans, transitively closed with 0 dangling edges, full coverage). - Every workflow + lockfile + dependabot.yml parses as YAML. - Workflow Security Linter steps (SPDX headers, permissions) pass locally. - Zero references to v4.38.1/`1c5b675` outside hold comments. <!-- SPDX-License-Identifier: AGPL-3.0-or-later --> Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…estate sweeps (#862) ##⚠️ Before you look at the checks: they will all be red, and it is not this code Every `pull_request` workflow on this branch reports `startup_failure` with zero jobs — **18 of 18**, including workflows this PR never touches. That is not the pin fix failing. It is the same wall the estate's agent-pushed PRs always get (`MetaManifold-WebUI#72`, `oikosbot#107`, both merged on owner review). Established by elimination here: it stayed 18 of 18 with an empty commit and again with the workflow edits removed from the branch entirely. **Rule of thumb, now written into the docs:** if a workflow the PR does not touch fails at startup, the cause is not the PR's contents. Consequence: this PR will sit `BLOCKED` on required checks that can never satisfy. To validate it, push the branch from your own account (`git fetch origin arena/01a0dd51-hypatia && git push my-fork arena/01a0dd51-hypatia:...`), or merge on review. The new `estate-rules` CI job runs the rule tests on any human- or dependabot-authored PR. --- ## What this fixes `github/codeql-action@1c5b6756…` is the commit GitHub rejects at workflow start-up — `startup_failure`, zero jobs, no logs. This repository carries it in `codeql.yml` and `security-policy.yml` under the comment `# v4.38.0`, because the 2026-09-22 rollback was applied as a **relabel**: the pin was renamed, not replaced. `actions.lock` holds the correct `b96794f0…` pin, so the lockfile and the workflows disagree — this PR makes them agree. Same signature as `hyperpolymath/nexia-list#100`, where it was diagnosed and rolled back. Locally re-verified: the two `codeql.yml` sites and the six `security-policy.yml` sites now carry `b96794f0…`, the `uses:` count is unchanged, and no denylisted token remains in either file. ## What it adds The machinery the incident showed was missing, all driven by one policy file (`.machine_readable/merge-orchestration/pr-automerge-policy.json`): | Piece | Purpose | |---|---| | `lib/rules/pin_integrity.ex` | PI001–PI005: denylisted pin, mislabelled pin, locked moving ref, lock/workflow divergence, stale pin — plus the mechanical substitution that refuses to guess | | `lib/rules/pr_automerge.ex` | PA001–PA006: which open PRs are unambiguous bumps/chores, which are poisoned, which need a human | | `test/rules/*.exs` | the incident's own cases as tests, including the poisoned SHA wearing a correct `# v4.38.0` label | | `scripts/sweeps/estate-*.sh` | pin repair, PR disposition, absence intake, estate statistics (`--rewrite`/`--execute` opt-in; dry run by default) | | `docs/operations/estate-automerge.adoc` | the handoff document, including how to tell the two `startup_failure` causes apart | ## Why not a title matcher The estate has 33 open dependency PRs, all titled `chore(deps): bump …`. Twenty-five of them re-introduce the poisoned pin, and at least two hide a major bump (`actions/checkout` v4.1.7 → v7.0.1) behind a grouped-update title. Decisions are made from the diff's `uses:` refs, never from the title or the inline comment. ## Safety properties verified against live data - `--execute` refuses any decision whose PR head moved: tested against all 33 live decisions — **33 refused, 0 applied**. - The live-diff re-proof was run against real PRs: the 5 auto-merge candidates read clean, 3 poisoned ones read poisoned — no false negatives, no false positives. - A repair that cannot be proved is a finding, not an action: substitution refuses without a `known_good_sha`, and refuses if the rewrite would drop a `uses:` site. ## Stats artifact: measured, not assumed `estate-stats.sh --checks` now measures what the dashboard was asked to track and could not: **408 repositories, 350 with a test surface, 58 with none, 120 whose most recent suite failed**. Paging reports 3 critical, 2 warn, 2 unavailable (the bench metrics, for which no producer exists — reported unavailable rather than 0). ## Reflexivity This touches hypatia's own rules and bot directives, which is `NA-005` — proposed, never self-approved. Please review rather than letting a robot merge it. --------- Co-authored-by: hypatia <hypatia@hyperpolymath.invalid> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…e gates behind them (#29) Closes #23. ## What was actually wrong Run logs are unreadable from my environment, so everything below was measured from the Actions/checks API, the upstream repositories, and by running the gate scripts locally against this tree. | Symptom on `main` | Cause | |---|---| | Governance / Hypatia / Scorecard fail in **0 s**, no jobs | #26 pinned them to three `hyperpolymath/standards` SHAs that **do not exist** upstream (`8f31a5a4`, `cc58c0cb`, `8750b94a` → `No commit found for SHA`) | | CodeQL / SonarQube `startup_failure` | `actions.lock` never updated for #26 (codeql SHA, sonar v8.2.2) or #28 | | CodeQL would still die even with the lock fixed | #28 bumped to codeql-action **4.38.1**, which GitHub refuses at startup estate-wide (hyperpolymath/nexia-list#100) | | Workflow Security Linter red | #26 prepended a **second** `gh actions-lock` banner to all 25 workflows, pushing every SPDX header off line 1 | | Lock Sync Gate red | consequence of the above | | Governance (last real run) — Allowlist Preflight, SHA-pin check | stale Aug‑04 standards pin; passes against current standards | | Static Analysis Gate — 3 Hypatia criticals | two banned‑language `.py` mint helpers; `github.actor == 'dependabot[bot]'` gate (RE008) | ## What this PR does **Workflows / lockfile** - All five `standards` reusable-workflow callers pin **one** published commit, `bd9313a6` (main HEAD today). Verified with standards' own `check-workflow-staleness.sh` and `check-action-pins-resolve.sh`. - `codeql.yml` → **v4.38.0** (`b96794f0`, the same SHA standards pins), in this repo's tag+lock convention; `dependabot.yml` ignores exactly `4.38.1` so the grouped bump cannot re-break it. - `actions.lock` resynced and **transitively closed** — new leaf records for the standards record's nested `uses:`, sonar v8.2.2, zero unreferenced records; every `commit:` verified against the upstream peeled tag. - SPDX back on line 1 everywhere; duplicate banners removed. - `scorecard.yml` grants `actions: read` on the calling job (the reusable requires it; job-level permissions replace rather than merge). **Governance @ `bd9313a6`** — every scriptable job run locally: allowlist, pin-existence, staleness, UUID v7, duplicate keys, trusted-base, licence, exemption/debt ratchets, package policy, docs, language policy — all green. - The **new UUID v7 gate** (standard dated 2026‑09‑29) rejected the clade UUIDv5. The identity is now a v7 minted with the `uuid` library: `01a0ed2d-28fe-70cb-8aa6-462024f85795`. The old value was derived, never registered (`registered-in-gv-clade-index = false`), so no alias is carried. `CLAUDE.md` regenerated (uuid + `CLADE@` hash); `just repo-init` now mints v7 rather than deriving v5; the stale `build/templates/` mint leftover is removed.⚠️ This is the one judgement call in the PR — see below. **Static Analysis Gate** - `dependabot-automerge.yml` gates on the PR **author** + same‑repo head, not `github.actor`. - The two Python helpers are replaced by rsr-template-repo's Rust ports (`scripts/*.rs` + `scripts/rust-tool.sh`). Zero Python in the tree. - `timeout-minutes` added on `labels.yml` / `label-triage.yml` (warnings). **Tests** — `tests/workflows/foundation_ci_security_test.sh` now asserts *properties* with negative fixtures (SPDX‑first, lock coverage + closure, single standards revision, CodeQL posture, no actor gates, no Python). It fails on today's `main` and passes here. The previous version and `foundation_ci_fixes_test.sh` snapshotted #26's exact SHAs — including the three forged ones — so they could only agree with the defect; folded into one file. No `continue-on-error` added; no error downgraded to a warning. ## Acceptance criteria from #23 1. **Estate Rules** — already green on `main` since #26 (the issue predates that); unchanged here. 2. **Governance** — forged pins replaced; every job's script passes locally against `standards@bd9313a6`. The UUID v7 gate is a cross-cutting class (rsr-template-repo itself still carries a v5) and belongs in hyperpolymath/standards#994's family; this repo is fixed rather than exempted. 3. **Dogfood Gate** — already green on `main`; unchanged. 4. **Static Analysis Gate** — each critical repaired, none muted. ## Reviewer note The clade UUID change is deliberate and reversible, but it *is* an identity change. If you'd rather keep the v5 and take the gate red until the estate decides how CLADE identities migrate, revert the `CLADE.a2ml` / `CLAUDE.md` / `repo-init.just` hunks and the rest of this PR stands on its own. --------- Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
## Why `main` (`1927641`) is out of sync with its own `actions.lock`. The result is that `Governance Check / Actions lockfile verify` and `actions.lock is in sync` are red on `main`, and `coverage.yml` is startup-dead (run 36163988135, `startup_failure`). Two dependabot merges edited `uses:` lines without the lock: | PR | change | disposition here | |---|---|---| | #108 (grouped) | `github/codeql-action` v4.38.0 → **v4.38.1** (`1c5b675`) in `codeql.yml` ×2 and `oikosbot.yml` ×1 | **reverted** to v4.38.0 `b96794f` | | #122 | `taiki-e/install-action` v2.87.17 → v2.87.18 in `coverage.yml` | **kept**; the lock now follows it | #108 reverts #107's pin. It swapped the SHA underneath HOLD comments that say codeql-action must stay on v4.38.0: v4.38.1 is rejected at workflow startup estate-wide (hyperpolymath/nexia-list#100). The full hold in `.github/dependabot.yml` did not stop it, because an `ignore` rule is bypassed inside a `groups:` update. That is the measured behaviour tracked in hyperpolymath/standards#1037. ## What changed - `codeql.yml:52,57` and `oikosbot.yml:43`: `1c5b675… # v4.38.1` → `b96794f… # v4.38.0`. The HOLD comments already describe this state, so they are unchanged. - `actions.lock`: the `coverage.yml` key and the `dependencies:` record now name `taiki-e/install-action@v2.87.18`. The tag resolves to commit `dfae9bf3d6f6c6f20ef4ebb3486c01a51341ff12`; `owner_id`/`repo_id` are unchanged. ## Evidence: before/after on identical binaries | check | before (`origin/main`) | after (this branch) | |---|---|---| | `scripts/check-lock-sync.sh` | rc=1, **6 FAIL** (codeql, coverage, oikosbot: missing + stale each) | rc=0, **0 FAIL** | | `gh actions-lock --no-fix` | `valid=false`, rc=1: 1 `ref-changed` error + 3 `stale` + 3 `sha-as-ref` + 1 `ref-moved` | `valid=true`, rc=0: 3 `sha-as-ref` (the deliberate HOLD pins) + 1 `ref-moved` (`dogfood-gate.yml` `@main`, out of scope) | | `actionlint` on the 3 edited workflows | — | rc=0 | ## Deliberately not in this PR - **`.github/dependabot.yml`** is untouched. The structural cure for the grouped-update bypass (`exclude-patterns` on the group) is staged, estate-wide policy in hyperpolymath/standards#1037 (AC1 → AC5), and this PR does not pre-empt it. - **codeql-action v4.38.2** exists upstream, but nothing in the estate has verified it yet, so it isn't adopted here. - The in-repo recurrence guard is to make the lock gates **required** on `main`. That is the next step (Tier A close-out), and it needs this PR's runs green first. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01YSq3UodR3CjsuAK5yoTzHF Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
… D118 (supersedes #56) (#58) ## Supersedes #56 This is #56's exact content: the same signed commit `d3afb4e`, directly on `main` `afda1f7`. The only difference is that it leaves out the commit #56 picked up afterwards. - At 10:26:40Z `coderabbitai[bot]` pushed **unsigned** commit `3c4c13d` onto #56 ("docs(wiki): convert README to Markdown and update repository map"). - It was triggered by a "Commit to this branch" checkbox tick on the walkthrough comment, at 10:21:47Z and again at 10:32:47Z. - The tick came from an agent session on the shared account, not from the maintainer. - The commit is off-scope: `.adoc`→`.md` against the estate AsciiDoc convention, unrelated to CI. - `main` carries `required_signatures`, so that unsigned head made **every workflow `startup_failure` (jobs=0)**. - Removing it from #56 in place would need a force-push. Instead, #56 is closed and this PR carries the signed commit alone. Nothing is lost: - `3c4c13d` stays reachable at `refs/pull/56/head`; - it is also preserved in a local git bundle. - If the wiki conversion is wanted, it deserves its own PR and its own decision. ### Why this one is on the critical path for every marid PR `main`'s `code_scanning` rule waits for CodeQL results. The CodeQL workflow on `main` startup-fails, so no PR can currently satisfy the rule; #57 was refused on exactly that. #55's own merge was recorded as a bypass over the same two rules (rule-suite 4234619834: `pull_request` + `code_scanning` "waiting for results from CodeQL"). This PR restores the workflow, so it has to land first. ## What broke main Dependabot **#55** merged one grouped update that did two independent things, each of which kills workflows at startup (zero jobs, no logs): | file | #55 changed | effect | |---|---|---| | `codeql.yml` | `init`/`analyze` → `1c5b675` — the **v4.38.1** commit, estate startup-killer ([nexia-list#100](hyperpolymath/nexia-list#100)). The inline comment still said `# v4.38.0`. | `CodeQL Security Analysis` = `startup_failure` | | `pages.yml` | `haskell-actions/setup` v2.12.0 → **v2.12.1**, with no lock update | `GitHub Pages` = `startup_failure` | The desync also reddens every gate that verifies the lock (Lock Sync, Governance, Workflow Security Linter). ## The fix 1. **Revert both codeql pins to `b96794f`.** That is v4.38.0: annotated tag `4bd7200` → commit `b96794f`, which the lock already binds (v4.38.1 is annotated tag `c23de5a` → commit `1c5b675`). The existing comment is accurate again. 2. **Keep haskell v2.12.1 and lock it:** annotated tag `0f7370c` → commit `0f8e8c9`. The lock delta comes from a sandboxed `gh actions-lock --no-narrow --no-migrate-local-actions` run and is restricted to the four haskell lines, so it matches the tool's own haskell delta line for line. - ⚠ The tool *also* lowercased an unrelated transitive record, `Swatinem/rust-cache` → `swatinem/rust-cache`. That change is **not** taken: it is outside this fix, and ref case is not something to change silently. - The tool also wanted to prepend its banner to `lock-sync-gate.yml`. That is cosmetic, so it is not taken either. 3. **D118: take `github/codeql-action` out of automatic bumps.** It is excluded from the `actions` group and ignored. - Both halves are needed. An `ignore` is bypassed inside a `groups:` update (measured on 15 repos, 2026-09-23). - The dependabot schema itself says an excluded dependency *"will continue to raise single pull requests"*. - From here on, codeql-action is bumped by hand, in the same PR as the lock regeneration. The estate-wide cure stays [standards#1037](hyperpolymath/standards#1037). ## Evidence: matched pairs, same scripts, only the tree differs | check | `main` (`afda1f7`) | this branch | |---|---|---| | `bash scripts/check-lock-sync.sh` | **rc=1**, 4 FAIL (2 missing refs, 2 orphaned entries) | **rc=0**, in sync and transitively closed | | `gh actions-lock --no-fix --json` | `valid=false` | `valid=true`, 0 errors | | verifier warning categories | `ref-moved=4 sha-as-ref=4 stale=4` | `ref-moved=4 sha-as-ref=4` (the orphans are gone, nothing new) | `--no-fix` was confirmed to write nothing: `diff -r` of `.github/` before and after the run was empty. ## Not in this PR (on purpose) - **D63-A**, adding `javascript-typescript` and `rust` to the CodeQL matrix, follows separately. Its acceptance criteria (a planted finding must surface, the coverage fraction recorded) are a quality change, and bundling them would hold the unbreak hostage to new `code_scanning` alerts. - The other red checks on main have separate causes: `docs/wikis/README.adoc` for the Central Estate audit, SonarQube 403 for #49, and the A2ML canon-lockstep gate for #31. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01YSq3UodR3CjsuAK5yoTzHF Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
#2) ## Why this PR exists The compare [main...coderabbit/fix-hypatia-scan-failures/f36ac704](https://github.com/hyperpolymath/CoprocessorRuntime.jl/compare/coderabbit/fix-hypatia-scan-failures/f36ac704?expand=1) **cannot become a PR**. GitHub reports *no common ancestor*: - `main` is `5ce66c6` - `coderabbit/fix-hypatia-scan-failures/f36ac704` is parentless commit `d008687` (“Initialize …”) That orphan tree is an older RSR-template snapshot. The actual Hypatia ignore entries from [rsr-template-repo#89](hyperpolymath/rsr-template-repo#89) (`RE001`/`RE005`/`RE008`) are already on `main`. Merging the orphan would not apply a delta. **Owner action:** delete `coderabbit/fix-hypatia-scan-failures/f36ac704`. This branch shares history with `main`. ## CI that this tree can fix | Check | Cause | Fix here | |---|---|---| | CodeQL / Governance / Rust CI / Code Quality `startup_failure` on #1 | Dependabot bumped `codeql-action` to **4.38.1** (`1c5b675`) and `haskell-actions/setup` to v2.12.1 without regenerating `actions.lock`. 4.38.1 is blocked estate-wide ([nexia-list#100](hyperpolymath/nexia-list#100)). | Revert CodeQL to `b96794f` (v4.38.0, already locked). Revert haskell-actions/setup to v2.12.0. | | Hypatia Security Scan | Reusable at `da2c748` clones **hypatia@HEAD** and `mix escript.build`. Build failed here *and* on hyperpolymath/hypatia after [#863](hyperpolymath/hypatia#863) (same 33s failure). Scanner never ran. | `secrets: inherit` so `HYPATIA_SCAN_PAT` reaches the reusable. **Cannot** cure a broken hypatia HEAD — see [standards#1014](hyperpolymath/standards#1014). | | Lock Sync Gate | Same pin/lock desync, plus missing julia-ci lock records. | Pins match the lock; julia-ci entries added with closed `dependencies:` records. | Full write-up: `docs/status/HYPATIA-GATE.adoc`. ## The library (it was still an unminted spine) `Project.toml` uuid `54e4c7d3-acab-5c3f-ab09-6ee0d181492b` (UUIDv5 of the repo uuid). Zero runtime deps. Tests: Test + Aqua. Honest scope: **contracts, not kernels**. No CUDA/ROCm/Metal. Selection stays in AcceleratorGate.jl. | Piece | Runtime form | Not claimed | |---|---|---| | Choreographic projection | `LaunchPlan` / `project` / `HostRole`/`DeviceRole` | K-CUT (`kcut = :open` unless the transfer is injective) | | Tropical grades | `ResourceGrade`, `tropical_seq` (`+`), `tropical_alt` (`max`) | Lean `ResourceSemiring` | | `hub_ceiling` | `universal_hub_allowed()` throws `HubCeilingRefusal` | A universal vendor adapter | | Echo loss | `TransferMap` + `EchoResidue` | Agda fibres / EchoTypes.jl replay | | Epistemic no-smuggling | device `Knowledge` without `sound=true` is refused | Full warrant calculus | | CNO / OND | `CNOClaim` / `ONDClaim`, default `:unproved` | Coq/Lean proofs; OND-6 | | Janus inversion | `InverseMeta` | januskey's file log | Taken / not-taken from the `-type` repos: `docs/theory/TYPE-INFORMED-BACKENDS.adoc`. ## Wiring across the estate (this session can only push this repo) Exact patches for Hyperpolymath.jl (metal-layer `using` + `Project.toml` uuid) and notes for AcceleratorGate, LowLevel, EchoTypes, EpistemicTypes, QuantumCircuit, FirmwareAudit: `docs/ecosystem/HYPERPOLYMATH-WIRING.adoc` Hyperpolymath.jl is the linking directory; it does not yet name this package. That is a follow-up PR on Hyperpolymath.jl. ## Checklist - [x] Placeholders filled (`scripts/check-no-placeholders.sh` PASS) - [x] SPDX on new Julia sources - [x] No vendor kernels, no `hub` adapter - [x] Julia CI workflow added (1.9 + 1) - [ ] Hypatia scan green *when hypatia HEAD builds* (not this repo) Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>



Summary
Fixes the
CodeQL Security Analysis+Hypatia Security Scanstartup_failurethat has blocked both workflows onmainsince 2026-09-22 03:06 UTC (first failing run: #94's branch; every run since).Root cause
The grouped dependabot bump #94 moved
github/codeql-actionv4.38.0 → v4.38.1 incodeql.yml(init/analyze) andhypatia-scan.yml(upload-sarif). Since that merge, every run of those two workflows fails at startup (0 jobs ever dispatch — no job logs exist). The same signature now reproduces estate-wide, keyed exactly on the codeql-action version:@v4.38.1tag@1c5b675(4.38.1 SHA)@1c5b675(4.38.1 SHA)@v4.38.1tag@v4.38.0tag@v4.34/4.38.0@b96794f0(4.38.0 SHA)The v4.38.1 tag object exists (peeled
1c5b675653bb…) — verified vials-remote/API — but GitHub refuses it at workflow startup (tag and SHA form, per hypatia/rsr-template). Byte-identical replicas of the failing workflows under a new path on a scratch branch do start and execute, so the YAML/content itself is valid; v4.38.1 resolution is rejected by GitHub's actions catalog/policy layer on default-branch-evaluated runs. Exact GitHub-internal reason is not visible from the API (startup_failure runs expose no error text); the behavioural fix is unambiguous: stay on the last green release.Changes
codeql.yml,hypatia-scan.yml: pincodeql-action/*to@b96794f015dfd88f77b49b1c93e0fa7110f94c63(v4.38.0, SHA-pinned — satisfies this repo'ssha_pinning_requiredpolicy and matches the greendeed-ecosystemconfiguration).actions.lock: re-keyed to the SHA pin. This also fixes today'sWorkflow security linterfailure ("lock lists github/codeql-action@v4.38.0 but no workflow uses it") — dependabot bumpeduses:without regenerating the lock; the estate's locked-actions gate caught it exactly as designed.dependabot.yml:ignorerule forgithub/codeql-action@4.38.1so the daily grouped actions update can't re-merge the same broken bump overnight.Verification
The PR itself is the live test:
pull_requestruns of CodeQL and Hypatia on this branch should dispatch jobs (rather than startup_failure). Watch runs above. If either still fails at startup, the remaining levers are owner-side (delete+recreate workflow files to clear the poisoned registration, or repo Settings → Code security / Actions policy review), but the version discriminator evidence says this rollback is the fix.Follow-ups (estate-wide, not in this PR)
codeql-reusable.yml/hypatia-scan-reusable.ymlcurrently pin the 4.38.1 SHA (1c5b675…) and should be re-pinned to v4.38.0 SHA until upstream clears 4.38.1.Rollback of the codeql-action portion of #94; all other bumps in #94 are untouched. See issue #49 for the CI-honesty context — this is precisely the class of failure that used to be invisible.