Skip to content

fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure - #100

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/codeql-4381-rollback
Sep 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/codeql-4381-rollback

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Fixes the CodeQL Security Analysis + Hypatia Security Scan startup_failure that has blocked both workflows on main since 2026-09-22 03:06 UTC (first failing run: #94's branch; every run since).

Root cause

The grouped dependabot bump #94 moved github/codeql-action v4.38.0 → v4.38.1 in codeql.yml (init/analyze) and hypatia-scan.yml (upload-sarif). Since that merge, every run of those two workflows fails at startup (0 jobs ever dispatch — no job logs exist). The same signature now reproduces estate-wide, keyed exactly on the codeql-action version:

repo ref latest codeql/hypatia status
vexometer @v4.38.1 tag 🔴 startup_failure (since 09-21)
hypatia @1c5b675 (4.38.1 SHA) 🔴 startup_failure
rsr-template-repo @1c5b675 (4.38.1 SHA) 🔴 startup_failure (since ~09-15)
nexia-list @v4.38.1 tag 🔴 startup_failure (since #94)
affinescript @v4.38.0 tag ✅ green 09-21
boj-server @v4.34/4.38.0 ✅ green 09-21
deed-ecosystem @b96794f0 (4.38.0 SHA) ✅ green 09-21

The v4.38.1 tag object exists (peeled 1c5b675653bb…) — verified via ls-remote/API — but GitHub refuses it at workflow startup (tag and SHA form, per hypatia/rsr-template). Byte-identical replicas of the failing workflows under a new path on a scratch branch do start and execute, so the YAML/content itself is valid; v4.38.1 resolution is rejected by GitHub's actions catalog/policy layer on default-branch-evaluated runs. Exact GitHub-internal reason is not visible from the API (startup_failure runs expose no error text); the behavioural fix is unambiguous: stay on the last green release.

Changes

  • codeql.yml, hypatia-scan.yml: pin codeql-action/* to @b96794f015dfd88f77b49b1c93e0fa7110f94c63 (v4.38.0, SHA-pinned — satisfies this repo's sha_pinning_required policy and matches the green deed-ecosystem configuration).
  • actions.lock: re-keyed to the SHA pin. This also fixes today's Workflow security linter failure ("lock lists github/codeql-action@v4.38.0 but no workflow uses it") — dependabot bumped uses: without regenerating the lock; the estate's locked-actions gate caught it exactly as designed.
  • dependabot.yml: ignore rule for github/codeql-action@4.38.1 so the daily grouped actions update can't re-merge the same broken bump overnight.

Verification

The PR itself is the live test: pull_request runs of CodeQL and Hypatia on this branch should dispatch jobs (rather than startup_failure). Watch runs above. If either still fails at startup, the remaining levers are owner-side (delete+recreate workflow files to clear the poisoned registration, or repo Settings → Code security / Actions policy review), but the version discriminator evidence says this rollback is the fix.

Follow-ups (estate-wide, not in this PR)

  • Same rollback needed in vexometer, hypatia, rsr-template-repo, and any other repo that merged the 4.38.1 actions bump (dependabot auto-merge reproduced the break within hours per repo).
  • Standards canonical codeql-reusable.yml / hypatia-scan-reusable.yml currently pin the 4.38.1 SHA (1c5b675…) and should be re-pinned to v4.38.0 SHA until upstream clears 4.38.1.

Rollback of the codeql-action portion of #94; all other bumps in #94 are untouched. See issue #49 for the CI-honesty context — this is precisely the class of failure that used to be invisible.

…e startup_failure)

Dependabot grouped bump #94 (codeql-action v4.38.0 -> v4.38.1) correlates
1:1 with every codeql.yml / hypatia-scan.yml run failing at startup
(0 jobs dispatched, no runner error) from 2026-09-22 03:06 UTC. The same
pattern reproduces estate-wide:

  RED    vexometer  codeql @v4.38.1 tag        startup_failure since 09-21
  RED    hypatia    codeql @1c5b675 (4.38.1)   startup_failure since 09-22
  RED    rsr-template codeql @1c5b675 (4.38.1) startup_failure since 09-15
  RED    nexia-list codeql @v4.38.1 tag        startup_failure since 09-22
  GREEN  affinescript    codeql @v4.38.0 tag   pass 09-21
  GREEN  boj-server      codeql @v4.38.0/4.34  pass 09-21
  GREEN  deed-ecosystem  codeql @b96794f0 SHA  pass 09-21

Controlled probes (byte-replicas of the failing files under new paths on a
scratch branch) DO start, so the file content is valid per se; the
v4.38.1 release (tag AND its commit SHA) is being refused at workflow
startup on every default-branch-evaluated run. Fully reversible fix:
pin to the last green release v4.38.0 by SHA (matches deed-ecosystem,
satisfies the repo's sha-pinning policy) until 4.38.1 is cleared.

Also fixes governance "Workflow security linter" failure: actions.lock
referenced codeql-action@v4.38.0 with no matching uses: entry (drift
introduced by dependabot, which does not regenerate the lock). Lock
re-keyed to the SHA pin used here.

Dependabot guard added: ignore github/codeql-action 4.38.1 so the daily
actions group cannot re-merge the broken bump tonight.
@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: d05345de-4157-4704-90bb-34facbd144e9

📥 Commits

Reviewing files that changed from the base of the PR and between 81e6716 and ae8385c.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • .github/dependabot.yml
  • .github/workflows/codeql.yml
  • .github/workflows/hypatia-scan.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (26)
  • GitHub Check: scan / gitleaks
  • GitHub Check: scan / rust-secrets
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Licence consistency
  • GitHub Check: scan / shell-secrets
  • GitHub Check: governance / Security policy checks
  • GitHub Check: 🔴 GATE: CI honesty self-test (fail fixtures)
  • GitHub Check: 🔴 GATE: Empty-linter (invisible characters)
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: Validate K9 contracts
  • GitHub Check: 🟡 CHECK: Groove manifest check
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: Hypatia Neurosymbolic Analysis
  • GitHub Check: analyze (javascript-typescript, none)
  • GitHub Check: wasm build
  • GitHub Check: analyze (rust, none)
  • GitHub Check: fmt + clippy + test
  • GitHub Check: rescript + wasm + bun test + bundle
⚠️ CI failures not shown inline (17)

GitHub Actions: ui-ci / 0_rescript + wasm + bun test + bundle.txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run bun run build:res
 �[36;1mbun run build:res�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 $ cd ui && bunx rescript
 >>>> Start compiling
 >>>> Finish compiling (exit: 2)
 Error: /home/runner/work/nexia-list/nexia-list/ui/rescript.json: No such file or directory
 ##[error]Process completed with exit code 2.

GitHub Actions: ui-ci / rescript + wasm + bun test + bundle: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run bun run build:res
 �[36;1mbun run build:res�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 $ cd ui && bunx rescript
 >>>> Start compiling
 >>>> Finish compiling (exit: 2)
 Error: /home/runner/work/nexia-list/nexia-list/ui/rescript.json: No such file or directory
 ##[error]Process completed with exit code 2.

GitHub Actions: Governance / 1_governance _ Well-Known (RFC 9116 + RSR).txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run MIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)
 �[36;1mMIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)�[0m
 �[36;1mif [ -n "$MIXED" ]; then�[0m
 �[36;1m  echo "::error::Mixed content (HTTP in HTML)"�[0m

GitHub Actions: Governance / 2_governance _ Workflow security linter.txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"
 �[36;1mSCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f tools/policy/check-workflows-parse.sh ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-workflows-parse.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::workflow parser gate not found in standards@main or locally"�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"
 �[36;1mSCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f tools/policy/check-workflows-parse.sh ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-workflows-parse.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::workflow parser gate not found in standards@main or locally"�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1mSCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m# Self-hosting fallback: when THIS repository is standards, its own�[0m
 �[36;1m# working tree already holds the script, and during a rename that copy�[0m
 �[36;1m# is the only correct one — the pinned main checkout still has the old�[0m
 �[36;1m# name. Preferring the fetched copy keeps every other caller on the�[0m
 �[36;1m# canonical version.�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f scripts/check-workflow-duplicate-keys.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / 6_governance _ Code quality + docs.txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / governance _ Code quality + docs: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / governance _ Code quality + docs: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run # Split gate (standards#505): README + LICENSE block immediately —
 �[36;1m# Split gate (standards#505): README + LICENSE block immediately —�[0m
 �[36;1m# measured 0/412 callers missing either, so arming them reds nobody.�[0m
 �[36;1m# CONTRIBUTING (54/412 missing) warns until the cutoff baked into the�[0m
 �[36;1m# script, then blocks. See scripts/check-docs-presence.sh.�[0m
 �[36;1mcp .standards-checkout/scripts/check-docs-presence.sh "$RUNNER_TEMP/"�[0m
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-docs-presence.sh" .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ##[error]Missing required documentation: CONTRIBUTING

GitHub Actions: Governance / 8_governance _ Guix packaging policy (Nix retired).txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run # Move the checker OUT of the scanned tree and delete the standards
 �[36;1m# Move the checker OUT of the scanned tree and delete the standards�[0m
 �[36;1m# checkout before scanning: the gate walks the whole caller tree, so�[0m
 �[36;1m# a packaging file shipped inside .standards-checkout/ would satisfy�[0m
 �[36;1m# the policy on the caller's behalf (same trap as the baseline job).�[0m
 �[36;1mcp .standards-checkout/scripts/check-package-policy.sh "$RUNNER_TEMP/"�[0m
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-package-policy.sh" .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ##[error]Package policy violation: no packaging found.

GitHub Actions: Governance / governance _ Guix packaging policy (Nix retired): fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run # Move the checker OUT of the scanned tree and delete the standards
 �[36;1m# Move the checker OUT of the scanned tree and delete the standards�[0m
 �[36;1m# checkout before scanning: the gate walks the whole caller tree, so�[0m
 �[36;1m# a packaging file shipped inside .standards-checkout/ would satisfy�[0m
 �[36;1m# the policy on the caller's behalf (same trap as the baseline job).�[0m
 �[36;1mcp .standards-checkout/scripts/check-package-policy.sh "$RUNNER_TEMP/"�[0m
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-package-policy.sh" .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ##[error]Package policy violation: no packaging found.

GitHub Actions: Governance / 10_governance _ Security policy checks.txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / governance _ Security policy checks: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / 13_governance _ Language _ package anti-pattern policy.txt: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"
 �[36;1mSCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f tools/policy/check-language-policy.sh ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-language-policy.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-check)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::language-policy gate not found in standards@main or locally"�[0m

GitHub Actions: Governance / governance _ Language _ package anti-pattern policy: fix(ci): roll back codeql-action to v4.38.0 SHA pin — resolves CodeQL/Hypatia startup_failure

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"
 �[36;1mSCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f tools/policy/check-language-policy.sh ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-language-policy.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-check)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::language-policy gate not found in standards@main or locally"�[0m
🔇 Additional comments (3)
.github/workflows/codeql.yml (1)

47-47: LGTM!

Also applies to: 53-53

.github/workflows/hypatia-scan.yml (1)

248-248: LGTM!

.github/dependabot.yml (1)

11-17: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Pinned security scanning workflow actions to a fixed, verified version for more consistent and predictable scans.
    • Prevented automated dependency updates from proposing the excluded CodeQL version while the pin remains in place.

Walkthrough

The workflows now pin CodeQL actions to an immutable v4.38.0 commit. Dependabot ignores version 4.38.1 and documents the workflow-startup validation failure associated with that version.

Changes

CodeQL action pinning

Layer / File(s) Summary
Pin CodeQL workflow actions
.github/workflows/codeql.yml, .github/workflows/hypatia-scan.yml
The CodeQL initialisation, analysis, and SARIF upload actions now use commit b96794f015dfd88f77b49b1c93e0fa7110f94c63, annotated as v4.38.0.
Ignore the rejected Dependabot version
.github/dependabot.yml
Dependabot ignores github/codeql-action version 4.38.1. A comment records the workflow-startup validation failure.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to ae838

CodeQL and Hypatia remain pinned to v4.38.0, avoiding the reported startup failure with no actionable merge-blocking risk remaining.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the rollback to the v4.38.0 SHA pin and the CodeQL/Hypatia startup failure it addresses.
Description check ✅ Passed The description directly explains the v4.38.1 rollback, the startup failure, the Dependabot ignore rule, and the related workflow changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit pins the actions tight
At v4.38.0, clear and bright
Dependabot skips the faulty trail
The workflows start without that veil
Three small changes keep the checks in sight

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 70 issues detected

Severity Count
🔴 Critical 6
🟠 High 28
🟡 Medium 36

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Required workflow `scorecard.yml` is absent from .github/workflows/. The estate baseline expects it; without it this repository is unscanned for whatever that workflow covers, and its absence is silent — no job fails, because no job runs.",
    "type": "missing_workflow",
    "file": "scorecard.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Workflow executes remote script directly (curl/wget piped to shell). Download, verify checksum/signature, then execute.",
    "type": "download_then_run",
    "file": "ui-ci.yml",
    "action": "verify_download_integrity",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "trigger-boj"
  },
  {
    "reason": "Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "build"
  },
  {
    "reason": "Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "analyze"
  },
  {
    "reason": "Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "a2ml-validate"
  },
  {
    "reason": "Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "dogfood-summary"
  },
  {
    "reason": "Job `k9-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "k9-validate"
  },
  {
    "reason": "Job `scan` in hypatia-scan.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "hypatia-scan.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "scan"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 4dc2793 into main Sep 22, 2026
31 of 34 checks passed
@hyperpolymath
hyperpolymath deleted the fix/codeql-4381-rollback branch September 22, 2026 10:52
hyperpolymath added a commit that referenced this pull request Sep 22, 2026
…ypassed in #101) (#104)

## Summary

PR #101 proved (within ~1h of #100 landing) that the `versions:
["4.38.1"]` ignore rule does **not** stop dependabot from re-raising the
blocked bump: it swapped `b96794f0` (v4.38.0 commit, green) for
`1c5b675` (the **v4.38.1 commit**, estate-blocked) in SHA form today,
while copying my inline "4.38.1 blocked" warning comment verbatim.
`1c5b675` fails workflow startup on hypatia and rsr-template proven —
merging #101 would have re-broken CodeQL + Hypatia tonight.

#101 is closed with a warning comment. This PR upgrades the defence to
an **unconditional hold** on `github/codeql-action` (no `versions` key =
all updates ignored) until upstream clears 4.38.1 or a newer release is
verified green. Comment documents why the versions-scoped rule failed so
nobody "tidies" it back.

## Follow-ups outside this PR

- Same hold needed in the **standards** canonical dependabot config so
other estate repos don't take the SHA-form re-bump either — part of the
estate rollback batch.
- **Estate alert**: any repo whose dependabot merged the actions group
since ~Sep-15 may already have the broken ref (vexometer + hypatia +
rsr-template confirmed red).

Co-authored-by: Arena Agent <agent@arena.ai>
arena-ai-coding-agent Bot pushed a commit to metadatastician/paint-type that referenced this pull request Sep 24, 2026
… to un-startup-kill CI

Root cause of the estate-wide startup_failure that killed every workflow on
the previous attempt: github/codeql-action v4.38.1 (1c5b675) is rejected by
GitHub's workflow-startup validation — any workflow naming it dies at
startup with zero jobs. Dependabot #105 bumped codeql.yml/oikosbot.yml to
v4.38.1 while leaving actions.lock at v4.38.0, so main inherited both the
startup-kill and a lock drift.

Changes
- codeql.yml (init/analyze) and oikosbot.yml (upload-sarif): pinned to the
  v4.38.0 SHA b96794f015dfd88f77b49b1c93e0fa7110f94c63, matching the estate
  rollback precedent (hyperpolymath/nexia-list#100,
  hyperpolymath/standards#973/#978). persist-credentials: false retained.
- .github/dependabot.yml: full hold on github/codeql-action until upstream
  clears 4.38.1 or a newer release verifies green (a versions-only rule was
  bypassed by dependabot re-bumping in SHA form elsewhere in the estate).
- actions.lock resynced to the workflow YAML (all four lock-sync clauses):
  * codeql/oikosbot entries -> v4.38.0 SHA form with a dependencies record
  * coverage.yml plain drift closed: codecov-action v7.1.0 -> v7.1.1
    (303a32d, nested github-script use re-verified upstream) and
    taiki-e/install-action v2.87.13 -> v2.87.17 (94c31af, no nested uses)
  * pruned the stale slsa-github-generator chain retired by the #91 release
    rewrite (slsa records + orphaned softprops/upload-artifact leaves)

Verified locally: faithful port of scripts/check-lock-sync.sh passes all
clauses; every workflow + lockfile + dependabot.yml parses; workflow-linter
SPDX/permissions checks pass; zero references to v4.38.1/1c5b675 outside
hold comments.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath added a commit to metadatastician/paint-type that referenced this pull request Sep 24, 2026
… — un-startup-kill CI (#107)

## Summary

Follow-up to #106. That PR landed the #102 conflict resolution but
inherited Dependabot #105's broken state: `github/codeql-action` bumped
to **v4.38.1**, a version under an **estate-wide hold** because GitHub's
workflow-startup validation rejects it — any workflow naming it dies at
startup with zero jobs (hyperpolymath/nexia-list#100,
hyperpolymath/standards#973/#978). This is what caused the
`startup_failure`s observed while #106 was being verified, and it is
still killing **Coverage**, **OikosBot**, and reddening **Governance /
Actions lockfile verify** + **Lock Sync Gate** on main.

## Changes

- `codeql.yml` (init/analyze) and `oikosbot.yml` (upload-sarif): pinned
to the **v4.38.0 SHA** `b96794f` per the estate rollback precedent;
`persist-credentials: false` retained.
- `.github/dependabot.yml`: full hold on `github/codeql-action` until
upstream clears 4.38.1 or a newer release verifies green (the estate
measured that a `versions: ["4.38.1"]` rule gets bypassed when
dependabot re-raises in SHA form).
- `actions.lock` resynced to the workflow YAML (all four
`check-lock-sync.sh` clauses):
- codeql/oikosbot entries → v4.38.0 SHA form with a matching
`dependencies:` record
- plain drift closed: `codecov-action` v7.1.0 → v7.1.1 (`303a32d`,
nested `github-script` use re-verified upstream) and
`taiki-e/install-action` v2.87.13 → v2.87.17 (`94c31af`, no nested uses)
- pruned the stale `slsa-github-generator` chain retired by the #91
release rewrite

## Testing

- Faithful local port of `scripts/check-lock-sync.sh`: all clauses pass
(locked incl. job-level reusable refs, no orphans, transitively closed
with 0 dangling edges, full coverage).
- Every workflow + lockfile + dependabot.yml parses as YAML.
- Workflow Security Linter steps (SPDX headers, permissions) pass
locally.
- Zero references to v4.38.1/`1c5b675` outside hold comments.

<!-- SPDX-License-Identifier: AGPL-3.0-or-later -->

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath pushed a commit to hyperpolymath/hypatia that referenced this pull request Sep 26, 2026
…estate sweeps (#862)

## ⚠️ Before you look at the checks: they will all be red, and it is not
this code

Every `pull_request` workflow on this branch reports `startup_failure`
with zero jobs — **18 of 18**, including workflows this PR never
touches. That is not the pin fix failing. It is the same wall the
estate's agent-pushed PRs always get (`MetaManifold-WebUI#72`,
`oikosbot#107`, both merged on owner review). Established by elimination
here: it stayed 18 of 18 with an empty commit and again with the
workflow edits removed from the branch entirely.

**Rule of thumb, now written into the docs:** if a workflow the PR does
not touch fails at startup, the cause is not the PR's contents.

Consequence: this PR will sit `BLOCKED` on required checks that can
never satisfy. To validate it, push the branch from your own account
(`git fetch origin arena/01a0dd51-hypatia && git push my-fork
arena/01a0dd51-hypatia:...`), or merge on review. The new `estate-rules`
CI job runs the rule tests on any human- or dependabot-authored PR.

---

## What this fixes

`github/codeql-action@1c5b6756…` is the commit GitHub rejects at
workflow start-up — `startup_failure`, zero jobs, no logs. This
repository carries it in `codeql.yml` and `security-policy.yml` under
the comment `# v4.38.0`, because the 2026-09-22 rollback was applied as
a **relabel**: the pin was renamed, not replaced. `actions.lock` holds
the correct `b96794f0…` pin, so the lockfile and the workflows disagree
— this PR makes them agree.

Same signature as `hyperpolymath/nexia-list#100`, where it was diagnosed
and rolled back.

Locally re-verified: the two `codeql.yml` sites and the six
`security-policy.yml` sites now carry `b96794f0…`, the `uses:` count is
unchanged, and no denylisted token remains in either file.

## What it adds

The machinery the incident showed was missing, all driven by one policy
file (`.machine_readable/merge-orchestration/pr-automerge-policy.json`):

| Piece | Purpose |
|---|---|
| `lib/rules/pin_integrity.ex` | PI001–PI005: denylisted pin,
mislabelled pin, locked moving ref, lock/workflow divergence, stale pin
— plus the mechanical substitution that refuses to guess |
| `lib/rules/pr_automerge.ex` | PA001–PA006: which open PRs are
unambiguous bumps/chores, which are poisoned, which need a human |
| `test/rules/*.exs` | the incident's own cases as tests, including the
poisoned SHA wearing a correct `# v4.38.0` label |
| `scripts/sweeps/estate-*.sh` | pin repair, PR disposition, absence
intake, estate statistics (`--rewrite`/`--execute` opt-in; dry run by
default) |
| `docs/operations/estate-automerge.adoc` | the handoff document,
including how to tell the two `startup_failure` causes apart |

## Why not a title matcher

The estate has 33 open dependency PRs, all titled `chore(deps): bump …`.
Twenty-five of them re-introduce the poisoned pin, and at least two hide
a major bump (`actions/checkout` v4.1.7 → v7.0.1) behind a
grouped-update title. Decisions are made from the diff's `uses:` refs,
never from the title or the inline comment.

## Safety properties verified against live data

- `--execute` refuses any decision whose PR head moved: tested against
all 33 live decisions — **33 refused, 0 applied**.
- The live-diff re-proof was run against real PRs: the 5 auto-merge
candidates read clean, 3 poisoned ones read poisoned — no false
negatives, no false positives.
- A repair that cannot be proved is a finding, not an action:
substitution refuses without a `known_good_sha`, and refuses if the
rewrite would drop a `uses:` site.

## Stats artifact: measured, not assumed

`estate-stats.sh --checks` now measures what the dashboard was asked to
track and could not: **408 repositories, 350 with a test surface, 58
with none, 120 whose most recent suite failed**. Paging reports 3
critical, 2 warn, 2 unavailable (the bench metrics, for which no
producer exists — reported unavailable rather than 0).

## Reflexivity

This touches hypatia's own rules and bot directives, which is `NA-005` —
proposed, never self-approved. Please review rather than letting a robot
merge it.

---------

Co-authored-by: hypatia <hypatia@hyperpolymath.invalid>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath pushed a commit to metadatastician/sim-public-relations that referenced this pull request Sep 29, 2026
…e gates behind them (#29)

Closes #23.

## What was actually wrong

Run logs are unreadable from my environment, so everything below was
measured from the Actions/checks API, the upstream repositories, and by
running the gate scripts locally against this tree.

| Symptom on `main` | Cause |
|---|---|
| Governance / Hypatia / Scorecard fail in **0 s**, no jobs | #26 pinned
them to three `hyperpolymath/standards` SHAs that **do not exist**
upstream (`8f31a5a4`, `cc58c0cb`, `8750b94a` → `No commit found for
SHA`) |
| CodeQL / SonarQube `startup_failure` | `actions.lock` never updated
for #26 (codeql SHA, sonar v8.2.2) or #28 |
| CodeQL would still die even with the lock fixed | #28 bumped to
codeql-action **4.38.1**, which GitHub refuses at startup estate-wide
(hyperpolymath/nexia-list#100) |
| Workflow Security Linter red | #26 prepended a **second** `gh
actions-lock` banner to all 25 workflows, pushing every SPDX header off
line 1 |
| Lock Sync Gate red | consequence of the above |
| Governance (last real run) — Allowlist Preflight, SHA-pin check |
stale Aug‑04 standards pin; passes against current standards |
| Static Analysis Gate — 3 Hypatia criticals | two banned‑language `.py`
mint helpers; `github.actor == 'dependabot[bot]'` gate (RE008) |

## What this PR does

**Workflows / lockfile**
- All five `standards` reusable-workflow callers pin **one** published
commit, `bd9313a6` (main HEAD today). Verified with standards' own
`check-workflow-staleness.sh` and `check-action-pins-resolve.sh`.
- `codeql.yml` → **v4.38.0** (`b96794f0`, the same SHA standards pins),
in this repo's tag+lock convention; `dependabot.yml` ignores exactly
`4.38.1` so the grouped bump cannot re-break it.
- `actions.lock` resynced and **transitively closed** — new leaf records
for the standards record's nested `uses:`, sonar v8.2.2, zero
unreferenced records; every `commit:` verified against the upstream
peeled tag.
- SPDX back on line 1 everywhere; duplicate banners removed.
- `scorecard.yml` grants `actions: read` on the calling job (the
reusable requires it; job-level permissions replace rather than merge).

**Governance @ `bd9313a6`** — every scriptable job run locally:
allowlist, pin-existence, staleness, UUID v7, duplicate keys,
trusted-base, licence, exemption/debt ratchets, package policy, docs,
language policy — all green.
- The **new UUID v7 gate** (standard dated 2026‑09‑29) rejected the
clade UUIDv5. The identity is now a v7 minted with the `uuid` library:
`01a0ed2d-28fe-70cb-8aa6-462024f85795`. The old value was derived, never
registered (`registered-in-gv-clade-index = false`), so no alias is
carried. `CLAUDE.md` regenerated (uuid + `CLADE@` hash); `just
repo-init` now mints v7 rather than deriving v5; the stale
`build/templates/` mint leftover is removed. ⚠️ This is the one
judgement call in the PR — see below.

**Static Analysis Gate**
- `dependabot-automerge.yml` gates on the PR **author** + same‑repo
head, not `github.actor`.
- The two Python helpers are replaced by rsr-template-repo's Rust ports
(`scripts/*.rs` + `scripts/rust-tool.sh`). Zero Python in the tree.
- `timeout-minutes` added on `labels.yml` / `label-triage.yml`
(warnings).

**Tests** — `tests/workflows/foundation_ci_security_test.sh` now asserts
*properties* with negative fixtures (SPDX‑first, lock coverage +
closure, single standards revision, CodeQL posture, no actor gates, no
Python). It fails on today's `main` and passes here. The previous
version and `foundation_ci_fixes_test.sh` snapshotted #26's exact SHAs —
including the three forged ones — so they could only agree with the
defect; folded into one file.

No `continue-on-error` added; no error downgraded to a warning.

## Acceptance criteria from #23
1. **Estate Rules** — already green on `main` since #26 (the issue
predates that); unchanged here.
2. **Governance** — forged pins replaced; every job's script passes
locally against `standards@bd9313a6`. The UUID v7 gate is a
cross-cutting class (rsr-template-repo itself still carries a v5) and
belongs in hyperpolymath/standards#994's family; this repo is fixed
rather than exempted.
3. **Dogfood Gate** — already green on `main`; unchanged.
4. **Static Analysis Gate** — each critical repaired, none muted.

## Reviewer note
The clade UUID change is deliberate and reversible, but it *is* an
identity change. If you'd rather keep the v5 and take the gate red until
the estate decides how CLADE identities migrate, revert the `CLADE.a2ml`
/ `CLAUDE.md` / `repo-init.just` hunks and the rest of this PR stands on
its own.

---------

Co-authored-by: arena-ai-coding-agent[bot] <298482267+arena-ai-coding-agent[bot]@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath added a commit to metadatastician/paint-type that referenced this pull request Sep 30, 2026
## Why

`main` (`1927641`) is out of sync with its own `actions.lock`. The
result is that `Governance Check / Actions lockfile verify` and
`actions.lock is in sync` are red on `main`, and `coverage.yml` is
startup-dead (run 36163988135, `startup_failure`). Two dependabot merges
edited `uses:` lines without the lock:

| PR | change | disposition here |
|---|---|---|
| #108 (grouped) | `github/codeql-action` v4.38.0 → **v4.38.1**
(`1c5b675`) in `codeql.yml` ×2 and `oikosbot.yml` ×1 | **reverted** to
v4.38.0 `b96794f` |
| #122 | `taiki-e/install-action` v2.87.17 → v2.87.18 in `coverage.yml`
| **kept**; the lock now follows it |

#108 reverts #107's pin. It swapped the SHA underneath HOLD comments
that say codeql-action must stay on v4.38.0: v4.38.1 is rejected at
workflow startup estate-wide (hyperpolymath/nexia-list#100). The full
hold in `.github/dependabot.yml` did not stop it, because an `ignore`
rule is bypassed inside a `groups:` update. That is the measured
behaviour tracked in hyperpolymath/standards#1037.

## What changed

- `codeql.yml:52,57` and `oikosbot.yml:43`: `1c5b675… # v4.38.1` →
`b96794f… # v4.38.0`. The HOLD comments already describe this state, so
they are unchanged.
- `actions.lock`: the `coverage.yml` key and the `dependencies:` record
now name `taiki-e/install-action@v2.87.18`. The tag resolves to commit
`dfae9bf3d6f6c6f20ef4ebb3486c01a51341ff12`; `owner_id`/`repo_id` are
unchanged.

## Evidence: before/after on identical binaries

| check | before (`origin/main`) | after (this branch) |
|---|---|---|
| `scripts/check-lock-sync.sh` | rc=1, **6 FAIL** (codeql, coverage,
oikosbot: missing + stale each) | rc=0, **0 FAIL** |
| `gh actions-lock --no-fix` | `valid=false`, rc=1: 1 `ref-changed`
error + 3 `stale` + 3 `sha-as-ref` + 1 `ref-moved` | `valid=true`, rc=0:
3 `sha-as-ref` (the deliberate HOLD pins) + 1 `ref-moved`
(`dogfood-gate.yml` `@main`, out of scope) |
| `actionlint` on the 3 edited workflows | — | rc=0 |

## Deliberately not in this PR

- **`.github/dependabot.yml`** is untouched. The structural cure for the
grouped-update bypass (`exclude-patterns` on the group) is staged,
estate-wide policy in hyperpolymath/standards#1037 (AC1 → AC5), and this
PR does not pre-empt it.
- **codeql-action v4.38.2** exists upstream, but nothing in the estate
has verified it yet, so it isn't adopted here.
- The in-repo recurrence guard is to make the lock gates **required** on
`main`. That is the next step (Tier A close-out), and it needs this PR's
runs green first.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01YSq3UodR3CjsuAK5yoTzHF

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/marid that referenced this pull request Sep 30, 2026
… D118 (supersedes #56) (#58)

## Supersedes #56

This is #56's exact content: the same signed commit `d3afb4e`, directly
on `main` `afda1f7`. The only difference is that it leaves out the
commit #56 picked up afterwards.

- At 10:26:40Z `coderabbitai[bot]` pushed **unsigned** commit `3c4c13d`
onto #56 ("docs(wiki): convert README to Markdown and update repository
map").
- It was triggered by a "Commit to this branch" checkbox tick on the
walkthrough comment, at 10:21:47Z and again at 10:32:47Z.
- The tick came from an agent session on the shared account, not from
the maintainer.
- The commit is off-scope: `.adoc`→`.md` against the estate AsciiDoc
convention, unrelated to CI.
- `main` carries `required_signatures`, so that unsigned head made
**every workflow `startup_failure` (jobs=0)**.
- Removing it from #56 in place would need a force-push. Instead, #56 is
closed and this PR carries the signed commit alone. Nothing is lost:
  - `3c4c13d` stays reachable at `refs/pull/56/head`;
  - it is also preserved in a local git bundle.
- If the wiki conversion is wanted, it deserves its own PR and its own
decision.

### Why this one is on the critical path for every marid PR

`main`'s `code_scanning` rule waits for CodeQL results. The CodeQL
workflow on `main` startup-fails, so no PR can currently satisfy the
rule; #57 was refused on exactly that. #55's own merge was recorded as a
bypass over the same two rules (rule-suite 4234619834: `pull_request` +
`code_scanning` "waiting for results from CodeQL"). This PR restores the
workflow, so it has to land first.

## What broke main

Dependabot **#55** merged one grouped update that did two independent
things, each of which kills workflows at startup (zero jobs, no logs):

| file | #55 changed | effect |
|---|---|---|
| `codeql.yml` | `init`/`analyze` → `1c5b675` — the **v4.38.1** commit,
estate startup-killer
([nexia-list#100](hyperpolymath/nexia-list#100)).
The inline comment still said `# v4.38.0`. | `CodeQL Security Analysis`
= `startup_failure` |
| `pages.yml` | `haskell-actions/setup` v2.12.0 → **v2.12.1**, with no
lock update | `GitHub Pages` = `startup_failure` |

The desync also reddens every gate that verifies the lock (Lock Sync,
Governance, Workflow Security Linter).

## The fix

1. **Revert both codeql pins to `b96794f`.** That is v4.38.0: annotated
tag `4bd7200` → commit `b96794f`, which the lock already binds (v4.38.1
is annotated tag `c23de5a` → commit `1c5b675`). The existing comment is
accurate again.
2. **Keep haskell v2.12.1 and lock it:** annotated tag `0f7370c` →
commit `0f8e8c9`. The lock delta comes from a sandboxed `gh actions-lock
--no-narrow --no-migrate-local-actions` run and is restricted to the
four haskell lines, so it matches the tool's own haskell delta line for
line.
- ⚠ The tool *also* lowercased an unrelated transitive record,
`Swatinem/rust-cache` → `swatinem/rust-cache`. That change is **not**
taken: it is outside this fix, and ref case is not something to change
silently.
- The tool also wanted to prepend its banner to `lock-sync-gate.yml`.
That is cosmetic, so it is not taken either.
3. **D118: take `github/codeql-action` out of automatic bumps.** It is
excluded from the `actions` group and ignored.
- Both halves are needed. An `ignore` is bypassed inside a `groups:`
update (measured on 15 repos, 2026-09-23).
- The dependabot schema itself says an excluded dependency *"will
continue to raise single pull requests"*.
- From here on, codeql-action is bumped by hand, in the same PR as the
lock regeneration. The estate-wide cure stays
[standards#1037](hyperpolymath/standards#1037).

## Evidence: matched pairs, same scripts, only the tree differs

| check | `main` (`afda1f7`) | this branch |
|---|---|---|
| `bash scripts/check-lock-sync.sh` | **rc=1**, 4 FAIL (2 missing refs,
2 orphaned entries) | **rc=0**, in sync and transitively closed |
| `gh actions-lock --no-fix --json` | `valid=false` | `valid=true`, 0
errors |
| verifier warning categories | `ref-moved=4 sha-as-ref=4 stale=4` |
`ref-moved=4 sha-as-ref=4` (the orphans are gone, nothing new) |

`--no-fix` was confirmed to write nothing: `diff -r` of `.github/`
before and after the run was empty.

## Not in this PR (on purpose)

- **D63-A**, adding `javascript-typescript` and `rust` to the CodeQL
matrix, follows separately. Its acceptance criteria (a planted finding
must surface, the coverage fraction recorded) are a quality change, and
bundling them would hold the unbreak hostage to new `code_scanning`
alerts.
- The other red checks on main have separate causes:
`docs/wikis/README.adoc` for the Central Estate audit, SonarQube 403 for
#49, and the A2ML canon-lockstep gate for #31.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01YSq3UodR3CjsuAK5yoTzHF

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to hyperpolymath/CoprocessorRuntime.jl that referenced this pull request Oct 3, 2026
#2)

## Why this PR exists

The compare
[main...coderabbit/fix-hypatia-scan-failures/f36ac704](https://github.com/hyperpolymath/CoprocessorRuntime.jl/compare/coderabbit/fix-hypatia-scan-failures/f36ac704?expand=1)
**cannot become a PR**. GitHub reports *no common ancestor*:

- `main` is `5ce66c6`
- `coderabbit/fix-hypatia-scan-failures/f36ac704` is parentless commit
`d008687` (“Initialize …”)

That orphan tree is an older RSR-template snapshot. The actual Hypatia
ignore entries from
[rsr-template-repo#89](hyperpolymath/rsr-template-repo#89)
(`RE001`/`RE005`/`RE008`) are already on `main`. Merging the orphan
would not apply a delta.

**Owner action:** delete
`coderabbit/fix-hypatia-scan-failures/f36ac704`. This branch shares
history with `main`.

## CI that this tree can fix

| Check | Cause | Fix here |
|---|---|---|
| CodeQL / Governance / Rust CI / Code Quality `startup_failure` on #1 |
Dependabot bumped `codeql-action` to **4.38.1** (`1c5b675`) and
`haskell-actions/setup` to v2.12.1 without regenerating `actions.lock`.
4.38.1 is blocked estate-wide
([nexia-list#100](hyperpolymath/nexia-list#100)).
| Revert CodeQL to `b96794f` (v4.38.0, already locked). Revert
haskell-actions/setup to v2.12.0. |
| Hypatia Security Scan | Reusable at `da2c748` clones **hypatia@HEAD**
and `mix escript.build`. Build failed here *and* on
hyperpolymath/hypatia after
[#863](hyperpolymath/hypatia#863) (same 33s
failure). Scanner never ran. | `secrets: inherit` so `HYPATIA_SCAN_PAT`
reaches the reusable. **Cannot** cure a broken hypatia HEAD — see
[standards#1014](hyperpolymath/standards#1014).
|
| Lock Sync Gate | Same pin/lock desync, plus missing julia-ci lock
records. | Pins match the lock; julia-ci entries added with closed
`dependencies:` records. |

Full write-up: `docs/status/HYPATIA-GATE.adoc`.

## The library (it was still an unminted spine)

`Project.toml` uuid `54e4c7d3-acab-5c3f-ab09-6ee0d181492b` (UUIDv5 of
the repo uuid). Zero runtime deps. Tests: Test + Aqua.

Honest scope: **contracts, not kernels**. No CUDA/ROCm/Metal. Selection
stays in AcceleratorGate.jl.

| Piece | Runtime form | Not claimed |
|---|---|---|
| Choreographic projection | `LaunchPlan` / `project` /
`HostRole`/`DeviceRole` | K-CUT (`kcut = :open` unless the transfer is
injective) |
| Tropical grades | `ResourceGrade`, `tropical_seq` (`+`),
`tropical_alt` (`max`) | Lean `ResourceSemiring` |
| `hub_ceiling` | `universal_hub_allowed()` throws `HubCeilingRefusal` |
A universal vendor adapter |
| Echo loss | `TransferMap` + `EchoResidue` | Agda fibres / EchoTypes.jl
replay |
| Epistemic no-smuggling | device `Knowledge` without `sound=true` is
refused | Full warrant calculus |
| CNO / OND | `CNOClaim` / `ONDClaim`, default `:unproved` | Coq/Lean
proofs; OND-6 |
| Janus inversion | `InverseMeta` | januskey's file log |

Taken / not-taken from the `-type` repos:
`docs/theory/TYPE-INFORMED-BACKENDS.adoc`.

## Wiring across the estate (this session can only push this repo)

Exact patches for Hyperpolymath.jl (metal-layer `using` + `Project.toml`
uuid) and notes for AcceleratorGate, LowLevel, EchoTypes,
EpistemicTypes, QuantumCircuit, FirmwareAudit:

`docs/ecosystem/HYPERPOLYMATH-WIRING.adoc`

Hyperpolymath.jl is the linking directory; it does not yet name this
package. That is a follow-up PR on Hyperpolymath.jl.

## Checklist

- [x] Placeholders filled (`scripts/check-no-placeholders.sh` PASS)
- [x] SPDX on new Julia sources
- [x] No vendor kernels, no `hub` adapter
- [x] Julia CI workflow added (1.9 + 1)
- [ ] Hypatia scan green *when hypatia HEAD builds* (not this repo)

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant