Context
Since 5e75753 (2026-09-28), these workflows have been red on main and on every PR head. #209 fixes only CodeQL: it re-keys codeql.yml's actions.lock entry, and CodeQL is the only required check. The rest are pre-existing. #209 introduces none of them.
The table below was measured on 2026-10-01. It compares main 5e75753, the #209 head 39081ec, and the unrelated PR branch docs/signing-policy-d218.
| Workflow |
Conclusion |
Likely cause |
| chapel-ci, Dogfood Gate, Dependency Review, bridge-gate |
startup_failure |
Probably the same class as CodeQL: an actions.lock entry that is stale against the workflow's refs. gh actions-lock --no-fix --json reports 58 repo errors after #209. |
.github/workflows/{cargo-audit,coverage,release}.yml |
failure, and the run has no workflow name |
The file does not parse, or the run is refused before it is named. |
| Governance (Workflow security linter, Actions lockfile verify) |
failure |
Lock drift and linter findings. |
| Secret Scanner (gitleaks) |
failure |
Needs triage. |
| Rust CI (clippy, fmt) |
failure on main |
Needs triage. |
Acceptance criteria
🤖 Generated with Claude Code
Context
Since
5e75753(2026-09-28), these workflows have been red onmainand on every PR head. #209 fixes only CodeQL: it re-keys codeql.yml'sactions.lockentry, and CodeQL is the only required check. The rest are pre-existing. #209 introduces none of them.The table below was measured on 2026-10-01. It compares main
5e75753, the #209 head39081ec, and the unrelated PR branchdocs/signing-policy-d218.startup_failureactions.lockentry that is stale against the workflow's refs.gh actions-lock --no-fix --jsonreports 58 repo errors after #209..github/workflows/{cargo-audit,coverage,release}.ymlfailure, and the run has no workflow namefailurefailurefailureon mainAcceptance criteria
gh actions-lock --no-fix --jsonreports 0 errors. Edit the lock by hand:gh actions-lockwrite mode de-pins SHAs and corrupts local action refs.mainends instartup_failure.name:.🤖 Generated with Claude Code