Repository navigation
Cross-cutting governance reds surfaced by the actions.lock cure — 9 classes across 17 PRs (incl. a live gate for the retired A2ML) #994
Description
Activity
- addedcicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementPolicy, rulesets, standards, compliance, and their enforcementrefactorRestructuring that preserves observable behaviourRestructuring that preserves observable behaviour
on Sep 22, 2026 Evidence from the A2ML-gate retirement sweep (13 PRs) — plus a root cause for this issue's #1 class
The 13 PRs retiring the dead A2ML gate (see #1010, scope corrected there from 142/112 to 13) have been measured against their own base branches. They add nothing to the red surface, and they let me diagnose
lint-workflows.1. The sweep introduces no reds
Failing check-runs compared head vs base at the same (job) granularity, so a
continue-on-errorjob cannot manufacture a phantom:- 11 of 13: head red set is a strict subset of base. Nothing new.
- 2 of 13 (
consent-aware-web#10,_pathroot#29) showlint-workflowsas "new" — but that job does not exist onmainat all.workflow-linter.ymltriggers onpush:withpaths: ['.github/workflows/**'], and no recent main push touched a workflow. These PRs are simply the first commits in a long time to touch.github/workflows/, so a latent job ran for the first time. Surfaced, not introduced.
startup_failurelikewise only ever falls:common-signal17→4,consent-aware-web5→2,sr71-blackglider5→2,project-ovine2→2. Every head set is a strict subset of its base set, and the residue isgovernance.yml/hypatia-scan.yml— this issue's territory, not the gate's.2. ⭐
lint-workflowsis two different failures wearing one nameThis issue lists
lint-workflowsas its largest class (10). It is not one defect. Resolving the failing step splits it cleanly:step repos root cause Check SPDX Headerscadastra,consent-aware-web,harvard-dehallucinatora false positive — an ordering bug, not a missing licence Check SHA-Pinned Actionscommon-signal,_pathrootgenuinely unpinned refs The SPDX one is worth reading closely.
gh actions-lockprepends its stamp above line 1, displacing the SPDX header:# This workflow is managed by gh actions-lock. <- line 1, inserted by the tool # SPDX-License-Identifier: MPL-2.0 <- line 2, was line 1The checker's own message is "Add '# SPDX-License-Identifier: MPL-2.0' as first line" — it tests line 1 only. So in
consent-aware-web19 of 19 workflow files are reported as missing an SPDX header while every one of them has it. The licence is present throughout; only the ordering is wrong. This is the same upstreamgh actions-lockdefect already recorded as stamp-placement, now shown to have a live estate-wide consequence.Two candidate cures, both one line:
- (a) make the checker accept an SPDX header anywhere in the leading comment block — the tolerant fix, immune to any future tool that prepends a stamp; or
- (b) make
gh actions-lockwrite its stamp below the SPDX header, and re-stamp the estate.
(a) is the more durable arm — it fixes the class rather than the instance, and does not require re-running a tool over every repo. I can implement it on request; it is a new finding, so under the standing stopping rule it is an issue with acceptance criteria rather than a blocker on the 13 PRs.
The
Check SHA-Pinned Actionshalf is unrelated and real — e.g.common-signalhascodeql-action/init@v4.37.9,codeql-action/analyze@v4.37.9,action-editorconfig-checker@v3.0.0,action-gh-release@v3.0.3, all in files the sweep never touched. Note the codeql pair also feeds #1005.3. Correction to this issue's A2ML line
This issue records 3 ×
Validate A2ML manifestsas a live gate for something retired. Measured across all 84 live-workflow repos, that check name covers three unrelated populations — 13 repos run a dead action (renamed repo, could only ever fail), 54 run a live DEED validator under a residual A2ML step name, and 15 already call the successor. Only the 13 are being retired. Full table and method in #1010.4. Red surface of the 13 PRs
repo PR failing check-runs (all pre-existing) hyperpolymath/proven-servershyperpolymath/proven-servers#90 estate-audit,governance / Allowlist Preflight,governance / Language / package anti-pattern policy,governance / Trusted-base reduction policy,governance / Workflow security lintermetadatastician/_pathrootmetadatastician/_pathroot#29 analyze (actions, none),check,estate-rules,governance / Check Workflow Staleness,governance / Workflow security linter,Hypatia neurosymbolic scan,lint-workflows,openssf-compliancemetadatastician/boj-server-mk2metadatastician/boj-server-mk2#47 Empty-linter (invisible characters),estate-rules,governance / Workflow security linter,Hypatia neurosymbolic scan,SonarQubemetadatastician/cadastrametadatastician/cadastra#53 analyze (actions, none),check,estate-rules,governance / Allowlist Preflight,governance / Workflow security linter,Hypatia neurosymbolic scan,lint-workflows,SonarQubemetadatastician/common-signalmetadatastician/common-signal#7 estate-rules,Hypatia neurosymbolic scan,lint-workflowsmetadatastician/consent-aware-webmetadatastician/consent-aware-web#10 estate-rules,Hypatia neurosymbolic scan,lint-workflowsmetadatastician/harvard-dehallucinatormetadatastician/harvard-dehallucinator#18 analyze (actions, none),estate-rules,governance / Allowlist Preflight,governance / Workflow security linter,Hypatia neurosymbolic scan,lint-workflowsmetadatastician/paint-typemetadatastician/paint-type#89 Sustainability Analysismetadatastician/pong-pingmetadatastician/pong-ping#7 estate-rules,Hypatia neurosymbolic scanmetadatastician/project-ovinemetadatastician/project-ovine#26 estate-rules,Hypatia neurosymbolic scan,SonarQubemetadatastician/sim-public-relationsmetadatastician/sim-public-relations#24 estate-rules,governance / Allowlist Preflight,Hypatia neurosymbolic scanmetadatastician/sr71-blackglidermetadatastician/sr71-blackglider#20 estate-rules,Hypatia neurosymbolic scanmetadatastician/stapelnmetadatastician/stapeln#75 Aspect tests,governance / Language / package anti-pattern policy,governance / Validate Hypatia Baseline,scan / Hypatia Neurosymbolic Analysispaint-type#89is the closest to landing: a single pre-existing red (Sustainability Analysis).Acceptance criteria
Check SPDX Headerspasses on a workflow whose SPDX line sits below a tool-inserted stamp — asserted by a test fixture with the stamp on line 1, so the fix cannot regress silently.Check SHA-Pinned Actionsreports zero refs oncommon-signaland_pathrootafter theircodeql.yml/quality.yml/release.ymlrefs are pinned or lock-covered.- The Hypatia family reports under one check name, not four.
- Each of the 13 PRs above reaches a state where every check is terminal-success at full suite size, or its remaining red is booked here with an owner.
- No PR in the set merges over a red (standing ruling).
Nothing here blocks #1010's sweep; it is booked so the reds have an owner.
🤖 Generated with Claude Code
- added a commit that references this issue
on Sep 29, 2026 - addedpriority:p1High - schedule nextHigh - schedule nextscope:estateAffects many or all repos across the estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked upFully specified and ready to be picked up
on Sep 30, 2026 - added 7 commits that reference this issue
on Oct 1, 2026 19 remaining items
- added 15 commits that reference this issue
on Oct 1, 2026
Summary
The
actions.lockdesync campaign (#968) has landed its cure: 6 PRs merged, 5 more are greenwith auto-merge armed. What remains red on the other 17 PRs is, with very few exceptions, not
lockfile damage and not caused by those PRs. It is a set of estate-wide governance checks that
were already failing and only became visible once the lock cure revived the workflows that run
them.
This is the expected shape. Per the standing stopping rule a pre-existing red is an issue with
acceptance criteria, never a merge blocker — this is that issue for the cross-cutting classes.
Each affected repo also gets its own triage issue listing its own reds, linked back here.
Measured distribution (17 red PRs, 2026-09-22)
lint-workflowsgovernance / Workflow security lintermainbranchesHypatia neurosymbolic scan(5),scan / …(2),hypatia / …(2)governance / Allowlist PreflightValidate A2ML manifestsgovernance / Guix packaging policy (Nix retired)SonarQubegovernance / Validate Hypatia Baselineanalyze (actions, none)Long tail, one repo each:
Validate K9 contracts,Validate DEED manifests,scan / gitleaks,openssf-compliance,estate-audit,estate-rules,check,core-fill-tests,extension-build,GSBot build…,governance / Check Workflow Staleness,governance / Language / package anti-pattern policy,Analyze (actions).⚠ Three things worth a decision rather than a fix
1.
Validate A2ML manifestsis a live gate for a system that does not exist.It is failing on
gossamer#174,cadastra#51andfirst-post#14. Standing estate doctrine isthat A2ML is dead — killed by the ML-community name clash. A gate that validates manifests for
a retired format is not something to repair; the likely correct action is to remove it. I have
not removed anything: that is a call for the owner, not a triage fix.
2. The Hypatia scanner reports under four different check names.
Hypatia neurosymbolic scan,scan / Hypatia Neurosymbolic Analysis,hypatia / Hypatia Neurosymbolic Analysis,governance / Validate Hypatia Baseline. A rulesetrequires a check by exact context name, so four spellings means four separate required-check
entries to keep in step, and renaming any of them orphans every open PR that predates the rename.
Worth converging on one name — deliberately, with the PRs rebased, not casually.
3.
governance / Workflow security linteris red onmaintoo in at leastawesome-nickelandjulia-professional-registry. A check that is red onmaincannot be used tojudge a branch; it measures the estate, not the change.
Acceptance criteria
gate, or accept with a documented exemption. A class may not stay undetermined.
Validate A2ML manifestshas an explicit owner ruling (retire vs keep). If retired, itis removed from the 3 repos and from the estate template in the same change.
affected open PR rebased onto it, or an explicit decision to keep the four names, with the
reason written down.
mainis listed, with the date it went red. Nothing isrequired of a branch that its base does not satisfy.
continue-on-error, by demoting a failure to a warning, orby dropping the check from the required set without AC1's determination. Repair or retire;
never mute.
Scope note
This issue does not block any campaign PR. The lock cure is independently verified: the gate
kills a mutant that deletes a locked
uses:entry, and the previously-dead workflows now execute.A red here is a workflow getting its first real measurement in months, which is the cure
working, not a regression.
Related: #968 (campaign roll-up), #993 (lock policy + the pin bump), #987 (phantom blob pins).
🤖 Generated with Claude Code
https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm