Skip to content

Cross-cutting governance reds surfaced by the actions.lock cure — 9 classes across 17 PRs (incl. a live gate for the retired A2ML) #994

Description

@hyperpolymath

Summary

The actions.lock desync campaign (#968) has landed its cure: 6 PRs merged, 5 more are green
with auto-merge armed. What remains red on the other 17 PRs is, with very few exceptions, not
lockfile damage and not caused by those PRs
. It is a set of estate-wide governance checks that
were already failing
and only became visible once the lock cure revived the workflows that run
them.

This is the expected shape. Per the standing stopping rule a pre-existing red is an issue with
acceptance criteria, never a merge blocker — this is that issue for the cross-cutting classes.
Each affected repo also gets its own triage issue listing its own reds, linked back here.

Measured distribution (17 red PRs, 2026-09-22)

n failing check reading
10 lint-workflows often twice per repo — a matrix leg, so ~6 repos
9 governance / Workflow security linter also red on several main branches
9 Hypatia family — Hypatia neurosymbolic scan (5), scan / … (2), hypatia / … (2) four different check names for one scanner
5 governance / Allowlist Preflight the actions allow-list
3 Validate A2ML manifests ⚠ see below
3 governance / Guix packaging policy (Nix retired)
2 SonarQube
2 governance / Validate Hypatia Baseline
2 analyze (actions, none) CodeQL

Long tail, one repo each: Validate K9 contracts, Validate DEED manifests, scan / gitleaks,
openssf-compliance, estate-audit, estate-rules, check, core-fill-tests,
extension-build, GSBot build…, governance / Check Workflow Staleness,
governance / Language / package anti-pattern policy, Analyze (actions).

⚠ Three things worth a decision rather than a fix

1. Validate A2ML manifests is a live gate for a system that does not exist.
It is failing on gossamer#174, cadastra#51 and first-post#14. Standing estate doctrine is
that A2ML is dead — killed by the ML-community name clash. A gate that validates manifests for
a retired format is not something to repair; the likely correct action is to remove it. I have
not removed anything: that is a call for the owner, not a triage fix.

2. The Hypatia scanner reports under four different check names.
Hypatia neurosymbolic scan, scan / Hypatia Neurosymbolic Analysis,
hypatia / Hypatia Neurosymbolic Analysis, governance / Validate Hypatia Baseline. A ruleset
requires a check by exact context name, so four spellings means four separate required-check
entries to keep in step, and renaming any of them orphans every open PR that predates the rename.
Worth converging on one name — deliberately, with the PRs rebased, not casually.

3. governance / Workflow security linter is red on main too in at least
awesome-nickel and julia-professional-registry. A check that is red on main cannot be used to
judge a branch; it measures the estate, not the change.

Acceptance criteria

  • AC1 — For each of the 9 classes above, one determination is recorded: fix, retire the
    gate
    , or accept with a documented exemption. A class may not stay undetermined.
  • AC2 — Validate A2ML manifests has an explicit owner ruling (retire vs keep). If retired, it
    is removed from the 3 repos and from the estate template in the same change.
  • AC3 — The Hypatia check-name question is settled: either one canonical context name with every
    affected open PR rebased onto it, or an explicit decision to keep the four names, with the
    reason written down.
  • AC4 — Every check currently red on main is listed, with the date it went red. Nothing is
    required of a branch that its base does not satisfy.
  • AC5 — No class is closed by adding continue-on-error, by demoting a failure to a warning, or
    by dropping the check from the required set without AC1's determination. Repair or retire;
    never mute.

Scope note

This issue does not block any campaign PR. The lock cure is independently verified: the gate
kills a mutant that deletes a locked uses: entry, and the previously-dead workflows now execute.
A red here is a workflow getting its first real measurement in months, which is the cure
working, not a regression.

Related: #968 (campaign roll-up), #993 (lock policy + the pin bump), #987 (phantom blob pins).

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

Activity

  1. added
    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates
    governancePolicy, rulesets, standards, compliance, and their enforcement
    refactorRestructuring that preserves observable behaviour
    on Sep 22, 2026
  2. hyperpolymath commented on Sep 22, 2026

    @hyperpolymath
    OwnerAuthor

    Evidence from the A2ML-gate retirement sweep (13 PRs) — plus a root cause for this issue's #1 class

    The 13 PRs retiring the dead A2ML gate (see #1010, scope corrected there from 142/112 to 13) have been measured against their own base branches. They add nothing to the red surface, and they let me diagnose lint-workflows.

    1. The sweep introduces no reds

    Failing check-runs compared head vs base at the same (job) granularity, so a continue-on-error job cannot manufacture a phantom:

    • 11 of 13: head red set is a strict subset of base. Nothing new.
    • 2 of 13 (consent-aware-web#10, _pathroot#29) show lint-workflows as "new" — but that job does not exist on main at all. workflow-linter.yml triggers on push: with paths: ['.github/workflows/**'], and no recent main push touched a workflow. These PRs are simply the first commits in a long time to touch .github/workflows/, so a latent job ran for the first time. Surfaced, not introduced.

    startup_failure likewise only ever falls: common-signal 17→4, consent-aware-web 5→2, sr71-blackglider 5→2, project-ovine 2→2. Every head set is a strict subset of its base set, and the residue is governance.yml / hypatia-scan.yml — this issue's territory, not the gate's.

    2. ⭐ lint-workflows is two different failures wearing one name

    This issue lists lint-workflows as its largest class (10). It is not one defect. Resolving the failing step splits it cleanly:

    step repos root cause
    Check SPDX Headers cadastra, consent-aware-web, harvard-dehallucinator a false positive — an ordering bug, not a missing licence
    Check SHA-Pinned Actions common-signal, _pathroot genuinely unpinned refs

    The SPDX one is worth reading closely. gh actions-lock prepends its stamp above line 1, displacing the SPDX header:

    # This workflow is managed by gh actions-lock.     <- line 1, inserted by the tool
    # SPDX-License-Identifier: MPL-2.0                 <- line 2, was line 1
    

    The checker's own message is "Add '# SPDX-License-Identifier: MPL-2.0' as first line" — it tests line 1 only. So in consent-aware-web 19 of 19 workflow files are reported as missing an SPDX header while every one of them has it. The licence is present throughout; only the ordering is wrong. This is the same upstream gh actions-lock defect already recorded as stamp-placement, now shown to have a live estate-wide consequence.

    Two candidate cures, both one line:

    • (a) make the checker accept an SPDX header anywhere in the leading comment block — the tolerant fix, immune to any future tool that prepends a stamp; or
    • (b) make gh actions-lock write its stamp below the SPDX header, and re-stamp the estate.

    (a) is the more durable arm — it fixes the class rather than the instance, and does not require re-running a tool over every repo. I can implement it on request; it is a new finding, so under the standing stopping rule it is an issue with acceptance criteria rather than a blocker on the 13 PRs.

    The Check SHA-Pinned Actions half is unrelated and real — e.g. common-signal has codeql-action/init@v4.37.9, codeql-action/analyze@v4.37.9, action-editorconfig-checker@v3.0.0, action-gh-release@v3.0.3, all in files the sweep never touched. Note the codeql pair also feeds #1005.

    3. Correction to this issue's A2ML line

    This issue records 3 × Validate A2ML manifests as a live gate for something retired. Measured across all 84 live-workflow repos, that check name covers three unrelated populations — 13 repos run a dead action (renamed repo, could only ever fail), 54 run a live DEED validator under a residual A2ML step name, and 15 already call the successor. Only the 13 are being retired. Full table and method in #1010.

    4. Red surface of the 13 PRs

    repo PR failing check-runs (all pre-existing)
    hyperpolymath/proven-servers hyperpolymath/proven-servers#90 estate-audit, governance / Allowlist Preflight, governance / Language / package anti-pattern policy, governance / Trusted-base reduction policy, governance / Workflow security linter
    metadatastician/_pathroot metadatastician/_pathroot#29 analyze (actions, none), check, estate-rules, governance / Check Workflow Staleness, governance / Workflow security linter, Hypatia neurosymbolic scan, lint-workflows, openssf-compliance
    metadatastician/boj-server-mk2 metadatastician/boj-server-mk2#47 Empty-linter (invisible characters), estate-rules, governance / Workflow security linter, Hypatia neurosymbolic scan, SonarQube
    metadatastician/cadastra metadatastician/cadastra#53 analyze (actions, none), check, estate-rules, governance / Allowlist Preflight, governance / Workflow security linter, Hypatia neurosymbolic scan, lint-workflows, SonarQube
    metadatastician/common-signal metadatastician/common-signal#7 estate-rules, Hypatia neurosymbolic scan, lint-workflows
    metadatastician/consent-aware-web metadatastician/consent-aware-web#10 estate-rules, Hypatia neurosymbolic scan, lint-workflows
    metadatastician/harvard-dehallucinator metadatastician/harvard-dehallucinator#18 analyze (actions, none), estate-rules, governance / Allowlist Preflight, governance / Workflow security linter, Hypatia neurosymbolic scan, lint-workflows
    metadatastician/paint-type metadatastician/paint-type#89 Sustainability Analysis
    metadatastician/pong-ping metadatastician/pong-ping#7 estate-rules, Hypatia neurosymbolic scan
    metadatastician/project-ovine metadatastician/project-ovine#26 estate-rules, Hypatia neurosymbolic scan, SonarQube
    metadatastician/sim-public-relations metadatastician/sim-public-relations#24 estate-rules, governance / Allowlist Preflight, Hypatia neurosymbolic scan
    metadatastician/sr71-blackglider metadatastician/sr71-blackglider#20 estate-rules, Hypatia neurosymbolic scan
    metadatastician/stapeln metadatastician/stapeln#75 Aspect tests, governance / Language / package anti-pattern policy, governance / Validate Hypatia Baseline, scan / Hypatia Neurosymbolic Analysis

    paint-type#89 is the closest to landing: a single pre-existing red (Sustainability Analysis).

    Acceptance criteria

    1. Check SPDX Headers passes on a workflow whose SPDX line sits below a tool-inserted stamp — asserted by a test fixture with the stamp on line 1, so the fix cannot regress silently.
    2. Check SHA-Pinned Actions reports zero refs on common-signal and _pathroot after their codeql.yml/quality.yml/release.yml refs are pinned or lock-covered.
    3. The Hypatia family reports under one check name, not four.
    4. Each of the 13 PRs above reaches a state where every check is terminal-success at full suite size, or its remaining red is booked here with an owner.
    5. No PR in the set merges over a red (standing ruling).

    Nothing here blocks #1010's sweep; it is booked so the reds have an owner.

    🤖 Generated with Claude Code

    https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

  3. added
    scope:estateAffects many or all repos across the estate
    status:readyFully specified and ready to be picked up
    on Sep 30, 2026
  4. 19 remaining items

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementpriority:p1High - schedule nextrefactorRestructuring that preserves observable behaviourscope:estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked up

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions