Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 10 additions & 10 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ workflows:
- 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d'
- 'actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346'
- 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9'
- 'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d'
- 'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
'.github/workflows/changelog-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/changelog.yml': []
Expand All @@ -33,7 +33,7 @@ workflows:
- 'actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3'
'.github/workflows/ci-pipeline.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d'
- 'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
- 'oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6'
'.github/workflows/codeql-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
Expand Down Expand Up @@ -99,7 +99,7 @@ workflows:
- 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d'
- 'actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346'
- 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9'
- 'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d'
- 'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
'.github/workflows/pages.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346'
Expand Down Expand Up @@ -147,7 +147,7 @@ workflows:
- 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
'.github/workflows/tailscale-connect-reusable.yml':
- 'tailscale/github-action@780049a30b6ff5c378a9e7b389d15ece7a204888'
- 'tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd'
dependencies:
'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9':
ref: '55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
Expand Down Expand Up @@ -233,9 +233,9 @@ dependencies:
commit: 'sha1-abea47f85e598557f500fa1fd2ab7464fcb39406'
owner_id: 1006268
repo_id: 212984112
'haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d':
ref: 'v2.12.1'
commit: 'sha1-0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
owner_id: 75048950
repo_id: 623796603
'ocaml/setup-ocaml@93303b622b2522e4411e295f9e77411a24912ac7':
Expand Down Expand Up @@ -263,9 +263,9 @@ dependencies:
commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
owner_id: 580492
repo_id: 298565987
'tailscale/github-action@780049a30b6ff5c378a9e7b389d15ece7a204888':
ref: '780049a30b6ff5c378a9e7b389d15ece7a204888'
commit: 'sha1-780049a30b6ff5c378a9e7b389d15ece7a204888'
'tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd':
ref: 'v4.2.0'
commit: 'sha1-d1b6cd204f8dceda5b3eaad7f1f767be390056cd'
owner_id: 48932923
repo_id: 360548653
'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555':
Expand Down
37 changes: 32 additions & 5 deletions .github/workflows/governance-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -230,10 +230,19 @@ jobs:
# cache step because cache restore happens before the clone, so the key
# cannot hash a not-yet-cloned tree — it must hash the remote ref.
sha=$(git ls-remote https://github.com/hyperpolymath/hypatia.git HEAD | cut -f1)
if [ -z "$sha" ]; then
if [[ ! "$sha" =~ ^[0-9a-f]{40}$ ]]; then
echo "ERROR: could not resolve hypatia HEAD via git ls-remote" >&2
exit 1
fi
case "$sha" in
4654d7a3d49f413f49c00fb7e592db7d026ffca2|\
de52a3dabb2c10bf239784e50ab25267a5a6ebbb|\
43124f025ab338c26f137927be1e5ca6a84bd8c2|\
4f9874e3f589f2e4964f788687266580ccde4507)
echo "::warning::Hypatia HEAD $sha hits compile break hyperpolymath/hypatia#869 (standards#1050); holding on 9f2f62f5c9463c79b33a5ebf54372166ce56f349 until upstream advances"
sha="9f2f62f5c9463c79b33a5ebf54372166ce56f349"
;;
esac
echo "sha=$sha" >> "$GITHUB_OUTPUT"
echo "Resolved hypatia HEAD: $sha"

Expand All @@ -252,21 +261,39 @@ jobs:
# ran against a stale ruleset. No restore-keys on purpose — a partial
# restore would repopulate ~/hypatia and the guards below would skip
# the rebuild, reintroducing the staleness.
key: hypatia-scanner-v3-${{ runner.os }}-${{ steps.hypatia-rev.outputs.sha }}
key: hypatia-scanner-v4-${{ runner.os }}-${{ steps.hypatia-rev.outputs.sha }}

- name: Clone Hypatia
- name: Check out resolved Hypatia commit
if: needs.workflow-staleness.outputs.has_baseline == 'true'
env:
HYPATIA_SHA: ${{ steps.hypatia-rev.outputs.sha }}
run: |
set -euo pipefail
if [ ! -d "$HOME/hypatia" ]; then
git clone --depth 1 https://github.com/hyperpolymath/hypatia.git "$HOME/hypatia"
git init "$HOME/hypatia"
git -C "$HOME/hypatia" remote add origin https://github.com/hyperpolymath/hypatia.git
git -C "$HOME/hypatia" fetch --depth 1 origin "$HYPATIA_SHA"
git -C "$HOME/hypatia" checkout --detach FETCH_HEAD
fi
ACTUAL_SHA=$(git -C "$HOME/hypatia" rev-parse HEAD)
if [ "$ACTUAL_SHA" != "$HYPATIA_SHA" ]; then
echo "::error::Hypatia cached source does not match the resolved commit"
exit 1
fi

- name: Build Hypatia scanner
if: needs.workflow-staleness.outputs.has_baseline == 'true'
run: |
cd "$HOME/hypatia"
if [ ! -x hypatia ]; then
mix deps.get && mix escript.build
if ! (mix deps.get && mix escript.build); then
echo "::error::Hypatia scanner build failed at commit $(git rev-parse HEAD) — see upstream hyperpolymath/hypatia"
exit 1
fi
fi
if [ ! -x hypatia ]; then
echo "::error::Hypatia scanner binary is missing after build"
exit 1
fi

# A reusable workflow only auto-checks-out its own YAML, not sibling
Expand Down
50 changes: 34 additions & 16 deletions .github/workflows/hypatia-scan-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,19 @@ jobs:
echo "ERROR: could not resolve hypatia HEAD via git ls-remote" >&2
exit 1
fi
# Hold past the 4-commit hyperpolymath/hypatia#869 compile-break window
# (4654d7a3d4..4f9874e3f5, unescaped `/` in lib/rules/pin_integrity.ex:56)
# on the last compilable main commit (9f2f62f5c9463c79b33a5ebf54372166ce56f349).
# As soon as hypatia main advances past 4f9874e3f5, HEAD is used directly.
case "$sha" in
4654d7a3d49f413f49c00fb7e592db7d026ffca2|\
de52a3dabb2c10bf239784e50ab25267a5a6ebbb|\
43124f025ab338c26f137927be1e5ca6a84bd8c2|\
4f9874e3f589f2e4964f788687266580ccde4507)
echo "::warning::Hypatia HEAD $sha hits compile break hyperpolymath/hypatia#869 (standards#1050); holding on 9f2f62f5c9463c79b33a5ebf54372166ce56f349 until upstream advances"
sha="9f2f62f5c9463c79b33a5ebf54372166ce56f349"
;;
esac
echo "sha=$sha" >> "$GITHUB_OUTPUT"
echo "Resolved hypatia HEAD: $sha"

Expand Down Expand Up @@ -89,7 +102,14 @@ jobs:
run: |
cd "$HOME/hypatia"
if [ ! -x hypatia ]; then
mix deps.get && mix escript.build
if ! (mix deps.get && mix escript.build); then
echo "::error::Hypatia scanner build failed at commit $(git rev-parse HEAD) — see upstream hyperpolymath/hypatia"
exit 1
fi
fi
if [ ! -x hypatia ]; then
echo "::error::Hypatia scanner binary is missing after build"
exit 1
fi

- name: Run Hypatia scan
Expand All @@ -106,7 +126,8 @@ jobs:
# code-scanning still works in repos where the PAT isn't present yet.
GITHUB_TOKEN: ${{ secrets.HYPATIA_SCAN_PAT || secrets.GITHUB_TOKEN }}
run: |
echo "Scanning repository: ${{ github.repository }}"
set -euo pipefail
echo "Scanning repository: ${GITHUB_REPOSITORY:-}"
# --exit-zero: hypatia-cli exits 1 when findings exist; under the default
# `bash -eo pipefail` that aborts this step before the counts/outputs/summary
# run AND skips the upload, so the gate fails opaquely. Gate on the severity
Expand All @@ -120,24 +141,25 @@ jobs:
# findings fixed in code since the last scan auto-close instead of
# orphaning as stale open alerts.
HYPATIA_FORMAT=sarif "$HOME/hypatia/hypatia-cli.sh" scan . --exit-zero > hypatia.sarif
if [ ! -s hypatia.sarif ]; then
echo "::error::Hypatia did not produce hypatia.sarif"
exit 2
fi

- name: Validate findings and count severities
id: scan
run: |
set -euo pipefail
# Exactly one JSON array of findings, each with a recognised severity.
# Missing/truncated output is a scanner error, never an empty clean
# scan: a scanner that emits nothing is indistinguishable from a
# crashed/truncated run, so the gate fails closed (science-ci-
# security-test.rb pins this too). The #741 `empty findings are
# valid` control tested the pre-#771 slurp accident (`[[]]` has
# length 1); #771's `length > 0` is the documented intent.
if [ ! -s hypatia-findings.json ] || ! jq -e '
type == "array" and length > 0 and all(.[];
# Missing/truncated/multi-document output is a scanner error and fails
# closed; a single well-formed `[]` is a valid clean scan when the
# scanner step succeeded (standards#1054).
if [ ! -s hypatia-findings.json ] || ! jq -e -s '
length == 1 and (.[0] | type == "array" and all(.[];
type == "object" and (.severity as $s |
["critical", "high", "medium", "warn", "low", "info", "informational"] | index($s) != null))
["critical", "high", "medium", "warn", "low", "info", "informational"] | index($s) != null)))
' hypatia-findings.json >/dev/null; then
echo "::error::Hypatia did not produce a valid findings array"
echo "::error::Hypatia did not produce one valid findings array"
exit 2
fi

Expand Down Expand Up @@ -166,7 +188,6 @@ jobs:
} >> "$GITHUB_STEP_SUMMARY"

- name: Relativize finding paths
if: always()
run: |
# Hoisted out of the gate step so the SARIF filter and the gate share
# ONE definition of a finding's path. code_safety / honest_completion
Expand Down Expand Up @@ -204,7 +225,6 @@ jobs:

- name: Filter SARIF through the baseline before upload
id: filter_baseline
if: always()
run: |
# ⚠ WITHOUT THIS, ACKNOWLEDGING A FINDING DOES NOT UNBLOCK ANYTHING.
# A finding travelled two paths that never met: the gate filtered
Expand Down Expand Up @@ -233,7 +253,6 @@ jobs:
bash "$FILTER" hypatia.sarif hypatia-findings.relativized.json .hypatia-baseline.json

- name: Upload SARIF to code scanning
if: always()
# NOTE: this does NOT make under-permissioned callers "skip gracefully".
# This workflow declares `security-events: write` at the top, so a
# caller granting only `read` is rejected at startup and NO step of
Expand All @@ -258,7 +277,6 @@ jobs:
fi

- name: Upload findings artifacts
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: hypatia-scan-findings
Expand Down
4 changes: 2 additions & 2 deletions .machine_readable/REGISTRY.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ name = "Hyperpolymath Estate Constitution"
stream = "governance"
home = "0-canon/constitution/"
canonical_doc = "0-canon/constitution/README.adoc"
source_hash = "sha256:e0f2c790f01b05bd331748918f197e7df0273ec0aa745908a109db3b2113bca7"
source_hash = "sha256:be48496f7f786d9aca12271afeb063c10b8ea6ce6bec2efad4f2401d0186ccef"
route = "the highest estate-level rules, authority precedence, assurance, contribution, exceptions, and known tensions"

[[spec]]
Expand Down Expand Up @@ -207,7 +207,7 @@ name = "RSR — Rhodium Standard Repositories"
stream = "governance"
home = "rhodium-standard-repositories/"
canonical_doc = "rhodium-standard-repositories/README.adoc"
source_hash = "sha256:5e9282daf9273d89ddd58af8af87c2a1d73e95fde6a43409ebccca7b1d4878b9"
source_hash = "sha256:bc9c99e1d48f9b6ca6985fc705976ed0fee560d60c1d3259e1647a382b76a1e1"
route = "the repository-compliance standard every repo is graded against"

[[spec]]
Expand Down
1 change: 0 additions & 1 deletion 1-formats/deed/spec/abnf/deed.abnf
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@
; archive/deed.abnf_v0.1.0-draft under its true version. Its only extra rule
; (version-field) is superseded: v1.0.0 folds :schema-version into `field`
; with the "exactly once" side condition.
; pending owner ruling. Grammar below is unchanged.
; Requires RFC 7405 (%s"..." case-sensitive string literals).
;
; NOTE: there is no "key = value" production and no "[section]" production.
Expand Down
4 changes: 2 additions & 2 deletions ULTRAPLAN-2026-09-24.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -925,7 +925,7 @@ mechanically against the API census). Disposition codes:
|#960
|D73-C downstream: 21 launcher descriptors + trigger/ still name the de
|KEEP
|21 launcher descriptors + trigger/ name deleted launcher-standard.a2ml - this repo
|21 launcher descriptors + trigger/ name deleted launcher-standard (.a2ml) - this repo
|===

=== Cluster C8: Debtfile & ratchet mechanics (4 issues)
Expand Down Expand Up @@ -1380,7 +1380,7 @@ amended (Rule 8: record the supersession, don't amend silently)
|this repo states 2026-09-22 (LANGUAGE-POLICY v1.6.0, `language-policy.scm`)
|*Needs a one-line ruling* declaring 2026-09-22 canonical, then propagation

|21 launcher descriptors naming deleted `launcher-standard.a2ml` (#960)
|21 launcher descriptors naming deleted `launcher-standard (.a2ml)` (#960)
|this repo (`launcher/`)
|*Open, fixable here* — rename-or-delete the references

Expand Down
Loading
Loading