Skip to content

fix(ci): cure the three main reds — drop Deno CI (#160), bump governance to standards@fad242d3 (#163) - #164

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/160-163-cure-main-reds
Sep 22, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/160-163-cure-main-reds

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Cures the three reds that sit on every push to main and every PR, so that a PR can be fully green again. Closes #160. Closes #163.

What changes

file change why
.github/workflows/deno-ci.yml deleted Deno is banned estate-wide (bun is the runtime); the workflow ran on every PR and failed. #160
examples/web-project-deno.json deleted the only Deno artefact; nothing else references it. #160
.github/workflows/governance.yml pin bd0df9ea → fad242d35291de1898242d6737ba02b74a59a2f2 (standards main 2026-09-07, post-#742) the pin tropical-types and nextgen-typing are green on. #163
.github/workflows/actions.lock drop the deno-ci.yml: [] key the workflow no longer exists

.github/CONTRIBUTING.md stays where it is: check-docs-presence.sh at the new pin accepts that path and names it the canonical location, so no move was needed.

How each #163 red is cured (measured, not assumed)

  • Allowlist Preflight — at fad242d3 the live-policy probe is a separate credentialed advisory job (actions-policy-live) that emits ::warning:: and never exit 1; allowlist-preflight no longer needs HYPATIA_SCAN_PAT (declared required: false).
  • Workflow security linter — the SPDX predicate now scans the whole leading comment block, so the # managed by gh actions-lock line 1 no longer hides the SPDX-License-Identifier on line 2. Ran the exact predicate over all 16 workflows on this branch: 0 failures. Also ran the three new steps' scripts locally (check-workflows-parse.sh, check-workflow-duplicate-keys.sh at fad242d3; check-action-pins-resolve.sh from main): all 16 parse, 16 clean, 3/3 pins resolve.
  • Code quality + docs — check-docs-presence.sh passes with CONTRIBUTING under .github/ (✅ Core documentation present).

Other gates at the new pin, run locally against this branch:

  • check-actions-lock-gate.sh with update-actions-lock.sh --verify-local (the actions-lock-verify job): valid: true, transitive coverage verified. One pre-existing advisory sha-as-ref note on push-email-notify.yml's bare-SHA ref, not a failure.
  • exemption ratchet vs origin/main: unchanged (.hypatia-ignore 9, root-allow.txt 1), OK. Debt ratchet: no Debtfile, nothing to ratchet.
  • check-ts-allowlist.sh, check-language-policy.sh (the two new language-policy steps): both pass. Tracked *.v files are Coq; the V-lang rule keys on v.mod/vpkg.json only.

Lock-free bump: every step-level action inside governance-reusable.yml@fad242d3 (checkout 3d3c42e5, cache 55cc8345, editorconfig 840e866d, setup-beam 54075bcc) is already in actions.lock at that SHA. Standards HEAD would bump editorconfig to 51f63319 and force a lock regeneration; deliberately not taken.

Note on the Rust CI check

rust-ci-reusable.yml@bd0df9ea's detect job checks out refs/pull/N/merge. When a PR is merged within seconds of opening, the merge ref is gone by the time the queued job starts and the check fails on Checkout repository (that is what happened to #158 and #159; #157, held open, passed). Holding this PR open until every check is green avoids the race; a pin bump to a reusable with the github.sha cure is a separate follow-up.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

… to fad242d3

- Delete .github/workflows/deno-ci.yml and examples/web-project-deno.json.
  Deno is banned estate-wide (bun is the runtime) and the workflow ran on
  every pull request, so no PR could be fully green. Closes #160. The
  `deno-ci.yml: []` key leaves actions.lock with it; `gh actions-lock
  --no-fix` still verifies (16 workflows).
- Bump governance-reusable.yml bd0df9ea → fad242d3 (standards main
  2026-09-07, the pin tropical-types and nextgen-typing are green on).
  Cures: Allowlist Preflight (the live policy check is now a credentialed
  advisory job that skips without HYPATIA_SCAN_PAT), Workflow security
  linter (the SPDX predicate reads the whole leading comment block, so
  the `# managed by gh actions-lock` line 1 no longer hides line 2), and
  Code quality + docs (check-docs-presence.sh accepts
  .github/CONTRIBUTING.md, its documented canonical location). Lock-free:
  every inner action of the new reusable is already in actions.lock at
  the same SHA. Closes #163.

Measured locally on this branch before push: standards'
check-actions-lock-gate.sh (--verify-local) valid; exemption + debt
ratchets OK; check-docs-presence.sh pass; SPDX + permissions predicate
16/16 workflows.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@coderabbitai

coderabbitai Bot commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2b04e87d-04d8-4700-955f-c64e06276f32

📥 Commits

Reviewing files that changed from the base of the PR and between 74202cb and d5f4d28.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • .github/workflows/deno-ci.yml
  • .github/workflows/governance.yml
  • examples/web-project-deno.json
 ________________________________________________________________
< 'Works on my machine' is not a QA strategy, it's a confession. >
 ----------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 3c8796a into main Sep 22, 2026
25 of 28 checks passed
@hyperpolymath
hyperpolymath deleted the fix/160-163-cure-main-reds branch September 22, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant