From d5f4d283c64f35ee9c65ad4bf6e3da308bd11669 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 22 Sep 2026 22:52:22 +0100 Subject: [PATCH] =?UTF-8?q?fix(ci):=20cure=20the=20three=20main=20reds=20?= =?UTF-8?q?=E2=80=94=20drop=20Deno=20CI,=20bump=20governance=20pin=20to=20?= =?UTF-8?q?fad242d3?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Delete .github/workflows/deno-ci.yml and examples/web-project-deno.json. Deno is banned estate-wide (bun is the runtime) and the workflow ran on every pull request, so no PR could be fully green. Closes #160. The `deno-ci.yml: []` key leaves actions.lock with it; `gh actions-lock --no-fix` still verifies (16 workflows). - Bump governance-reusable.yml bd0df9ea → fad242d3 (standards main 2026-09-07, the pin tropical-types and nextgen-typing are green on). Cures: Allowlist Preflight (the live policy check is now a credentialed advisory job that skips without HYPATIA_SCAN_PAT), Workflow security linter (the SPDX predicate reads the whole leading comment block, so the `# managed by gh actions-lock` line 1 no longer hides line 2), and Code quality + docs (check-docs-presence.sh accepts .github/CONTRIBUTING.md, its documented canonical location). Lock-free: every inner action of the new reusable is already in actions.lock at the same SHA. Closes #163. Measured locally on this branch before push: standards' check-actions-lock-gate.sh (--verify-local) valid; exemption + debt ratchets OK; check-docs-presence.sh pass; SPDX + permissions predicate 16/16 workflows. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57 --- .github/workflows/actions.lock | 1 - .github/workflows/deno-ci.yml | 24 ------------------------ .github/workflows/governance.yml | 2 +- examples/web-project-deno.json | 20 -------------------- 4 files changed, 1 insertion(+), 46 deletions(-) delete mode 100644 .github/workflows/deno-ci.yml delete mode 100644 examples/web-project-deno.json diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 8173160..ccd82a9 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -11,7 +11,6 @@ workflows: '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - 'github/codeql-action@v4.38.0' - '.github/workflows/deno-ci.yml': [] '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': [] '.github/workflows/label-triage.yml': [] diff --git a/.github/workflows/deno-ci.yml b/.github/workflows/deno-ci.yml deleted file mode 100644 index bc232b6..0000000 --- a/.github/workflows/deno-ci.yml +++ /dev/null @@ -1,24 +0,0 @@ -# This workflow is managed by gh actions-lock. -# SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. -# Thin wrapper around the estate-wide reusable Deno CI bundle. -# See: hyperpolymath/standards/.github/workflows/deno-ci-reusable.yml -name: Deno CI - -on: - push: - branches: [main, master] - pull_request: - -concurrency: - group: ${{ github.workflow }}-${{ github.ref }} - cancel-in-progress: true - -permissions: - actions: read - contents: read - -jobs: - deno-ci: - uses: hyperpolymath/standards/.github/workflows/deno-ci-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4 # standards#168 head diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 165f567..77ebcee 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -35,4 +35,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4 # main 2026-05-27 (post-#219 workflow_sha fix) + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fad242d35291de1898242d6737ba02b74a59a2f2 # main 2026-09-07 (post-#742; live-policy advisory, SPDX comment-block predicate) diff --git a/examples/web-project-deno.json b/examples/web-project-deno.json deleted file mode 100644 index 6938b76..0000000 --- a/examples/web-project-deno.json +++ /dev/null @@ -1,20 +0,0 @@ -{ - "// NOTE": "Example deno.json for AffineScript web projects", - "tasks": { - "build": "deno run -A npm:affinescript", - "clean": "deno run -A npm:affinescript clean", - "watch": "deno run -A npm:affinescript -w", - "serve": "deno run -A jsr:@std/http/file-server .", - "test": "deno test --allow-all" - }, - "imports": { - "affinescript": "npm:affinescript@^12.1.0", - "@affinescript/core": "npm:@affinescript/core@^1.6.0", - "safe-dom/": "https://raw.githubusercontent.com/hyperpolymath/affinescript-dom-mounter/main/src/", - "proven/": "../proven/bindings/affinescript/src/" - }, - "compilerOptions": { - "allowJs": true, - "checkJs": false - } -}