Skip to content

fix(ci): close the governance gate — SPDX, permissions, SHA pins, reusable bump#41

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/governance-gate-sweep
Jul 21, 2026
Merged

fix(ci): close the governance gate — SPDX, permissions, SHA pins, reusable bump#41
hyperpolymath merged 1 commit into
mainfrom
fix/governance-gate-sweep

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The governance gate is all-jobs-must-pass, so these ship as one commit;
individually none of them turns the repo green.

  • SPDX line-1 header and a top-level permissions: block on every
    workflow file (the two Workflow security linter checks).
  • Every uses: tag reference resolved to a full 40-hex commit SHA. This
    satisfies the linter and also the repository's own
    sha_pinning_required Actions policy, which refuses @v4 at parse
    time — a refusal that produces no check run at all.
  • hypatia-scan.yml now grants security-events: write. This is not
    cosmetic and is not separable from the pin bump below: at HEAD the
    reusable declares security-events: write where the old pin declared
    read, and a called workflow cannot escalate beyond its caller's
    grant. Bumping the pin without this would fail at parse time.
  • The three reusables watched by the staleness gate (governance,
    hypatia-scan, scorecard) advanced to standards HEAD, which is 62
    commits ahead of the false-green cache fix and includes the
    deny-list-negative fix from standards#524.

mirror-reusable and secret-scanner-reusable are deliberately left on
their current pins: the staleness gate does not watch them, so they are
not holding anything red, and bumping them carries unrelated risk.

Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com

…sable bump

The governance gate is all-jobs-must-pass, so these ship as one commit;
individually none of them turns the repo green.

* SPDX line-1 header and a top-level `permissions:` block on every
  workflow file (the two `Workflow security linter` checks).
* Every `uses:` tag reference resolved to a full 40-hex commit SHA. This
  satisfies the linter and also the repository's own
  `sha_pinning_required` Actions policy, which refuses `@v4` at parse
  time — a refusal that produces no check run at all.
* `hypatia-scan.yml` now grants `security-events: write`. This is not
  cosmetic and is not separable from the pin bump below: at HEAD the
  reusable declares `security-events: write` where the old pin declared
  `read`, and a called workflow cannot escalate beyond its caller's
  grant. Bumping the pin without this would fail at parse time.
* The three reusables watched by the staleness gate (governance,
  hypatia-scan, scorecard) advanced to standards HEAD, which is 62
  commits ahead of the false-green cache fix and includes the
  deny-list-negative fix from standards#524.

`mirror-reusable` and `secret-scanner-reusable` are deliberately left on
their current pins: the staleness gate does not watch them, so they are
not holding anything red, and bumping them carries unrelated risk.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath marked this pull request as ready for review July 21, 2026 21:18
@hyperpolymath
hyperpolymath merged commit a50f628 into main Jul 21, 2026
23 of 24 checks passed
@hyperpolymath
hyperpolymath deleted the fix/governance-gate-sweep branch July 21, 2026 21:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant