Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 30 additions & 11 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,22 +1,41 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file
# SPDX-License-Identifier: MPL-2.0
# Estate dependabot policy: hyperpolymath/standards docs/DEPENDABOT-POLICY.adoc
# (standards#297). Local history that shaped this file: #63/#64/#68/#69 and
# issue #67.
#
# READ BEFORE MERGING ANY PR THIS FILE PRODUCES:
# Dependabot rewrites `uses:` refs in the workflow YAML but CANNOT touch
# .github/workflows/actions.lock. A merged bump therefore desyncs the lock,
# and GitHub then refuses EVERY affected workflow at startup (jobs=0,
# "startup_failure", no logs). That is what killed all 9 workflows on main
# after #69/#70 (issue #67). The `Lock Sync Gate` check goes red on exactly
# such a PR; a red gate on a dependabot PR means "regenerate the lock in the
# same PR", never "merge anyway". See docs/ci/CHECK-DETERMINATIONS.adoc.

version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
# Weekly, not daily: every actions bump needs a paired lockfile
# regeneration by a human, so the cadence is set to what a human
# reviews, not what a bot can emit (estate policy).
interval: "weekly"
groups:
actions:
patterns:
- "*"
open-pull-requests-limit: 2
ignore:
# HOLD: github/codeql-action at v4.38.0 (SHA-pinned). v4.38.1 fails
# GitHub workflow-startup validation estate-wide (nexia-list#100;
# SHA-form re-bump bypassed versions-scoped ignores - nexia-list#101).
# Hold until upstream clears 4.38.1 or a new release verifies green.
- dependency-name: "github/codeql-action"

# HOLD: github/codeql-action at v4.38.0 (SHA-pinned b96794f0). v4.38.1
# (1c5b6756) fails GitHub workflow-startup validation estate-wide
# (nexia-list#100). Hold until upstream clears 4.38.1 or a newer release
# verifies green; revisit deliberately, not weekly.
#
# The trailing * is load-bearing. Workflows reference the SUBPATH actions
# (github/codeql-action/init, /analyze, /upload-sarif) and Dependabot
# treats each subpath as its own dependency name -- so the previous bare
# "github/codeql-action" entry matched NONE of them. That is how #69
# re-bumped 4.38.0 -> 4.38.1 straight through the hold that #64 set and
# #68 re-asserted.
- dependency-name: "github/codeql-action*"
25 changes: 4 additions & 21 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -11,12 +11,10 @@ workflows:
- 'actions/configure-pages@v6.0.0'
- 'actions/deploy-pages@v5.0.1'
- 'actions/upload-pages-artifact@v5.0.0'
- 'haskell-actions/setup@v2.12.0'
- 'haskell-actions/setup@v2.12.1'
'.github/workflows/ci.yml':
- 'actions/checkout@v7.0.1'
- 'denoland/setup-deno@v2.0.5'
- 'dtolnay/rust-toolchain@v1'
- 'jetli/wasm-pack-action@v0.4.0'
'.github/workflows/codeql.yml':
- 'actions/checkout@v7.0.1'
- 'github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63'
Expand Down Expand Up @@ -96,11 +94,6 @@ dependencies:
repo_id: 496012378
uses:
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
'denoland/setup-deno@v2.0.5':
ref: 'v2.0.5'
commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
owner_id: 42048915
repo_id: 356423100
'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772':
ref: '6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
Expand Down Expand Up @@ -131,14 +124,9 @@ dependencies:
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
owner_id: 9919
repo_id: 259445878
'github/codeql-action@v4.38.0':
ref: 'v4.38.0'
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
owner_id: 9919
repo_id: 259445878
'haskell-actions/setup@v2.12.0':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
'haskell-actions/setup@v2.12.1':
ref: 'v2.12.1'
commit: 'sha1-0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
owner_id: 75048950
repo_id: 623796603
'hyperpolymath/smtp-notify-action@v0.3.0':
Expand All @@ -165,11 +153,6 @@ dependencies:
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
'jetli/wasm-pack-action@v0.4.0':
ref: 'v0.4.0'
commit: 'sha1-0d096b08b4e5a7de8c28de67e11e945404e9eefa'
owner_id: 1142758
repo_id: 244578171
'peter-evans/repository-dispatch@v4.0.1':
ref: 'v4.0.1'
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
Expand Down
33 changes: 21 additions & 12 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,37 @@
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
#
# CI for the implemented part of this repository: the Rust PDF core.
#
# History (issue #67): this file used to carry `core-fill-tests` and
# `extension-build`, which ran `deno task test:core-fill`, `deno task build:wasm`
# and `deno task build`. Those tasks lived in deno.json, which #43 deleted on
# 2026-08-24; the two jobs were red on every run from then on and were RETIRED
# by #71. `test:core-fill` was `cargo test ... fill_blocks_`, a strict subset of
# the `rust-core` job below. The extension bundle has no toolchain in this
# checkout (see README "Current status"); when one lands, add its build job
# here and record it in docs/ci/CHECK-DETERMINATIONS.adoc.
#
# There is deliberately NO lockfile-verification job in this file. A job that
# checks actions.lock from inside a workflow that GitHub refuses to start when
# actions.lock is out of sync can never report the fault it exists to catch.
# That check lives in lock-sync-gate.yml, which carries no `uses:` at all and
# is therefore immune to the failure it detects.
name: CI
permissions:
actions: read
contents: read

on:

push:
branches: ["main"]
pull_request:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
rust-core:
name: Rust core (tests, formatting, lint)
Expand All @@ -31,14 +51,3 @@ jobs:
run: cargo test --manifest-path rust/pdftool_core/Cargo.toml --locked
- name: Run Clippy
run: cargo clippy --manifest-path rust/pdftool_core/Cargo.toml --locked --all-targets -- -D warnings

workflow-lock:
name: Verify Actions lockfile
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@v7.0.1
- name: Install GNU awk
run: sudo apt-get update && sudo apt-get install -y gawk
- name: Verify workflow lockfile
run: ./scripts/check-lock-sync.sh
4 changes: 2 additions & 2 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ jobs:

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 -- HOLD: do not bump; 4.38.1 (1c5b675) is blocked estate-wide (nexia-list#100); dependabot ignore in .github/dependabot.yml
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
Expand Down Expand Up @@ -112,6 +112,6 @@ jobs:
exit 1

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 -- HOLD: do not bump; 4.38.1 (1c5b675) is blocked estate-wide (nexia-list#100); dependabot ignore in .github/dependabot.yml
with:
category: "/language:${{matrix.language}}"
2 changes: 1 addition & 1 deletion .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -246,7 +246,7 @@ jobs:
always() &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.fork != true)
uses: github/codeql-action/upload-sarif@1c5b675653bb5c22dbe9b12b556ec555138e09fd # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)
uses: github/codeql-action/upload-sarif@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 -- HOLD: do not bump; 4.38.1 (1c5b675) is blocked estate-wide (nexia-list#100); dependabot ignore in .github/dependabot.yml
with:
sarif_file: hypatia.sarif
# Distinct category so Hypatia results coexist with CodeQL's
Expand Down
4 changes: 4 additions & 0 deletions CHANGELOG.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,10 @@ noreply@anthropic.com

==== Fixed

* fix(ci): resync actions.lock after #69/#70/#71 desync that startup-killed
every workflow on main; re-pin codeql-action to the held v4.38.0; correct the
dependabot codeql ignore glob; retire `core-fill-tests`/`extension-build` with
a written determination in docs/ci/CHECK-DETERMINATIONS.adoc (#67)
* fix(ci): sync hypatia-scan.yml to canonical (#5)
* fix(ci): adopt canonical hypatia-scan.yml (#4)
* fix(scorecard): enforce granular permissions and add fuzzing
Expand Down
16 changes: 10 additions & 6 deletions TEST-NEEDS.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -7,18 +7,20 @@
[cols=",,",options="header",]
|===
|Category |Count |Notes
|Test directories |1 |Location(s): /tests
|CI workflows |15 |Running tests on GitHub Actions
|Unit tests |Configured |AffineScript Jest/Vitest setup
|Test directories |1 |Location(s): /tests (aspect + fuzz placeholder)
|CI workflows |15 |`ci.yml` runs the Rust core checks; see docs/ci/CHECK-DETERMINATIONS.adoc
|Unit tests |Implemented |Rust `pdftool_core` (`cargo test --locked`)
|===

=== What’s Covered

* [x] AffineScript unit tests
* [x] JavaScript interop tests
* [x] Rust core unit tests (block detection, `fill_blocks_*` AcroForm writeback, taxonomy errors)
* [x] `cargo fmt --check` and `cargo clippy -D warnings` in CI

=== Still Missing (for CRG B+)

* [ ] Extension frontend build + tests — no AffineScript/bundle toolchain in this checkout
(retired CI job `extension-build`; see docs/ci/CHECK-DETERMINATIONS.adoc)
* [ ] Code coverage reports (codecov integration)
* [ ] Detailed test documentation in CONTRIBUTING.md
* [ ] Integration tests beyond unit tests
Expand All @@ -28,5 +30,7 @@

[source,bash]
----
npm run test # or: affinescript build && npm run test
cargo fmt --manifest-path rust/pdftool_core/Cargo.toml -- --check
cargo test --manifest-path rust/pdftool_core/Cargo.toml --locked
cargo clippy --manifest-path rust/pdftool_core/Cargo.toml --locked --all-targets -- -D warnings
----
3 changes: 2 additions & 1 deletion TOPOLOGY.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,8 @@ CORE (RUST/WASM)
Error Taxonomy ██████████ 100% Structured error codes active

REPO INFRASTRUCTURE
Deno Build Tasks ██████████ 100% deno task build verified
Rust CI (fmt/test/clippy) ██████████ 100% ci.yml rust-core job
Extension bundle pipeline ░░░░░░░░░░ 0% deno.json removed in #43; no toolchain
.machine_readable/ ██████████ 100% STATE.a2ml tracking
Containerfile ██████████ 100% Reproducible dev env

Expand Down
Loading