Skip to content

Triage: 3 pre-existing red checks surfaced by the actions.lock cure (PR #566) #568

Description

@hyperpolymath

Summary

hyperpolymath/gitbot-fleet#566 carries the actions.lock desync cure from the estate campaign (hyperpolymath/standards#968). The lockfile change itself verifies clean. The checks listed below are pre-existing reds that only became visible once the cure revived the workflows that run them.

Per the standing stopping rule, a pre-existing red is an issue with acceptance criteria, not a merge blocker. This is that issue for this repo.

Failing checks (3)

GSBot build, tests and dependency security

  • Determine whether GSBot build, tests and dependency security is fixed, retired, or accepted with a documented exemption. It may not stay undetermined.
  • Record whether GSBot build, tests and dependency security is also red on main. If it is, it measures the estate, not this change, and nothing is required of this branch that its base does not satisfy.
  • If fixed: the check is green on this PR head, and the fix is in the repo — not continue-on-error, not a demotion to a warning, not removal from the required set.

governance / Workflow security linter

Also red on main in several repos. Confirm whether this repo's main is red before treating it as a branch defect.

  • Determine whether governance / Workflow security linter is fixed, retired, or accepted with a documented exemption. It may not stay undetermined.
  • Record whether governance / Workflow security linter is also red on main. If it is, it measures the estate, not this change, and nothing is required of this branch that its base does not satisfy.
  • If fixed: the check is green on this PR head, and the fix is in the repo — not continue-on-error, not a demotion to a warning, not removal from the required set.

governance / Validate Hypatia Baseline

One of four different check names the Hypatia scanner reports under across the estate. See standards#994 AC3 before renaming anything — a rename orphans every open PR that predates it.

  • Determine whether governance / Validate Hypatia Baseline is fixed, retired, or accepted with a documented exemption. It may not stay undetermined.
  • Record whether governance / Validate Hypatia Baseline is also red on main. If it is, it measures the estate, not this change, and nothing is required of this branch that its base does not satisfy.
  • If fixed: the check is green on this PR head, and the fix is in the repo — not continue-on-error, not a demotion to a warning, not removal from the required set.

Acceptance criteria for closing this issue

  • Every check above has a recorded determination (fix / retire / exempt).
  • Any check determined fixed is green on a run of this repo's default branch.
  • Any check determined retired is removed from the workflow and from the repo's required-check set in the same change.
  • Any check determined exempt has the exemption written down with its reason and a review date.
  • No check was closed by muting it. Repair or retire; never silence.

Context

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesresearchOpen investigation; the outcome is knowledge, not code

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions