Skip to content

fix(ci): resync workflow pins with actions.lock and resolve orphan Hypatia compare - #3

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0eaa4-occupancy-types
Sep 29, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0eaa4-occupancy-types

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown

Why this PR exists

The compare main...coderabbit/fix-hypatia-scan-failures/f36ac704 cannot become a PR. GitHub reports no common ancestor (HTTP 404):

  • main is 1b3578b
  • coderabbit/fix-hypatia-scan-failures/f36ac704 is parentless commit 40296f6 (“Initialize coderabbit/fix-hypatia-scan-failures/f36ac704”) created 2 seconds after the initial commit.

That orphan tree is an older RSR-template snapshot (with legacy machine-readable/, missing www/, deleted modern scripts, and AGPL-3.0 text). Merging it would destroy modern repository structure and the Session IR / stackcert research code.

The actual Hypatia ignore entries from rsr-template-repo#89 (RE001/RE005/RE008) are already on main in .hypatia-ignore.

Owner action: Delete the remote branch coderabbit/fix-hypatia-scan-failures/f36ac704.

CI fixes in this PR

Check Root Cause Fix
Hypatia Security Scan Reusable workflow at da2c748 clones hypatia@HEAD and runs mix escript.build. Scanner build failed upstream on hypatia@HEAD (hypatia#863 / standards#1014, same ~31s failure estate-wide). The scanner never ran. In addition, the caller workflow was missing secrets: inherit. Added secrets: inherit in .github/workflows/hypatia-scan.yml. Scanner build will succeed once upstream HEAD is cleared.
Workflows dying with startup_failure on main (CodeQL, Pages, etc.) Dependabot PR #1 bumped codeql-action to 4.38.2 (2892aa5) and haskell-actions/setup to v2.12.1 in the YAML without updating actions.lock. That desync causes GitHub Actions to reject runs at startup (creating 0 jobs and reporting "This run likely failed because of a workflow file issue."). Furthermore, codeql-action v4.38.1/4.38.2 is blocked estate-wide (nexia-list#100). Reverted codeql-action/init and analyze to b96794f015dfd88f77b49b1c93e0fa7110f94c63 (v4.38.0). Reverted haskell-actions/setup to v2.12.0.
Lock Sync Gate YAML pins now strictly match actions.lock. All 4 lock-sync clauses pass (verified against actions.lock).
Repo Map Determinism Gate REPOSITORY-MAP.adoc had not been regenerated after PR #2 added ULTRAPLAN.md and populated examples/. Regenerated via scripts/gen-repo-map.sh (tests/shape/repo_map_determinism_test.sh PASS).

Full write-up added in docs/status/HYPATIA-GATE.adoc.

…ets, and audit orphan branch

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4ceec7e4-01f0-4b9a-87e7-fc55474b84f3

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 8921157 into main Sep 29, 2026
2 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0eaa4-occupancy-types branch September 29, 2026 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant