You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Cross-filed because comment permissions on this token are issues:create-only (commenting on #994 and #968 returns 403 Resource not accessible by integration, verified) — please fold into those threads.
From metadatastician/chronicles-of-slavia#100 closure (PR #113, merged 75a6983)
Record on the consumer side: docs/reports/ci/issue-100-closure-2026-09-28.adoc.
For the class notes of #994 — four determinations, four root mechanisms
check name
determination
root mechanism
SonarQube (CI/Quality)
exempt — documented, review 2026-10-05
Credential-defect class, not workflow defect. Recipe: read past the annotation to the first authenticated call — GET https://api.sonarcloud.io/analysis/jres → HTTP 403 Forbidden … check … SONAR_TOKEN. If jres is 403, the repo secret is rejected (expired/revoked/insufficient scope) and no config edit can go green: rotate, then confirm project provisioning (the project key doesn't resolve anonymously either). Workflow kept running + reporting red; nothing muted.
governance / Allowlist Preflight
fixed (per-job success on main at 05e27c6, a3dd9bef, 75a6983)
Old live-policy caller drifted against moving main; cured by standards@2479cf76 adoption (slavia #111), pin ratcheted by foundation_ci_security_test.sh.
governance / Workflow security linter
fixed (same runs)
Same adoption.
Hypatia neurosymbolic scan
fixed (per-job success on main at 75a6983, incl. deposit-findings cascade)
Upstream compile break: hypatia lib/rules/pin_integrity.ex:56 bare / in ~r/…/ class → MismatchedDelimiterError; introduced by #862, still at HEAD. Bisected → last-green 9f2f62f5c9463c79b33a5ebf54372166ce56f349; consumer pinned there with advance-only rule; upstream: hyperpolymath/hypatia#869. Infrastructure lessons for #994's defaults: (a) pin-affecting merges (#862, #867) went in with Escript Soundness red — that gate should block or at least gate-pin bumps; (b) ship an allow-failure: false-style knob for genuinely-blocking rungs like Soundness.
Method note for every future "red on PR head" reading (estate-wide): Arena-session PR branches have every run die at startup with Actor is not allowed to trigger Actions workflows — content-independent (annotation on run 36407881271; identical pattern on arena/01a0e227 ahead of #111; same tree green on main after merge). Arena PR-head runs are not measurable; measure main runs after merge.
For #968 — mechanism confirmation + the loop that keeps reopening it
Enforcement is native, runner-side, and total:Using locked action versions from the workflow's lockfile (verbatim runner line). Violations don't just fail a gate — every workflow in the repo dies at startup_failure with zero jobs, including the gates that verify the lock. Diagnosis order for whole-repo startup-death days: check actions.lock sync first.
Measured recurrence: slavia's Phase C — E2E verification + gateway↔gnosis seam tests #98-era cure held until Wave 7: Nix-mirror retirement (hesiod-dns-map…iseriser) #112 — a routine Dependabot group bump rewrote three uses: and never touched the lock (Dependabot structurally cannot). Result: exactly 6 violations, CodeQL/E2E/OikosBot at zero jobs, both lock gates red — and auto-merge completed anyway (lock gates are not in the required set per dependabot-automerge.yml: secret-scanner, codeql, hypatia-scan, openssf-compliance, build/test). A red lock gate does not stop merges in this estate.
Oracle fragility:check-lock-sync.sh depends on gawk's 3-arg match(); on non-gawk-awk systems the verifier itself misbehaves. (Slavia's session had to build gawk 4.1.0 from source to trust the verdict.) Worth documenting the dependency loudly or shipping a POSIX fallback.
Cross-filed because comment permissions on this token are
issues:create-only (commenting on #994 and #968 returns403 Resource not accessible by integration, verified) — please fold into those threads.From
metadatastician/chronicles-of-slavia#100 closure (PR #113, merged75a6983)Record on the consumer side:
docs/reports/ci/issue-100-closure-2026-09-28.adoc.For the class notes of #994 — four determinations, four root mechanisms
SonarQube(CI/Quality)GET https://api.sonarcloud.io/analysis/jres → HTTP 403 Forbidden … check … SONAR_TOKEN. Ifjresis 403, the repo secret is rejected (expired/revoked/insufficient scope) and no config edit can go green: rotate, then confirm project provisioning (the project key doesn't resolve anonymously either). Workflow kept running + reporting red; nothing muted.governance / Allowlist Preflightsuccessonmainat05e27c6,a3dd9bef,75a6983)main; cured bystandards@2479cf76adoption (slavia #111), pin ratcheted byfoundation_ci_security_test.sh.governance / Workflow security linterHypatia neurosymbolic scansuccessonmainat75a6983, incl. deposit-findings cascade)lib/rules/pin_integrity.ex:56bare/in~r/…/class →MismatchedDelimiterError; introduced by #862, still at HEAD. Bisected → last-green9f2f62f5c9463c79b33a5ebf54372166ce56f349; consumer pinned there with advance-only rule; upstream: hyperpolymath/hypatia#869. Infrastructure lessons for #994's defaults: (a) pin-affecting merges (#862, #867) went in withEscript Soundnessred — that gate should block or at least gate-pin bumps; (b) ship anallow-failure: false-style knob for genuinely-blocking rungs like Soundness.Method note for every future "red on PR head" reading (estate-wide): Arena-session PR branches have every run die at startup with
Actor is not allowed to trigger Actions workflows— content-independent (annotation on run 36407881271; identical pattern onarena/01a0e227ahead of #111; same tree green onmainafter merge). Arena PR-head runs are not measurable; measuremainruns after merge.For #968 — mechanism confirmation + the loop that keeps reopening it
Using locked action versions from the workflow's lockfile(verbatim runner line). Violations don't just fail a gate — every workflow in the repo dies atstartup_failurewith zero jobs, including the gates that verify the lock. Diagnosis order for whole-repo startup-death days: checkactions.locksync first.uses:and never touched the lock (Dependabot structurally cannot). Result: exactly 6 violations, CodeQL/E2E/OikosBot at zero jobs, both lock gates red — and auto-merge completed anyway (lock gates are not in the required set perdependabot-automerge.yml: secret-scanner, codeql, hypatia-scan, openssf-compliance, build/test). A red lock gate does not stop merges in this estate.check-lock-sync.shdepends on gawk's 3-argmatch(); on non-gawk-awksystems the verifier itself misbehaves. (Slavia's session had to build gawk 4.1.0 from source to trust the verdict.) Worth documenting the dependency loudly or shipping a POSIX fallback.scripts/update-actions-lock.sh(byte-identicalstandards@a2ff696— the gates' remediation text pointed at a file consumers don't have) and movedgithub-actionstoopen-pull-requests-limit: 0(GitHub-endorsed security-only switch; template precedent: same pattern ships forcargo), revisit condition written in-config: restore routine bumps when a heal-on-Dependabot path exists → tracked at github-actions Dependabot updates desync actions.lock in consumers (startup deaths), and the actions.lock doc link in the lock header is dead rsr-template-repo#205 (also reports the deadgh.io/actions-lockfiledoc URL in the lock header — 404s).