Skip to content

fix(ci,rulesets,triage): execute ULTRAPLAN-2026-09-29 Phase 0–2 fixes and verifications - #1064

Merged
hyperpolymath merged 2 commits into
mainfrom
arena/01a0ea9c-standards
Sep 29, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
arena/01a0ea9c-standards

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

Summary

Executes Phases 0–2 of ULTRAPLAN-2026-09-29.adoc, repairing the active CI regressions on main and landing the repo-local fixes and regression suites for the triaged P0/P1/P2 issues:

  1. hypatia-scan-reusable @2479cf7: scan produces no hypatia.sarif — "Path does not exist: hypatia.sarif" (caller-visible startup-shaped failure) #1050 (P0) & Hypatia reusable validation rejects clean [] and accepts multiple JSON documents #1054 (P1) — .github/workflows/hypatia-scan-reusable.yml, .github/workflows/governance-reusable.yml, scripts/tests/hypatia-blocking-gate-test.sh, scripts/tests/science-ci-security-test.rb:
    • Reproduced #1050 against runs 36504013478 and 36504013387: upstream hyperpolymath/hypatia broke mix escript.build at 4654d7a3d4 (hyperpolymath/hypatia#869, unescaped / inside ~r/.../ character class at lib/rules/pin_integrity.ex:56; last compilable commit is 9f2f62f5c9463c79b33a5ebf54372166ce56f349). When Build Hypatia scanner failed, Relativize finding paths, Filter SARIF through the baseline before upload, Upload SARIF to code scanning, and Upload findings artifacts still executed due to if: always(), causing Upload SARIF to code scanning to fail on a nonexistent hypatia.sarif (Path does not exist: hypatia.sarif).
    • Removed if: always() from those four post-validation steps (which already sit upstream of the blocking gates), added a targeted hold on 9f2f62f5c9463c79b33a5ebf54372166ce56f349 for the 4-commit hypatia#869 broken window (4654d7a3d4..4f9874e3f5) in both hypatia-scan-reusable.yml and governance-reusable.yml (automatically resuming HEAD once upstream hypatia advances), and restored single-document jq -e -s validation in Validate findings and count severities so a clean [] scan is a positive control while empty/whitespace/truncated/multi-document output fails closed (#1054).
  2. apply-branch-gates: a gate workflow no PR can trigger still derives a required context #1040 (P1) — scripts/apply-branch-gates.sh, config/rulesets/gates.json, scripts/tests/branch-gates-apply-test.sh:
    • Added yaml_has_pr_trigger / wf_triggers_on_pr so apply-branch-gates.sh verifies that each candidate gate workflow triggers on pull_request / pull_request_target targeting the default branch before deriving its job contexts into required_status_checks, reporting no_pr_trigger=[<wf>] (and UNGATED if zero contexts survive). Added Case 26 and Mutant J in scripts/tests/branch-gates-apply-test.sh (103/103 passing).
  3. Scorecard reconciler fails correct repos: gh actions-lock --verify is blind to job-level reusable refs (wrong in both directions) #1036 (P1) — scripts/reconcile-scorecard-actions-lock.rb, scripts/tests/reconcile-scorecard-actions-lock-test.rb:
    • Updated ScorecardActionsLock to handle both directions of gh-actions-lock v0.1.6's blindness to job-level reusable workflow uses: refs: (AC1) accepting stale findings whose dependency (owner/repo@ref) is referenced by a job-level reusable uses: in that workflow, and (AC2 / Arm D) failing closed when a workflow's job-level reusable uses: ref is absent from .github/workflows/actions.lock.
  4. O6 propagation: four contradictions between the ruling and the committed rulesets #1032 (P1, items 3 & 4) — scripts/apply-tag-ruleset-canon.sh, config/README.adoc, tests/test_tag_ruleset_canon.sh:
    • Enforced .source_type == "Repository" before repo-level PUT in scripts/apply-tag-ruleset-canon.sh (failing closed with REFUSED-NO-SOURCE-TYPE when .source_type is absent and reporting ORG-INHERITED for .source_type == "Organization"), updated config/README.adoc, and added Property 14 + mutant test in tests/test_tag_ruleset_canon.sh (31/31 passing).
  5. 48 open Dependabot PRs re-introduce the codeql-action v4.38.1 startup-killer, and the dependabot.yml ignore rule is being bypassed in 15 repos #1037 (AC5) — docs/DEPENDABOT-POLICY.adoc:
    • Documented the dependency-name: "github/codeql-action*" trailing-wildcard requirement for subpath actions and its revisit trigger, plus recorded the live 48-PR re-enumeration in ULTRAPLAN-2026-09-29.adoc.
  6. grammar artifacts: .k9 has no grammar or contract at all, and deed.abnf states both “sole normative” and “pending owner ruling” #1058 (Finding 2) — 1-formats/deed/spec/abnf/deed.abnf & .machine_readable/REGISTRY.a2ml:
    • Removed the orphaned ; pending owner ruling. Grammar below is unchanged. line and regenerated .machine_readable/REGISTRY.a2ml (scripts/tests/build-registry-test.sh 9/9 passing).
  7. Additional main CI & script repairs:
    • Updated .github/workflows/actions.lock for #1060 (haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d and tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd) and guarded scripts/update-actions-lock.sh against empty verifier stdout (scripts/tests/actions-lock-update-test.sh 12/12 passing).
    • Repaired the duplicate if [ ! -s "$cache" ] merge artifact in scripts/apply-protection-floor.sh (#1031; scripts/tests/protection-floor-test.sh 50/50 passing).
    • Cleared retired launcher-standard filename tokens from ULTRAPLAN-2026-09-24.adoc and ULTRAPLAN-2026-09-29.adoc (scripts/tests/check-launcher-standard-currency-test.sh 19/19 passing).
    • Added scripts/triage-2026-09-29-apply.sh and scripts/tests/triage-2026-09-29-apply-test.sh.

Issue Links (Verified Phase 0 & Phase 1/2 Resolutions)

Closes #1057
Closes #956
Closes #1013
Closes #1005
Closes #637
Closes #709
Closes #715
Closes #784
Closes #1050
Closes #1054
Closes #1040

… and verifications

- Fix #1050 and #1054 in hypatia-scan-reusable.yml and governance-reusable.yml:
  remove if: always() from post-validation SARIF/artifact steps, hold past
  the 4-commit hyperpolymath/hypatia#869 compile-break window on 9f2f62f5c9,
  and restore single-document jq -e -s validation so clean [] scans pass.
- Fix #1040 in scripts/apply-branch-gates.sh and config/rulesets/gates.json:
  verify candidate gate workflows trigger on pull_request targeting the
  default branch before deriving job contexts into required_status_checks.
- Fix #1036 in scripts/reconcile-scorecard-actions-lock.rb: accept false
  stale findings for job-level reusable workflow refs and fail closed on
  Arm-D refs absent from actions.lock.
- Fix #1032 (items 3-4) in scripts/apply-tag-ruleset-canon.sh,
  config/README.adoc, and tests/test_tag_ruleset_canon.sh.
- Document github/codeql-action* wildcard hold in docs/DEPENDABOT-POLICY.adoc (#1037 AC5).
- Remove orphaned pending-ruling comment in 1-formats/deed/spec/abnf/deed.abnf (#1058)
  and regenerate .machine_readable/REGISTRY.a2ml.
- Repair duplicate cache block in scripts/apply-protection-floor.sh (#1031),
  sync .github/workflows/actions.lock for #1060, guard empty verifier stdout
  in scripts/update-actions-lock.sh, and clear retired launcher-standard
  filename tokens from ULTRAPLAN docs.
- Add scripts/triage-2026-09-29-apply.sh + regression test and record Phase 0-2
  live verification results in ULTRAPLAN-2026-09-29.adoc.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 97387fca-44ed-466d-88cc-9e40b62afd63

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit bd9313a into main Sep 29, 2026
3 of 5 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0ea9c-standards branch September 29, 2026 09:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment