Skip to content

feat(yaml): KYAML batch 1 + ratchet; withdraw blindness claim - #1124

Merged
hyperpolymath merged 1 commit into
mainfrom
feat/kyaml-nonworkflow-batch1
Oct 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
feat/kyaml-nonworkflow-batch1

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Part of #1024 (YAML-POLICY §5 step 5). Owner ruling D280 (#787).

What

  • Converts _shared/container/.gatekeeper.yaml to KYAML using scripts/kyaml-format.sh, which runs yq -p yaml -o kyaml '.' verbatim.
    • tools/yaml-comment-proof: 64/64 comments preserved, idempotent, data-equal. Both control mutants were killed.
  • Ratchet: Self Test gains a step, Converted YAML stays KYAML, that runs kyaml-format.sh --check over every converted file. Positive control: the block-style original fails, rc=1.
    • It adds no new uses:, so actions.lock is untouched.
    • The runner's yq already passes the kyaml-format suite (17/17 on main 71bb615).
  • Correction: withdraws YAML-POLICY §5 step 3's claim that "gh actions-lock is blind to KYAML". I re-tested with the same ref planted in each syntax, and the two syntaxes gave identical verdicts:
planted ref block KYAML
tag actions/setup-node@v4 rc=1 rc=1
bare SHA not in lock rc=0 rc=0

Fix mode also left a KYAML workflow byte-identical and kept its lock entries. The gap that remains has nothing to do with syntax and is tracked in #1025.

Scope (denominator)

This repo tracks 187 *.yml/*.yaml files:

🤖 Generated with Claude Code

https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS

YAML-POLICY §5 step 5 (#1024), standards-owned non-workflow YAML:
- convert _shared/container/.gatekeeper.yaml with scripts/kyaml-format.sh
  (comment proof: 64/64 preserved, idempotent, data-equal)
- Self Test gains a "Converted YAML stays KYAML" ratchet step
  (planted control: the block original goes red, rc=1)
- §5 step 3: withdraw "gh actions-lock is blind to KYAML"; a matched
  control showed identical verdicts in both syntaxes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f381d2b5-eb38-4a25-a9b0-cf7799bffd78

📥 Commits

Reviewing files that changed from the base of the PR and between 71bb615 and f027fba.

📒 Files selected for processing (3)
  • .github/workflows/self-test.yml
  • 3-practice/YAML-POLICY.adoc
  • _shared/container/.gatekeeper.yaml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 215df8e into main Oct 1, 2026
49 checks passed
@hyperpolymath
hyperpolymath deleted the feat/kyaml-nonworkflow-batch1 branch October 1, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant