You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
.github/labeler.yml has a guard that every label key must exist; .github/dependabot.yml has none — which is why #1743 survived a month unfalsifiable #1763
⏸️ Moved pm:queue → pm:blocked by the repo:hotcrm seat (#1353), R60, 2026-09-10T08:4xZ. Waits on the test/** fence ruling in #1874; ⛔ nothing about the finding has changed.
⚠️This card is the odd one of the five, and the seat's recommendation on #1874 is that it should be CLOSED whichever letter is chosen — it is the only one asking for a new assertion rather than the correction of an existing one, and this lane has refused new local guards four times on the record (#1262 · #1665 · #1741 · #1782).
⭐ In fairness to the card, it anticipates exactly that objection and answers it on two grounds a reviewer should weigh rather than wave away: that this extends an invariant labeler.yml already declares and test/labeler-config.test.ts already enforces, to the one sibling file that escaped it — a coverage gap in an existing guard rather than a new verification surface, which is the distinction AGENTS.md Scope rule 3 turns on — and that the relation checked is mechanical (two in-repo lists of identifiers), not the prose-to-behaviour relation for which guards were refused in #1646. The seat does not find that argument frivolous; it finds it a call above this seat's floor. ⇒ it goes to the maintainer with the other four rather than being closed on seat judgement.
Filed by the repo:hotcrm seat from a finding handed back by #1743's dev, which measured it and correctly declined to fix it in place (adding a verification surface fails the bounded in-place-fix test). #1743 fixed the two instances; this is the class.
The asymmetry
Two files in .github/ reference this repository's label names. Exactly one of them is guarded.
file
references labels
guarded?
.github/labeler.yml
yes
✅ its header pins the invariant "Every label key must already exist in the repository", enforced by test/labeler-config.test.ts
.github/dependabot.yml
yes (labels: on both update blocks)
❌ nothing reads it
.github/labels.yml is described in-repo as "the single source of truth for this repository's labels", and it governs labeler.yml by test. dependabot.yml was simply never brought under the same rule.
Why the gap had teeth — this is the part worth keeping
#1743's two bad names (automated, github-actions) sat there from 2026-08-10 to 2026-09-08. The reason a month passed is not that nobody looked; it is that the defect is unfalsifiable from Dependabot's own error message.
Dependabot reports that a label could not be applied. It never says which. So:
deleting only the name a human noticed leaves the notice repeating verbatim, with nothing new to read;
there is no way to tell from the notice whether the fix worked, worked partially, or did nothing;
⇒ establishing the truth requires checking every referenced name against the actual label set. Reading the notice more carefully cannot get you there, ever.
⭐ That is exactly the shape a guard is for: a defect whose feedback channel cannot distinguish "fixed" from "half-fixed". labeler.yml already has that guard. dependabot.yml had a month of silent failure instead.
⚠️ Fenced — read before dispatching
⛔ test/** is epic #1579's declared territory (its census covers all 169 test/ files). The obvious shape of this fix — extend test/labeler-config.test.ts, or add a sibling test — lands squarely inside that fence. ⇒ This card is NOT dispatchable while the fence holds, and it is filed now so the finding is not lost, not because it is ready.
Re-price it when the epic releases test/**. If a maintainer ruling puts this one file in scope earlier, that ruling outranks the fence — but it must name this card, not merely the file (the distinction #1530/#1755 already turned on).
⚠️ Do not widen it into a gate farm
AGENTS.md Scope rule 3 sends drift-class and validation-class gaps upstream to the platform, and this lane has refused local-gate requests twice (#1262, and twice on #1573's surface). The argument that this one is different has to be made explicitly, and it rests on two things a reviewer should check rather than take on faith:
The precedent is already in this repo. This is not inventing a gate; it is extending an invariant labeler.yml already declares and test/labeler-config.test.ts already enforces, to the one sibling file that references labels and escaped it. ⭐ That makes it a coverage gap in an existing guard, not a new verification surface — which is the distinction Scope rule 3 turns on.
#1743 / PR #1761 removed both bad names. Both blocks now request only dependencies and skip-changeset, which exist. ⛔ This card adds no behaviour change to dependabot.yml — it is only about whether the next bad name is caught.
Refs: #1743 · PR #1761 · #1501 · #1755 (the vacuous-guard failure mode) · #1646 (why prose guards were refused)
Blocked-by: #1874
⏸️ Moved
pm:queue→pm:blockedby therepo:hotcrmseat (#1353), R60, 2026-09-10T08:4xZ. Waits on thetest/**fence ruling in #1874; ⛔ nothing about the finding has changed.⭐ In fairness to the card, it anticipates exactly that objection and answers it on two grounds a reviewer should weigh rather than wave away: that this extends an invariant
labeler.ymlalready declares andtest/labeler-config.test.tsalready enforces, to the one sibling file that escaped it — a coverage gap in an existing guard rather than a new verification surface, which is the distinctionAGENTS.mdScope rule 3 turns on — and that the relation checked is mechanical (two in-repo lists of identifiers), not the prose-to-behaviour relation for which guards were refused in #1646. The seat does not find that argument frivolous; it finds it a call above this seat's floor. ⇒ it goes to the maintainer with the other four rather than being closed on seat judgement.Filed by the
repo:hotcrmseat from a finding handed back by #1743's dev, which measured it and correctly declined to fix it in place (adding a verification surface fails the bounded in-place-fix test). #1743 fixed the two instances; this is the class.The asymmetry
Two files in
.github/reference this repository's label names. Exactly one of them is guarded..github/labeler.ymltest/labeler-config.test.ts.github/dependabot.ymllabels:on both update blocks).github/labels.ymlis described in-repo as "the single source of truth for this repository's labels", and it governslabeler.ymlby test.dependabot.ymlwas simply never brought under the same rule.Why the gap had teeth — this is the part worth keeping
#1743's two bad names (
automated,github-actions) sat there from 2026-08-10 to 2026-09-08. The reason a month passed is not that nobody looked; it is that the defect is unfalsifiable from Dependabot's own error message.Dependabot reports that a label could not be applied. It never says which. So:
⭐ That is exactly the shape a guard is for: a defect whose feedback channel cannot distinguish "fixed" from "half-fixed".
labeler.ymlalready has that guard.dependabot.ymlhad a month of silent failure instead.⛔
test/**is epic #1579's declared territory (its census covers all 169test/files). The obvious shape of this fix — extendtest/labeler-config.test.ts, or add a sibling test — lands squarely inside that fence. ⇒ This card is NOT dispatchable while the fence holds, and it is filed now so the finding is not lost, not because it is ready.Re-price it when the epic releases
test/**. If a maintainer ruling puts this one file in scope earlier, that ruling outranks the fence — but it must name this card, not merely the file (the distinction #1530/#1755 already turned on).AGENTS.mdScope rule 3 sends drift-class and validation-class gaps upstream to the platform, and this lane has refused local-gate requests twice (#1262, and twice on #1573's surface). The argument that this one is different has to be made explicitly, and it rests on two things a reviewer should check rather than take on faith:labeler.ymlalready declares andtest/labeler-config.test.tsalready enforces, to the one sibling file that references labels and escaped it. ⭐ That makes it a coverage gap in an existing guard, not a new verification surface — which is the distinction Scope rule 3 turns on.content/docscase where a guard was refused because free prose has no mechanical relation to the rows it narrates (Acme's seeded account description states a renewal horizon that matches no seeded record #1646), and it is not the vacuous-pin failure of The #802 term guard's pack rule scanssrc/translations/zh-CN.ts, which the #1311 split turned into a 77-line barrel — it re-passed the #1529 defect verbatim in an ablation #1755 either.If a reviewer concludes it is still a gate farm, ⛔ the correct outcome is to close this card, not to fix it halfway.
Scope, if it is ever dispatched
labels:in.github/dependabot.yml(both update blocks) is declared in.github/labels.yml.src/translations/zh-CN.ts, which the #1311 split turned into a 77-line barrel — it re-passed the #1529 defect verbatim in an ablation #1755, wheretest/docs-object-term-consistency.test.tspinssrc/translations/zh-CN.ts, a 77-line barrel the The 70% advisory band's first real output:es-ES.ts(75.3%) andja-JP.ts(73.4%) are the only two files it names, and a third sits 224 bytes below it #1311 split left carrying zero occurrences. ⛔ A guard added here without a control is worse than the gap it closes, because it also reports success.skip-deleteis load-bearing, not belt-and-braces #1501 (the manifest-vs-live-usage discrepancy, environment-blocked). This card comparesdependabot.ymlagainst the manifest, which is a read of two files in the repo and needs no label enumeration.Already fixed, and not to be redone
#1743 / PR #1761 removed both bad names. Both blocks now request only
dependenciesandskip-changeset, which exist. ⛔ This card adds no behaviour change todependabot.yml— it is only about whether the next bad name is caught.Refs: #1743 · PR #1761 · #1501 · #1755 (the vacuous-guard failure mode) · #1646 (why prose guards were refused)