Skip to content

.github/labeler.yml has a guard that every label key must exist; .github/dependabot.yml has none — which is why #1743 survived a month unfalsifiable #1763

Description

@os-bill

Blocked-by: #1874

⏸️ Moved pm:queue → pm:blocked by the repo:hotcrm seat (#1353), R60, 2026-09-10T08:4xZ. Waits on the test/** fence ruling in #1874; ⛔ nothing about the finding has changed.

⚠️ This card is the odd one of the five, and the seat's recommendation on #1874 is that it should be CLOSED whichever letter is chosen — it is the only one asking for a new assertion rather than the correction of an existing one, and this lane has refused new local guards four times on the record (#1262 · #1665 · #1741 · #1782).

⭐ In fairness to the card, it anticipates exactly that objection and answers it on two grounds a reviewer should weigh rather than wave away: that this extends an invariant labeler.yml already declares and test/labeler-config.test.ts already enforces, to the one sibling file that escaped it — a coverage gap in an existing guard rather than a new verification surface, which is the distinction AGENTS.md Scope rule 3 turns on — and that the relation checked is mechanical (two in-repo lists of identifiers), not the prose-to-behaviour relation for which guards were refused in #1646. The seat does not find that argument frivolous; it finds it a call above this seat's floor. ⇒ it goes to the maintainer with the other four rather than being closed on seat judgement.


Filed by the repo:hotcrm seat from a finding handed back by #1743's dev, which measured it and correctly declined to fix it in place (adding a verification surface fails the bounded in-place-fix test). #1743 fixed the two instances; this is the class.

The asymmetry

Two files in .github/ reference this repository's label names. Exactly one of them is guarded.

file references labels guarded?
.github/labeler.yml yes ✅ its header pins the invariant "Every label key must already exist in the repository", enforced by test/labeler-config.test.ts
.github/dependabot.yml yes (labels: on both update blocks) ❌ nothing reads it

.github/labels.yml is described in-repo as "the single source of truth for this repository's labels", and it governs labeler.yml by test. dependabot.yml was simply never brought under the same rule.

Why the gap had teeth — this is the part worth keeping

#1743's two bad names (automated, github-actions) sat there from 2026-08-10 to 2026-09-08. The reason a month passed is not that nobody looked; it is that the defect is unfalsifiable from Dependabot's own error message.

Dependabot reports that a label could not be applied. It never says which. So:

  • deleting only the name a human noticed leaves the notice repeating verbatim, with nothing new to read;
  • there is no way to tell from the notice whether the fix worked, worked partially, or did nothing;
  • ⇒ establishing the truth requires checking every referenced name against the actual label set. Reading the notice more carefully cannot get you there, ever.

⭐ That is exactly the shape a guard is for: a defect whose feedback channel cannot distinguish "fixed" from "half-fixed". labeler.yml already has that guard. dependabot.yml had a month of silent failure instead.

⚠️ Fenced — read before dispatching

⛔ test/** is epic #1579's declared territory (its census covers all 169 test/ files). The obvious shape of this fix — extend test/labeler-config.test.ts, or add a sibling test — lands squarely inside that fence. ⇒ This card is NOT dispatchable while the fence holds, and it is filed now so the finding is not lost, not because it is ready.

Re-price it when the epic releases test/**. If a maintainer ruling puts this one file in scope earlier, that ruling outranks the fence — but it must name this card, not merely the file (the distinction #1530/#1755 already turned on).

⚠️ Do not widen it into a gate farm

AGENTS.md Scope rule 3 sends drift-class and validation-class gaps upstream to the platform, and this lane has refused local-gate requests twice (#1262, and twice on #1573's surface). The argument that this one is different has to be made explicitly, and it rests on two things a reviewer should check rather than take on faith:

  1. The precedent is already in this repo. This is not inventing a gate; it is extending an invariant labeler.yml already declares and test/labeler-config.test.ts already enforces, to the one sibling file that references labels and escaped it. ⭐ That makes it a coverage gap in an existing guard, not a new verification surface — which is the distinction Scope rule 3 turns on.
  2. The checked relation is mechanical, not prose. It compares two in-repo lists of identifiers. ⛔ That is the opposite of the content/docs case where a guard was refused because free prose has no mechanical relation to the rows it narrates (Acme's seeded account description states a renewal horizon that matches no seeded record #1646), and it is not the vacuous-pin failure of The #802 term guard's pack rule scans src/translations/zh-CN.ts, which the #1311 split turned into a 77-line barrel — it re-passed the #1529 defect verbatim in an ablation #1755 either.

If a reviewer concludes it is still a gate farm, ⛔ the correct outcome is to close this card, not to fix it halfway.

Scope, if it is ever dispatched

Already fixed, and not to be redone

#1743 / PR #1761 removed both bad names. Both blocks now request only dependencies and skip-changeset, which exist. ⛔ This card adds no behaviour change to dependabot.yml — it is only about whether the next bad name is caught.

Refs: #1743 · PR #1761 · #1501 · #1755 (the vacuous-guard failure mode) · #1646 (why prose guards were refused)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ci/cdCI plumbing and the verification pipeline

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions