现象
.github/workflows/gate-disposition.yml 仍是旧五输入版本,缺 disposition、counterevidence_json、tracking_issue 三项声明与转发。这是 zlxlabs/gate#275 记录的调用通道根因之一:模板侧已发布八输入,但存量业务 caller 没有消费。
- 来源:
zlxlabs/VideoTranscriptAPI 默认分支 main @ ff92a175243dde36143da867a95e2fdad384e16c
- 文件 blob:
2d9129ea6438d84aa1222531521d0cd3ae668064
- 调用目标:
zlxlabs/gate/.github/workflows/gate-v2-disposition.yml@v2(正确,保持 @v2,不要改成逐仓 40-hex pin)
已发布模板(八输入):https://github.com/zlxlabs/gate/blob/v2/templates/caller-gate-disposition.yml
两处真实差异
1. on.workflow_dispatch.inputs 缺三项声明
现状只有五项:
pr_number: { description: "pull request number", required: true, type: string }
primary_run_id: { description: "canonical primary run id", required: true, type: string }
primary_run_attempt: { description: "canonical primary run attempt", required: true, type: string }
finding_id: { description: "exact current-audit finding id", required: true, type: string }
reason: { description: "reason for the false-positive disposition", required: true, type: string }
应补三项可选(required: false)声明:
disposition: { description: "false-positive or deferred", required: false, type: string }
counterevidence_json: { description: "counterevidence JSON for false-positive", required: false, type: string }
tracking_issue: { description: "same-repository issue reference for deferred", required: false, type: string }
2. 调用 job 的 with 块缺三项转发
现状只转发五项;应补:
disposition: ${{ inputs.disposition }}
counterevidence_json: ${{ inputs.counterevidence_json }}
tracking_issue: ${{ inputs.tracking_issue }}
边界
- 五个基本输入保持
required: true,语义不变。
- 保持
@v2,不要引入逐仓 SHA pin。
- 不需要复制 secret,现有
secrets: inherit 保持不变。
- 不改
permissions,不改谁有资格做 disposition 处置。
- 上游 reusable workflow 的
gate_ref 是 deprecated/ignored 的兼容输入,不属于本契约,不要转发它。
完成判据
- 迁移后的文件与已发布八输入模板逐字段一致(声明 +
with 转发)。
- 一次真实的
workflow_dispatch 调用落到 gate-v2-disposition.yml@v2 并产生有效回执,而不是只改文件就算完。
- 空
disposition + 有效 counterevidence_json 应仍按 false-positive 处理;无效或缺失反证仍被权威验证拒绝;deferred 最终仍因 deferred_not_allowed_for_tier 被拒——这些语义在迁移后不得改变。
本 issue 只是交接证据,不代表已授权实施;是否在本仓改代码由持有方自行决定。gate-hub 侧不会代改本仓代码或开 PR。
现象
.github/workflows/gate-disposition.yml仍是旧五输入版本,缺disposition、counterevidence_json、tracking_issue三项声明与转发。这是zlxlabs/gate#275记录的调用通道根因之一:模板侧已发布八输入,但存量业务 caller 没有消费。zlxlabs/VideoTranscriptAPI默认分支main@ff92a175243dde36143da867a95e2fdad384e16c2d9129ea6438d84aa1222531521d0cd3ae668064zlxlabs/gate/.github/workflows/gate-v2-disposition.yml@v2(正确,保持@v2,不要改成逐仓 40-hex pin)已发布模板(八输入):https://github.com/zlxlabs/gate/blob/v2/templates/caller-gate-disposition.yml
两处真实差异
1.
on.workflow_dispatch.inputs缺三项声明现状只有五项:
应补三项可选(
required: false)声明:2. 调用 job 的
with块缺三项转发现状只转发五项;应补:
边界
required: true,语义不变。@v2,不要引入逐仓 SHA pin。secrets: inherit保持不变。permissions,不改谁有资格做 disposition 处置。gate_ref是 deprecated/ignored 的兼容输入,不属于本契约,不要转发它。完成判据
with转发)。workflow_dispatch调用落到gate-v2-disposition.yml@v2并产生有效回执,而不是只改文件就算完。disposition+ 有效counterevidence_json应仍按false-positive处理;无效或缺失反证仍被权威验证拒绝;deferred最终仍因deferred_not_allowed_for_tier被拒——这些语义在迁移后不得改变。