Skip to content

Allowlist Preflight red on main: check-allowed-actions.sh compares owner/repo case-sensitively #1172

Description

@hyperpolymath

What

governance / Allowlist Preflight has been red on main since #1153 (5693b8b2, 2026-10-05). It is still red on 5a0891e9. Error: GAP swatinem/rust-cache@6323deb1… (add its owner/* or owner/repo@* pattern…).

#1153 lowercased Swatinem/rust-cache to swatinem/rust-cache in .github/workflows/rust-ci-reusable.yml (lines 191 and 239). allowed-actions.json:90 lists "Swatinem/rust-cache@*", and scripts/check-allowed-actions.sh compares the two strings exactly. GitHub owner and repo names are case-insensitive, so the checker is answering a different question from the platform.

Because governance / Debt ratchet needs this job, it is reported as skipped on main rather than run.

Acceptance criteria

  • check-allowed-actions.sh case-folds owner/repo on both sides before comparing (about lines 43 and 47 of its embedded script).
  • A fixture test plants a mixed-case uses: against a differently-cased allowlist pattern and passes, and an owner that is not allowlisted still fails (positive control).
  • governance / Allowlist Preflight is green on main.

🤖 Generated with Claude Code

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions