Repository navigation
fix(lock): restore Asana/push-signed-commits entry dropped by #1160 - #1162
Conversation
The #1160 relock regenerated actions.lock from .github/workflows/ only and dropped the dependency used by the composite action .github/actions/signed-push/action.yml:42. `uses ⊆ actions.lock` has been red on main since ce92a8c ("not in actions.lock: Asana/push-signed-commits@d615ca88"). This restores the entry byte for byte as it stood on 5751b97 (ref v1.3, same commit and ids, same transitive uses). Verified: .githooks/validate-actions-lock.sh rc=1 before (1 ref missing), rc=0 after (26/26); scripts/check-lock-sync.sh rc=0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37473363733 K9 normative contract typecheckK9 contract self-testK9 conformance fixtures |
## Summary The R5 (route-to-canonical) step in `.github/workflows/governance-reusable.yml` runs under `bash -e`. `out=$(grep -nE …)` returns 1 when a pattern does not match, and that killed the step before `rc` was read. So the first clean file ended the scan with no output, and every later file went unscanned. This PR keeps the status with `|| rc=$?`. **Stacked on #1162** (the asana lock restore). Without #1162, the pre-commit `uses ⊆ actions.lock` hook refuses any commit on main. Once #1162 merges, this branch will be updated, and the diff will be the R5 commit only. ## Type of change - [x] 🐛 Bug fix: the R5 scan aborts silently. - [ ] ✨ New feature: not applicable. - [ ] 💥 Breaking change: no. Callers that passed before still pass. Callers with R5 hits after a clean file now see those hits, which is the intended behaviour. - [x] 🕳️ Soundness fix: a checker false negative. Hits after the first clean file were never reported. - [ ] 📖 Documentation: not applicable. - [ ] 🧹 Refactor: not applicable. - [ ] ⚡ Performance: not applicable. - [x] 🔧 Build / CI / tooling ## 📌 New pins - Head SHA: **824b98ab5bdc1a68c7c283a70aa61dc18243cd54** - None. No `uses:` or lock entry is changed by the R5 commit. The base commit e4641ca (#1162) restores the existing **Asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897** entry. ## How has this been verified? - `bash tests/test_governance_r5_bash_e.sh`: **RED 3/4** before the fix, because the no-match case exited early. **GREEN 4/4** after it. - `.githooks/docstring-scan.sh --staged`: 3/3 functions documented, coverage 100%. - The pre-commit hook suite passed: gitleaks, lint, SPDX, SHA-pinning and lockfile coverage. ## Checklist - [x] My commits are **signed**. - [x] I ran the project's own checks locally and they pass (as above). - [x] The new file `tests/test_governance_r5_bash_e.sh` carries `SPDX-License-Identifier: MPL-2.0`. - [ ] Docs are updated: not applicable. No documentation claims R5 behaviour. - [x] I have not introduced a soundness hole; this PR closes one. ## Notes for reviewers Every caller pinned to a governance-reusable SHA before this fix keeps the silent-exit behaviour until it repins. echidna's six standards callers will be repinned in a follow-up PR once this lands. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37473959921 K9 normative contract typecheckK9 contract self-testK9 conformance fixtures |
|
Add Carrot credits or activate Agent usage billing to use Autopilot |
|
|
Note for the record: this PR's only commit (e4641ca, restoring the 🤖 Generated with Claude Code |



Summary
Restores the
Asana/push-signed-commitsentry that the #1160 relock dropped from.github/workflows/actions.lock. The composite action.github/actions/signed-push/action.yml:42still uses it. Since ce92a8c,uses ⊆ actions.lockon main has failed withnot in actions.lock: Asana/push-signed-commits@d615ca88…. This is the defect raised on #1160 in issuecomment-6017428696, which was posted the minute it merged.Main has no linked issue for it; the red check on main is the record.
Type of change
uses ⊆ actions.lock.📌 New pins
actions/setup-python@v2). This is a restored entry, byte-identical to the one on 5751b97; it adds no new pin. No workflow YAML is changed.How has this been verified?
bash .githooks/validate-actions-lock.shon ce92a8c: rc=1,1 ref(s) missing from the lockfile(Asana). With this change: rc=0,26 SHA-pinned ref(s) found among 26 lockfile keys../scripts/check-lock-sync.shgives rc=0: everyuses:is locked, and every entry is referenced.git diff 5751b97e -- .github/workflows/actions.lockshows no Asana lines, so the restored block matches the pre-fix(lock): relock actions.lock after the rust-toolchain bump (#1157) #1160 one exactly.Checklist
git log --format=%G?givesG.Notes for reviewers
Main's other reds on ce92a8c are unrelated to this lock entry and are not touched here: Repo self-tests, Registry + topology, K9-SVC, Haskell pipeline, Hypatia scan/baseline, Allowlist Preflight, and SonarCloud.
gh actions-lock --no-fix --verifyalso reports alocal-actionerror forsigned-push-smoke.yml(uses: ./…). That error is pre-existing on 5751b97 and is a tool opinion, not a GitHub validation. It is left alone.🤖 Generated with Claude Code
https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7