fix: AGENTIC licence line + a2ml-validate-action repin - #50
Conversation
…, #669) 1. The AGENTIC.a2ml agent-constraint line "Never use AGPL license (...)" contradicts LICENCE-POLICY.adoc Rules 3 (co-developed), 4 (network services) and 5 (games), which MANDATE AGPL-3.0-or-later - and 144 copies named the retired PMPL-1.0-or-later. Replaced with a pointer to the policy plus the A2 no-automated-licence-edits rule, hardcoding no licence so it cannot go stale again. Same wording as the template fix in rsr-template-repo#45; owner-ruled sweep (2026-08-27). 2. Any workflow pinning hyperpolymath/a2ml-validate-action at 59145c7d or e558e79200 is repinned to 6ac6416f. Those two SHAs never existed: the repo itself was only created 2026-08-28 and populated by subtree split from a2ml/actions/validate (286 files, history preserved). The old pins could never resolve and made lockfile generation impossible. Direct push per owner ruling of 2026-08-28. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Up to standards ✅🟢 Issues
|
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe agent constraints now require consultation of the licence policy. They prohibit relicensing existing files, automated licence sweeps, and licence assumptions. They also specify default licences and policy rules. ChangesLicence guidance
Estimated code review effort: 1 (Trivial) | ~5 minutes Poem
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull Request Overview
While the update to the AI agent's licensing instructions correctly aligns with the official policy, the PR fails to deliver on its second primary objective: repinning the 'a2ml-validate-action'. This omission contradicts the PR's title and description. Although Codacy indicates the project is technically up to standards, this functional gap prevents the PR from meeting its acceptance criteria. Implementation of the action repin is required before this can be considered complete.
About this PR
- The repin of 'a2ml-validate-action' described in the PR title and description is entirely missing from the provided code changes. The current diff only addresses the license instructions, leaving a primary objective of this PR unfulfilled.
Test suggestions
- Verify that the agent instructions accurately distinguish between the default license (MPL) and mandated AGPL cases (Rules 3, 4, 5).
- Verify the 'a2ml-validate-action' is updated to a valid SHA in the relevant GitHub Workflow or action configuration file.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify that the agent instructions accurately distinguish between the default license (MPL) and mandated AGPL cases (Rules 3, 4, 5).
2. Verify the 'a2ml-validate-action' is updated to a valid SHA in the relevant GitHub Workflow or action configuration file.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
🔍 Hypatia Security ScanFindings: 76 issues detected
View findings[
{
"reason": "Issue in boj-build.yml",
"type": "missing_timeout_minutes",
"file": "boj-build.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in casket-pages.yml",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in casket-pages.yml",
"type": "missing_timeout_minutes",
"file": "casket-pages.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in codeql.yml",
"type": "missing_timeout_minutes",
"file": "codeql.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dependabot-automerge.yml",
"type": "missing_timeout_minutes",
"file": "dependabot-automerge.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dogfood-gate.yml",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dogfood-gate.yml",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dogfood-gate.yml",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dogfood-gate.yml",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in dogfood-gate.yml",
"type": "missing_timeout_minutes",
"file": "dogfood-gate.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |



Ruleset refused a direct push, so this lands by PR. Two mechanical fixes, owner-ruled:
Never use AGPL license (…)contradictsLICENCE-POLICY.adocRules 3/4/5 (which mandate AGPL for their scopes). Replaced with the policy pointer used inrsr-template-repo#45. Seestandards#646.a2ml-validate-actionrepin — the previously-pinned SHAs never existed; the repo was only created 2026-08-28 (split froma2ml/actions/validate, history preserved). Repinned to its real HEAD. Seestandards#669.🤖 Generated with Claude Code