fix: AGENTIC licence line + a2ml-validate-action repin - #69
Conversation
…, #669) 1. The AGENTIC.a2ml agent-constraint line "Never use AGPL license (...)" contradicts LICENCE-POLICY.adoc Rules 3 (co-developed), 4 (network services) and 5 (games), which MANDATE AGPL-3.0-or-later - and 144 copies named the retired PMPL-1.0-or-later. Replaced with a pointer to the policy plus the A2 no-automated-licence-edits rule, hardcoding no licence so it cannot go stale again. Same wording as the template fix in rsr-template-repo#45; owner-ruled sweep (2026-08-27). 2. Any workflow pinning hyperpolymath/a2ml-validate-action at 59145c7d or e558e79200 is repinned to 6ac6416f. Those two SHAs never existed: the repo itself was only created 2026-08-28 and populated by subtree split from a2ml/actions/validate (286 files, history preserved). The old pins could never resolve and made lockfile generation impossible. Direct push per owner ruling of 2026-08-28. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Up to standards ✅🟢 Issues
|
|
Caution Review failedThe pull request is closed. ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe agent policy replaces the AGPL prohibition with rules for relicensing, licence sweeps, policy consultation, default licences, and defined exceptions. ChangesLicence policy
Estimated code review effort: 1 (Trivial) | ~2 minutes Poem
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull Request Overview
While Codacy analysis indicates the changes are up to standards, there is a major gap in the implementation: the repinning of the 'a2ml-validate-action' mentioned in the PR title is entirely absent from the file changes. This missing acceptance criterion prevents the PR from fulfilling its stated purpose. Additionally, the agentic rules file contains inconsistent paths when referencing the licensing policy document.
About this PR
- The PR title and description indicate a repin of the 'a2ml-validate-action', but the current diff does not contain any updates to GitHub Actions or pin references. Please include the missing changes or update the PR scope.
1 comment outside of the diff
[REDACTED:HIGH_ENTROPY]
line 25⚪ LOW RISK
Nitpick: The reference to the policy document is inconsistent. Use the full path 'standards/LICENCE-POLICY.adoc' to match the reference in the following line.# sweep (standards/LICENCE-POLICY.adoc A2). New files get correct SPDX from birth.
Test suggestions
- Verify the agentic rules file correctly references the licensing policy and individual rule scopes (MPL, CC, AGPL, PMPL).
- Verify the a2ml-validate-action SHA is updated to the correct HEAD reference.
Prompt proposal for missing tests
Consider implementing these tests if applicable:
1. Verify the a2ml-validate-action SHA is updated to the correct HEAD reference.
TIP Improve review quality by adding custom instructions
TIP How was this review? Give us feedback
🔍 Hypatia Security ScanFindings: 62 issues detected
View findings[
{
"reason": "No test directory or test files found",
"type": "no_tests",
"file": "/home/runner/work/docmatrix/docmatrix",
"action": "flag",
"rule_module": "honest_completion",
"severity": "high",
"deduction": 20
},
{
"reason": "Issue in label-triage.yml",
"type": "missing_timeout_minutes",
"file": "label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in labels.yml",
"type": "missing_timeout_minutes",
"file": "labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in push-email-notify.yml",
"type": "missing_timeout_minutes",
"file": "push-email-notify.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Issue in instant-sync.yml",
"type": "secret_action_without_presence_gate",
"file": "instant-sync.yml",
"action": "peter-evans/repository-dispatch",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "unwrap() without prior check -- DoS via panic (2 occurrences, CWE-754)",
"type": "unwrap_without_check",
"file": "/home/runner/work/docmatrix/docmatrix/crates/formatrix-core/src/formats/djot.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "high"
},
{
"reason": "from_raw constructs types from raw pointers without safety checks (2 occurrences, CWE-676)",
"type": "from_raw",
"file": "/home/runner/work/docmatrix/docmatrix/crates/formatrix-core/src/ffi.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "high"
},
{
"reason": "as_ptr exposes raw pointer that may dangle or alias unsafely (8 occurrences, CWE-676)",
"type": "as_ptr",
"file": "/home/runner/work/docmatrix/docmatrix/crates/formatrix-core/src/ffi.rs",
"action": "flag",
"rule_module": "code_safety",
"severity": "medium"
},
{
"reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 0 day(s) old",
"type": "CSA001",
"file": "labels.yml",
"action": "review",
"rule_module": "code_scanning_alerts",
"severity": "medium"
},
{
"reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 0 day(s) old",
"type": "CSA001",
"file": "label-triage.yml",
"action": "review",
"rule_module": "code_scanning_alerts",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
Ruleset refused a direct push, so this lands by PR. Two mechanical fixes, owner-ruled:
Never use AGPL license (…)contradictsLICENCE-POLICY.adocRules 3/4/5 (which mandate AGPL for their scopes). Replaced with the policy pointer used inrsr-template-repo#45. Seestandards#646.a2ml-validate-actionrepin — the previously-pinned SHAs never existed; the repo was only created 2026-08-28 (split froma2ml/actions/validate, history preserved). Repinned to its real HEAD. Seestandards#669.🤖 Generated with Claude Code