Skip to content

fix: AGENTIC licence line + a2ml-validate-action repin - #88

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/agentic-licence-and-validate-pin
Aug 28, 2026
Merged

fix: AGENTIC licence line + a2ml-validate-action repin#88
hyperpolymath merged 1 commit into
mainfrom
fix/agentic-licence-and-validate-pin

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Ruleset refused a direct push, so this lands by PR. Two mechanical fixes, owner-ruled:

  1. AGENTIC licence lineNever use AGPL license (…) contradicts LICENCE-POLICY.adoc Rules 3/4/5 (which mandate AGPL for their scopes). Replaced with the policy pointer used in rsr-template-repo#45. See standards#646.
  2. a2ml-validate-action repin — the previously-pinned SHAs never existed; the repo was only created 2026-08-28 (split from a2ml/actions/validate, history preserved). Repinned to its real HEAD. See standards#669.

🤖 Generated with Claude Code

…, #669)

1. The AGENTIC.a2ml agent-constraint line "Never use AGPL license (...)"
   contradicts LICENCE-POLICY.adoc Rules 3 (co-developed), 4 (network
   services) and 5 (games), which MANDATE AGPL-3.0-or-later - and 144
   copies named the retired PMPL-1.0-or-later. Replaced with a pointer to
   the policy plus the A2 no-automated-licence-edits rule, hardcoding no
   licence so it cannot go stale again. Same wording as the template fix
   in rsr-template-repo#45; owner-ruled sweep (2026-08-27).

2. Any workflow pinning hyperpolymath/a2ml-validate-action at 59145c7d or
   e558e79200 is repinned to 6ac6416f. Those two SHAs never existed: the
   repo itself was only created 2026-08-28 and populated by subtree split
   from a2ml/actions/validate (286 files, history preserved). The old
   pins could never resolve and made lockfile generation impossible.

Direct push per owner ruling of 2026-08-28.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit da78514 into main Aug 28, 2026
@hyperpolymath
hyperpolymath deleted the fix/agentic-licence-and-validate-pin branch August 28, 2026 05:18
@sonarqubecloud

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 66dde7d1-02ee-482f-be20-a0497bf8545f

📥 Commits

Reviewing files that changed from the base of the PR and between deb5e21 and fbe73c3.

📒 Files selected for processing (1)
  • .machine_readable/descriptiles/AGENTIC.a2ml

📝 Walkthrough

Summary by CodeRabbit

  • Documentation
    • Expanded licensing guidance for project contributors and automated agents.
    • Clarified that existing files must not be relicensed and automated licence sweeps should not be run.
    • Documented default licensing options for code and prose, with additional rules for co-developed work, network-deployed services, and games.
    • Added guidance for maintaining a separate register for PMPL-licensed material.

Walkthrough

The agent constraints now provide expanded licence policy guidance. They define prohibited actions, default licences, AGPL conditions, and the PMPL register requirement.

Changes

Licence policy guidance

Layer / File(s) Summary
Agent licence constraints
.machine_readable/descriptiles/AGENTIC.a2ml
The constraints prohibit re-licensing existing files and automated licence sweeps. They reference standards/LICENCE-POLICY.adoc and define licence defaults and AGPL-3.0-or-later conditions.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Poem

A rabbit reads the licence guide,
With careful hops from side to side.
No sweeping scripts, no files re-signed,
Clear defaults keep the rules aligned.
AGPL waits where its terms apply.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Aug 28, 2026

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 4 issues detected

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 4
View findings
[
  {
    "reason": "Issue in label-triage.yml",
    "type": "missing_timeout_minutes",
    "file": "label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in labels.yml",
    "type": "missing_timeout_minutes",
    "file": "labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 0 day(s) old",
    "type": "CSA001",
    "file": "labels.yml",
    "action": "review",
    "rule_module": "code_scanning_alerts",
    "severity": "medium"
  },
  {
    "reason": "Code scanning (Hypatia): hypatia/workflow_audit/missing_timeout_minutes -- Hypatia workflow_audit: missing_timeout_minutes -- 0 day(s) old",
    "type": "CSA001",
    "file": "label-triage.yml",
    "action": "review",
    "rule_module": "code_scanning_alerts",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant