You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(ci): unbreak workflow YAML and add a complete actions.lock (#49)
Remediates **GitHub Workflow Dependency Locking** (public preview, no
changelog entry), which rejects runs at `startup_failure` — zero jobs,
no logs, nothing in REST or GraphQL. Full analysis:
`hyperpolymath/standards#657`.
**Proven on `hyperpolymath/anamnesis`: 6 of 6 workflows dead → 0
`startup_failure`, 13 running.**
### Five steps, in order — each blocks the next
**1. Unbreak the workflow YAML.** Any `permissions:` carrying a scalar
with an indented mapping under it:
```yaml
permissions: read-all
actions: read # <- mapping under a scalar. Unparseable.
```
This reaches past the one file: **`gh actions-lock` refuses to run when
*any* workflow in the repo fails to parse**, so the repo can never
acquire a lockfile and can never self-heal.
**2. Repin `standards` reusables** off commits with no `actions.lock`.
The rejection requires the **callee** to be covered *at the pinned SHA*
— unsatisfiable at a pre-lockfile commit.
**3. Generate** the lockfile with `gh actions-lock`.
**4. Hand-add the reusable-caller entries the tool omits**, as
`'<path>': []`.
⚠️ Measured across 218 repos: `P(startup_failure | has lockfile) =
91.7%` vs `15.8%` without — because every workflow a lockfile **omits**
is rejected. **A partial lock is worse than none.** Running `gh
actions-lock` and stopping there is how this outage spread.
**5. Restore `SPDX-License-Identifier` to line 1**, which the tool
displaces with its own banner and which the workflow-security linter
greps via `head -1`.
### Verified before this PR was opened
`0` unparseable workflows · lockfile covers **every** workflow, no
omissions · SPDX on line 1 in **every** file. The script refuses to push
if any of the three fails.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
0 commit comments