Skip to content

Ci/allowlist escalation preflight - #541

Merged
hyperpolymath merged 3 commits into
mainfrom
ci/allowlist-escalation-preflight
Jul 28, 2026
Merged

Ci/allowlist escalation preflight#541
hyperpolymath merged 3 commits into
mainfrom
ci/allowlist-escalation-preflight

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Jul 28, 2026

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers


Summary by Gitar

  • CI / Tooling:
    • Regenerated .machine_readable/REGISTRY.a2ml to satisfy registry and topology sync gate.

This will update automatically on new commits.

hyperpolymath and others added 3 commits July 11, 2026 11:36
Follow-up to #482. Two additions the live gossamer/metadatastician fix surfaced:

- scripts/set-allowed-actions.sh: escalate the apply repo -> org (owner) ->
  enterprise. A repo-level PUT that 409s "already set at the organization or
  enterprise level" now falls back to the governing level — the metadatastician
  case (allowlist enforced at the ORG level, so the repo PUT 409s).
- rhodium-standard-repositories/.github/workflows/allowlist-preflight.yml: a
  template workflow (seeded into every RSR repo) that runs check-allowed-actions
  using only actions/checkout, so it can never itself startup-fail. Turns an
  opaque estate-wide startup_failure blackout into one legible red check.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…gate)

Registry went stale after the #482 allowlist additions merged. Regenerated from
ground truth via scripts/build-registry.sh (32 specs) — no hand edits.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit bf67e18 into main Jul 28, 2026
1 check passed
@hyperpolymath
hyperpolymath deleted the ci/allowlist-escalation-preflight branch July 28, 2026 07:01
@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown
Code Review ✅ Approved

Regenerates REGISTRY.a2ml to satisfy the registry and topology sync gate alongside CI allowlist escalation and preflight canary changes. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant