Live Actions registry drift
The repository's Actions API currently reports 42 workflow identities. Numerous historical federation, OIDC, OpenCode product-loop, dependency-refresh, coverage, and desired-state bootstrap records remain in state: active, including examples such as:
bootstrap-federation-preflight.yml and URL-hardening variants;
bootstrap-finalize-coverage.yml;
- the OpenCode product-loop finalization/reconciliation bootstrap series;
bootstrap-https-review-remediation.yml;
- OIDC federation preflight versions through
v5;
bootstrap-upgrade-cryptography.yml;
- one-shot dependency-refresh/consolidation workflows;
- historical desired-state and coverage materializers.
Fresh protected-main contents lookup returns 404 Not Found for sampled active path .github/workflows/bootstrap-federation-preflight.yml. The source is absent, but GitHub continues to advertise the workflow identity as active.
The supported ci, CodeQL, Hourly PR steward, and Hourly product development workflows must be preserved. PR #74's egress repair is already on protected main; this issue tracks a separate workflow-lifecycle defect.
Root cause
Temporary federation and product-loop bootstrap workflows were removed from the protected-main tree after their bounded use, while their independent GitHub Actions registry records were not disabled. File deletion was treated as complete workflow lifecycle cleanup. Current tree-level tests cannot detect orphaned control-plane identities after source removal.
Realistic remediation
Keyverse remains owned by the enabled general CWL Autonomous Development writer lease. The fleet incident loop must remain read-only and must not race it. Under that owner path:
- paginate the complete Actions registry;
- bind evidence to the exact protected-main SHA and tree;
- classify present repository workflows, active orphan records, disabled records, GitHub-owned dynamic workflows, intended pending supported integrations, and unresolved records;
- refetch exact branch/workflow state immediately before mutation;
- disable active orphan repository-path identities through an authorized operator or normal reviewed control-plane action;
- preserve all current supported CI/security/hourly workflows;
- retain immutable before/after evidence.
Coordinate with central lifecycle issue ContextualWisdomLab/.github#945 and AppGuardrail detector issue ContextualWisdomLab/appguardrail#929. Do not add another PAT, COPILOT_GITHUB_TOKEN, broad secrets: inherit, or workflow-disable authority to an untrusted scanner.
Acceptance criteria
- complete paginated inventory and exact protected-main binding;
- every reviewed active repository-path workflow absent from protected
main disabled or explicitly justified;
- no current CI/security/hourly workflow disabled through name-only matching;
- no historical federation/product-loop bootstrap source reintroduced;
- read-only recurrence detector emits workflow ID, path, state, default-branch SHA, observation time, and pagination receipts;
- adversarial tests cover pagination truncation, permission loss, transient 403/404/5xx, branch movement, path case/encoding, renamed/reused workflow IDs, GitHub dynamic workflows, and a currently present bounded bootstrap still owned by an active PR;
- exact-head CI/security/review gates;
- normal protected-main integration;
- post-remediation live inventory proves orphan identities disabled while supported Hourly PR steward and Hourly product development remain operational.
This issue belongs to the organization-wide Hourly Product Development fleet incident.
Live Actions registry drift
The repository's Actions API currently reports 42 workflow identities. Numerous historical federation, OIDC, OpenCode product-loop, dependency-refresh, coverage, and desired-state bootstrap records remain in
state: active, including examples such as:bootstrap-federation-preflight.ymland URL-hardening variants;bootstrap-finalize-coverage.yml;bootstrap-https-review-remediation.yml;v5;bootstrap-upgrade-cryptography.yml;Fresh protected-main contents lookup returns
404 Not Foundfor sampled active path.github/workflows/bootstrap-federation-preflight.yml. The source is absent, but GitHub continues to advertise the workflow identity as active.The supported
ci,CodeQL,Hourly PR steward, andHourly product developmentworkflows must be preserved. PR #74's egress repair is already on protectedmain; this issue tracks a separate workflow-lifecycle defect.Root cause
Temporary federation and product-loop bootstrap workflows were removed from the protected-main tree after their bounded use, while their independent GitHub Actions registry records were not disabled. File deletion was treated as complete workflow lifecycle cleanup. Current tree-level tests cannot detect orphaned control-plane identities after source removal.
Realistic remediation
Keyverse remains owned by the enabled general CWL Autonomous Development writer lease. The fleet incident loop must remain read-only and must not race it. Under that owner path:
Coordinate with central lifecycle issue
ContextualWisdomLab/.github#945and AppGuardrail detector issueContextualWisdomLab/appguardrail#929. Do not add another PAT,COPILOT_GITHUB_TOKEN, broadsecrets: inherit, or workflow-disable authority to an untrusted scanner.Acceptance criteria
maindisabled or explicitly justified;This issue belongs to the organization-wide Hourly Product Development fleet incident.