Skip to content

fix(ci): call the estate reusables by their real ref — these never parsed - #16

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/reusable-workflow-refs
Sep 19, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/reusable-workflow-refs

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

These workflows carried uses: ../….github/workflows/<x>-reusable.yml, which is not a ref form
GitHub Actions supports
— a reusable-workflow uses: may be ./… (same repo) or
<owner>/<repo>/….yml@<ref> (cross repo). A ../ path is rejected at parse time, so each of these
workflows is permanently dead: conclusion=failure, 0 jobs, and a run name equal to its path
rather than its declared name:. That triple is also the signature of callee-lockfile poisoning,
which is why these read as lockfile faults rather than as what they are.

Two changes per file:

  1. the ref becomes the pinned cross-repo form,
    hyperpolymath/standards/.github/workflows/<x>-reusable.yml@4e6ffe55…;
  2. the caller grants the permissions the callee's job declares. A cross-repo callee cannot hold
    more than its caller grants it, so repairing only the ref would move the failure from parse time
    to run time — the same defect, one layer down. Permissions are keyed off the callee named in
    the ref, not the caller's filename: scorecard-enforcer.yml also calls scorecard-reusable.yml.

Refs hyperpolymath/standards#808. The reusables themselves are untouched — they were always fine;
this is the callers' ref form.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5155207d-3f85-4292-aa65-7926ebbd33f2

📥 Commits

Reviewing files that changed from the base of the PR and between cbf6467 and 4d7d346.

📒 Files selected for processing (7)
  • .github/workflows/codeql.yml
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/mirror.yml
  • .github/workflows/scorecard-enforcer.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml
 ____________________________________________________________________________________________
< Founder mode code reviewer: seeing not just the bugs but the vision in every line of code! >
 --------------------------------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…d copies

`uses: ../….github/workflows/<x>-reusable.yml` is not a ref form GitHub Actions supports, so every
workflow carrying it fails at parse time: conclusion=failure, 0 jobs, and a run name equal to its
path rather than its declared `name:`.

This repairs them throughout the tree, not only in the root `.github/workflows/`, because the root
is where they are *live* but the nested copies are where they *propagate* — standards' format
templates, k9-ecosystem's dispatch templates and deed-core's action scaffolds are what new repos are
minted from, and each one carried an unparseable ref.

Each ref becomes the pinned cross-repo form
`hyperpolymath/standards/.github/workflows/<x>-reusable.yml@4e6ffe55…`, and each calling job is
granted the permissions its callee declares — keyed off the callee named in the ref, since several
callers point at the same reusable. Without that step the repair only moves the failure from parse
time to run time.

Refs hyperpolymath/standards#808.
@hyperpolymath
hyperpolymath force-pushed the fix/reusable-workflow-refs branch from d38a49c to 4d7d346 Compare September 19, 2026 19:40
@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit abe3773 into main Sep 19, 2026
12 of 14 checks passed
@hyperpolymath
hyperpolymath deleted the fix/reusable-workflow-refs branch September 19, 2026 19:41
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants