fix(ci): call the estate reusables by their real ref — these never parsed - #16
Conversation
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…d copies `uses: ../….github/workflows/<x>-reusable.yml` is not a ref form GitHub Actions supports, so every workflow carrying it fails at parse time: conclusion=failure, 0 jobs, and a run name equal to its path rather than its declared `name:`. This repairs them throughout the tree, not only in the root `.github/workflows/`, because the root is where they are *live* but the nested copies are where they *propagate* — standards' format templates, k9-ecosystem's dispatch templates and deed-core's action scaffolds are what new repos are minted from, and each one carried an unparseable ref. Each ref becomes the pinned cross-repo form `hyperpolymath/standards/.github/workflows/<x>-reusable.yml@4e6ffe55…`, and each calling job is granted the permissions its callee declares — keyed off the callee named in the ref, since several callers point at the same reusable. Without that step the repair only moves the failure from parse time to run time. Refs hyperpolymath/standards#808.
d38a49c to
4d7d346
Compare
|
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out the documentation. |



These workflows carried
uses: ../….github/workflows/<x>-reusable.yml, which is not a ref formGitHub Actions supports — a reusable-workflow
uses:may be./…(same repo) or<owner>/<repo>/….yml@<ref>(cross repo). A../path is rejected at parse time, so each of theseworkflows is permanently dead:
conclusion=failure, 0 jobs, and a run name equal to its pathrather than its declared
name:. That triple is also the signature of callee-lockfile poisoning,which is why these read as lockfile faults rather than as what they are.
Two changes per file:
hyperpolymath/standards/.github/workflows/<x>-reusable.yml@4e6ffe55…;more than its caller grants it, so repairing only the ref would move the failure from parse time
to run time — the same defect, one layer down. Permissions are keyed off the callee named in
the ref, not the caller's filename:
scorecard-enforcer.ymlalso callsscorecard-reusable.yml.Refs hyperpolymath/standards#808. The reusables themselves are untouched — they were always fine;
this is the callers' ref form.