Skip to content

Commit 49ac3f5

Browse files
chore(ci): bump governance-reusable pin to standards main (#56)
Pinned revision `7fdc2705` of `governance-reusable.yml` carries two bugs that make Governance red on every consumer: 1. **Workflow security linter** runs `bash scripts/update-actions-lock.sh --verify-local` in the **caller's** checkout, where the script does not exist — exit 127. 2. **Allowlist Preflight** runs `check-actions-policy.sh` with an empty `GH_TOKEN` — `gh` refuses, exit 3. Both are cured on `standards` main (`fad242d35291de1898242d6737ba02b74a59a2f2`): the verifier is copied into `\$RUNNER_TEMP`, and the policy step is skipped when no credential is supplied. **Witness:** verified green on [hyperpolymath/blocky-writer#55](hyperpolymath/blocky-writer#55) at this exact SHA — governance run `completed/success`, 15/15 jobs, including the two jobs that were red on that repo's default branch. Judge this PR by the set difference against your own default branch (which governance jobs are newly red), not by overall check colour — unrelated build failures may pre-date it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent c9b38ad commit 49ac3f5

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

‎.github/workflows/governance.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,8 +27,9 @@ concurrency:
2727
cancel-in-progress: true
2828

2929
permissions:
30+
actions: read
3031
contents: read
3132

3233
jobs:
3334
governance:
34-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
35+
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fad242d35291de1898242d6737ba02b74a59a2f2

0 commit comments

Comments
 (0)