Skip to content

CI/CD regularisation: owner decisions O1–O10 (batch, non-blocking) #715

Description

@hyperpolymath

Spec: PR #714docs/superpowers/specs/2026-09-02-cicd-regularisation-design.md (§12). One reply covering all ten is enough; execution steps 1–3 proceed regardless.

  • O1 GitHub Team for metadatastician. Open https://education.github.com → dashboard → "Upgrade your academic organizations". Is metadatastician listed? If yes, upgrade (free). If not, apply for GitHub for Nonprofits (Team free). Until then metadatastician stays on per-repo rulesets (org rulesets 403 "Upgrade to GitHub Team", live 2026-09-02).
  • O2 Settings App (Probot) — is it installed anywhere? If not, every .github/settings.yml is dead and gets deleted.
  • O3 Dispositions: boj-build.yml "BoJ Server Build Trigger" (255 repos; DROP if BoJ retired) · mirror.yml targets (142 repos skip for missing forge secrets: keep on which?) · rhodibot.yml (93 repos, 78% red: retire or remake?) · ClusterFuzzLite cflite_* (keep on which Rust/Zig repos?).
  • O4 Repo moves beyond the first cut (games, befunge-cracker, stealth-glider → metadatastician; proofs/tooling stay). List any others, or "later".
  • O5 Three bypass-actor app IDs I cannot resolve (API returns 403 to a gh token): 1561, 85455, 946600. Settings → Applications on the account shows names. Remove if unrecognised?
  • O6 Gates vs bypass. Bypass applies to the whole ruleset, status checks included, so all nine bypass apps can merge around every GATE. Options: (a) single ruleset as planned, or (b) a second checks-only ruleset with bypass = claude, dependabot, github-actions, oikosbot, so the AI reviewers are held to the gates. Default if silent: (a).
  • O7 Julia private registry. julia-professional-registry exists. If Dependabot's Julia support cannot read it (pilot will tell), Renovate stays on those repos only. Acceptable?
  • O8 Squash-only, knowingly. Correction to the plan text: the LIVE ruleset (Optimus-Branch, every sampled repo) has no required_linear_history and allows merge, squash and rebase. The plan would ADD linear history and lock squash, because squash is the only method GitHub can sign server-side while keeping history linear (rebase merges cannot be signed). On 08-31 you replaced a ruleset on two repos to allow merge commits, so this is a real choice: (a) add linear history + squash-only estate-wide, or (b) keep merge commits allowed and no linear-history rule. Which?
  • O9 metadatastician app installs with no ruling: slack, microsoft-teams-for-github, thanks-dev, linear-data-importer, linear-code. Keep or uninstall? (codacy-production, gitar-bot, renovate, semgrep-app go per R1/R4/R5.)
  • O10 workflow-templates/ on a User-account .github. GitHub documents it for organisations only. I will plant one and check the "New workflow" page; if invisible, hyperpolymath new-repo distribution = rsr-template-repo only. No action from you unless you prefer another route.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesdecisionA ruling is required before work can proceedstatus:needs-ownerUnassigned and needs someone to take it

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions