Skip to content

Governance control loop runs in a repo with no working required checks, and enforces a retired 1Password lane #139

Description

@chitcommit

Found while retiring the ping-only adversarial-review requirement (#138). Three independent defects in the repo that enforces governance for six orgs.

1. build has failed on every PR since at least 2026-06-29

package.json pins "hono-agents": "^0.19.0". npm has only 3.x (latest seen: 3.0.12), so npm ci fails with ETARGET: No matching version found for hono-agents@^0.19.0. Confirmed on PRs #129, #131, #132, #133, #134, #136 and #138.

2. The required Org Governance Control Loop check can never report on a PR

Branch protection requires build, build-ui, and Org Governance Control Loop. That workflow triggers only on workflow_dispatch, schedule, and repository_dispatch — never pull_request — so it never reports on a PR head.

With (1) and (2), no chittycommand PR can merge without an admin override. Recent merges (#120, #123, #124, #131, #136) all went through the admin account. The governance repo has effectively no functioning merge gate.

This is the same deadlock class as a required context that no workflow produces. Either add a lightweight pull_request job that reports under that name, or drop it from the required list.

3. The loop runs DEGRADED on every pass, enforcing a retired lane

org-governance-policy.json requires .github/workflows/onepassword-rotation-audit.yml (in both requiredFiles and requiredWorkflowTriggers) and scripts/onepassword-rotation-audit.sh. None has a template under templates/governance-baseline/, so org-governance-remediate.sh's preflight reports 3 UNSATISFIABLE_GATEs and remediation runs in DEGRADED, issue-only mode that never converges.

1Password is retired as both lane and authority (cold_source_of_truth is chittysecrets, ratified 2026-08-21). This requirement asks every governed repo to audit rotation in a system that no longer exists. The decision is whether to replace it with a ChittySecrets-equivalent audit or drop it.

Also noticed

scripts/chittycompliance-dispatch.sh:126-127 end in || true, so agent-dispatch failures are swallowed.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions