Found while retiring the ping-only adversarial-review requirement (#138). Three independent defects in the repo that enforces governance for six orgs.
1. build has failed on every PR since at least 2026-06-29
package.json pins "hono-agents": "^0.19.0". npm has only 3.x (latest seen: 3.0.12), so npm ci fails with ETARGET: No matching version found for hono-agents@^0.19.0. Confirmed on PRs #129, #131, #132, #133, #134, #136 and #138.
2. The required Org Governance Control Loop check can never report on a PR
Branch protection requires build, build-ui, and Org Governance Control Loop. That workflow triggers only on workflow_dispatch, schedule, and repository_dispatch — never pull_request — so it never reports on a PR head.
With (1) and (2), no chittycommand PR can merge without an admin override. Recent merges (#120, #123, #124, #131, #136) all went through the admin account. The governance repo has effectively no functioning merge gate.
This is the same deadlock class as a required context that no workflow produces. Either add a lightweight pull_request job that reports under that name, or drop it from the required list.
3. The loop runs DEGRADED on every pass, enforcing a retired lane
org-governance-policy.json requires .github/workflows/onepassword-rotation-audit.yml (in both requiredFiles and requiredWorkflowTriggers) and scripts/onepassword-rotation-audit.sh. None has a template under templates/governance-baseline/, so org-governance-remediate.sh's preflight reports 3 UNSATISFIABLE_GATEs and remediation runs in DEGRADED, issue-only mode that never converges.
1Password is retired as both lane and authority (cold_source_of_truth is chittysecrets, ratified 2026-08-21). This requirement asks every governed repo to audit rotation in a system that no longer exists. The decision is whether to replace it with a ChittySecrets-equivalent audit or drop it.
Also noticed
scripts/chittycompliance-dispatch.sh:126-127 end in || true, so agent-dispatch failures are swallowed.
🤖 Generated with Claude Code
Found while retiring the ping-only adversarial-review requirement (#138). Three independent defects in the repo that enforces governance for six orgs.
1.
buildhas failed on every PR since at least 2026-06-29package.jsonpins"hono-agents": "^0.19.0". npm has only 3.x (latest seen: 3.0.12), sonpm cifails withETARGET: No matching version found for hono-agents@^0.19.0. Confirmed on PRs #129, #131, #132, #133, #134, #136 and #138.2. The required
Org Governance Control Loopcheck can never report on a PRBranch protection requires
build,build-ui, andOrg Governance Control Loop. That workflow triggers only onworkflow_dispatch,schedule, andrepository_dispatch— neverpull_request— so it never reports on a PR head.With (1) and (2), no chittycommand PR can merge without an admin override. Recent merges (#120, #123, #124, #131, #136) all went through the admin account. The governance repo has effectively no functioning merge gate.
This is the same deadlock class as a required context that no workflow produces. Either add a lightweight
pull_requestjob that reports under that name, or drop it from the required list.3. The loop runs DEGRADED on every pass, enforcing a retired lane
org-governance-policy.jsonrequires.github/workflows/onepassword-rotation-audit.yml(in bothrequiredFilesandrequiredWorkflowTriggers) andscripts/onepassword-rotation-audit.sh. None has a template undertemplates/governance-baseline/, soorg-governance-remediate.sh's preflight reports 3UNSATISFIABLE_GATEs and remediation runs in DEGRADED, issue-only mode that never converges.1Password is retired as both lane and authority (
cold_source_of_truthischittysecrets, ratified 2026-08-21). This requirement asks every governed repo to audit rotation in a system that no longer exists. The decision is whether to replace it with a ChittySecrets-equivalent audit or drop it.Also noticed
scripts/chittycompliance-dispatch.sh:126-127end in|| true, so agent-dispatch failures are swallowed.🤖 Generated with Claude Code