docs(foundation): keep the 2026-05-18 history entries append-only - #336
Conversation
PR #334 moved ABSZ_REF to f486c299 and, in passing, rewrote two dated 2026-05-18 entries in docs/foundation.adoc to name the new pin. Those entries record what was pinned in May; restore `3ff5cee` there and add a dated 2026-10-01 entry for the move. The current claims table and "Pinned inputs" keep f486c299. Answers the CodeRabbit thread on #334. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 43 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔍 Hypatia Security ScanFindings: 33 issues detected
View findings[
{
"reason": "Required file missing",
"type": "missing",
"file": "0-AI-MANIFEST.a2ml",
"action": "create",
"rule_module": "root_hygiene",
"severity": "high"
},
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"line": 39,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 46,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 87,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 53,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 34,
"reason": "workflow .github/workflows/labels.yml:34 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "warn"
},
{
"line": 48,
"reason": "workflow .github/workflows/label-triage.yml:48 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
"type": "WH006",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "warn"
},
{
"line": 27,
"reason": "workflow .github/workflows/scorecard.yml:27 uses `secrets: inherit` — forwards every caller secret to the reusable workflow",
"type": "WH008",
"file": ".github/workflows/scorecard.yml",
"action": "report",
"rule_module": "workflow_hardening",
"severity": "warn"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
|
Autopilot could not be updated. Open Coding to check access and billing. |
What
Keeps the two dated 2026-05-18 entries in
docs/foundation.adocat the revision they described (3ff5cee) and adds a dated 2026-10-01 entry recording theABSZ_REFmove tof486c29903434589117fa0662c6f29b0f17d1d5fmade by #334. The current claims table and "Pinned inputs" paragraph keepf486c299.Why
#334 rewrote the May history entries in passing. CodeRabbit flagged it on #334 (thread
discussion_r4155578184): a history log is append-only. This PR answers that thread.Evidence
git diff 511ef252..HEAD -- docs/foundation.adoc: two restored lines (97, 177) plus one appended entry; nothing else.checkandcold-checkon chore(agda): bump absolute-zero pin 3ff5cee7 -> f486c299 (Proofs green on main) #334 already verified the pin itself (run 36864369380 onabsolute-zerois the greenProofsreceipt).flake.guix, which does not exist since chore(nix->guix): remove flake.nix (Guix-only) #275. Out of scope; tracked as docs/foundation.adoc cites flake.guix, which does not exist on main (removed with flake.nix in #275) #335.🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57