Skip to content

fix(governance): make ratchets and lock checks fail honestly - #700

Merged
hyperpolymath merged 5 commits into
mainfrom
fix/exemption-ratchet-legacy-baseline
Aug 31, 2026
Merged

fix(governance): make ratchets and lock checks fail honestly#700
hyperpolymath merged 5 commits into
mainfrom
fix/exemption-ratchet-legacy-baseline

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Aug 31, 2026

Copy link
Copy Markdown
Owner

What changed

  • grandfather unchanged anonymous Hypatia baseline entries by full JSON-value multiset comparison
  • fail new, modified, or duplicated anonymous entries
  • allow documentation additions and deletions as debt reduction
  • make standards exercise the pull request copy of its exemption-ratchet script while consumers continue using standards main
  • accept gh actions-lock output only when its authoritative valid field is true, while preserving every advisory in the log
  • fail closed on invalid, malformed, or contradictory action-lock output

Controls

Exemption ratchet:

  • 44 unchanged legacy anonymous entries pass
  • new, duplicated, and same-size modified anonymous entries fail
  • adding documentation and deleting legacy debt pass
  • all 14 targeted cases pass

Action lock:

  • actual standards lock verifies as valid with advisories and restores workflow bytes
  • wrong reusable refs, non-stale invalid findings, malformed output, valid false with no findings, and failed refreshes all fail
  • all 9 targeted controls pass

Secret scans, Bash syntax, ShellCheck, and diff checks pass. Actionlint adds no diagnostic beyond the pre-existing job.workflow_sha and quoting findings already present on main.

@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 18 minutes.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ff3a8903-4b52-4c0f-aaef-7af8960435a2

📥 Commits

Reviewing files that changed from the base of the PR and between b5e96ee and 2a55bea.

📒 Files selected for processing (6)
  • .github/workflows/governance-reusable.yml
  • docs/EXEMPTION-MECHANISMS.adoc
  • scripts/check-exemption-ratchet.sh
  • scripts/tests/actions-lock-update-test.sh
  • scripts/tests/exemption-ratchet-test.sh
  • scripts/update-actions-lock.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath hyperpolymath changed the title fix(governance): ratchet only new anonymous exemptions fix(governance): make ratchets and lock checks fail honestly Aug 31, 2026
@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit f8cc276 into main Aug 31, 2026
46 checks passed
@hyperpolymath
hyperpolymath deleted the fix/exemption-ratchet-legacy-baseline branch August 31, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant