Skip to content

Commit e54b17a

Browse files
fix(ci): add SPDX header to pages.yml; remove retired scorecard-enforcer.yml (#292)
Two governance-gate failures, both surfaced only after the repository's Actions policy was fixed — these workflows previously `startup_failure`'d before any job could run, so the errors were invisible. ## 1. `Workflow security linter` ``` ERROR: .github/workflows/pages.yml missing SPDX header ``` `pages.yml` is the **active** Ddraig SSG docs deploy added in #288, and was the only workflow of 26 lacking the header. Added, matching `proofs.yml`'s form. Deliberately **not** deleted: it is live, and `pages-deploy.yml` is a different thing (Cloudflare Workers, not GitHub Pages) — they are not duplicates. ## 2. `Check Workflow Staleness` ``` ERROR: scorecard-enforcer.yml is retired. Use scorecard.yml -> standards scorecard-reusable.yml instead. ``` Removed; the replacement `scorecard.yml` is present. This also clears the separate `OpenSSF Scorecard Enforcer` run failure. **Checked before deleting:** the Base ruleset (`14285163`) requires only `Dependabot`, `Hypatia Neurosymbolic Analysis` and `Hypatia`. `Scorecard Enforcer` is not a required context, so removing the workflow cannot strand a PR on a permanently-"Expected" check — the failure mode this repo's `CLAUDE.md` warns about. ## Deliberately out of scope The staleness gate raises two further complaints that concern **shared CI fate** and want coordination rather than a drive-by fix: - `governance-reusable.yml` / `scorecard-reusable.yml` pin `d135b05bfc64` is **75 commits / 26 days** behind `standards` HEAD (refresh toward `8813ecf2a841`). Re-pinning consumers changes behaviour estate-wide, and at least one reusable (secret-scanner) is known not to inherit its config to callers — so a re-pin can make a gate stricter without giving it the configuration it needs. - OSSF Scorecard uploads SARIF to Code Scanning while not running for every PR head commit. ## Verification Replicated the linter's own check across all 25 remaining workflows — every one carries an SPDX header and a top-level `permissions:` block. `pages.yml` still parses as valid YAML. `actionlint` reports one **pre-existing** `SC2086` (info) in `pages.yml`, untouched by this change. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 123aa1f commit e54b17a

2 files changed

Lines changed: 5 additions & 124 deletions

File tree

.github/workflows/pages.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,8 @@
1+
# SPDX-License-Identifier: MPL-2.0
2+
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
3+
#
4+
# GitHub Pages docs deploy via the Ddraig SSG (#288).
5+
16
name: GitHub Pages (Ddraig SSG)
27
on:
38
push:

.github/workflows/scorecard-enforcer.yml

Lines changed: 0 additions & 124 deletions
This file was deleted.

0 commit comments

Comments
 (0)