Commit e54b17a
fix(ci): add SPDX header to pages.yml; remove retired scorecard-enforcer.yml (#292)
Two governance-gate failures, both surfaced only after the repository's
Actions policy
was fixed — these workflows previously `startup_failure`'d before any
job could run, so
the errors were invisible.
## 1. `Workflow security linter`
```
ERROR: .github/workflows/pages.yml missing SPDX header
```
`pages.yml` is the **active** Ddraig SSG docs deploy added in #288, and
was the only
workflow of 26 lacking the header. Added, matching `proofs.yml`'s form.
Deliberately **not** deleted: it is live, and `pages-deploy.yml` is a
different thing
(Cloudflare Workers, not GitHub Pages) — they are not duplicates.
## 2. `Check Workflow Staleness`
```
ERROR: scorecard-enforcer.yml is retired.
Use scorecard.yml -> standards scorecard-reusable.yml instead.
```
Removed; the replacement `scorecard.yml` is present. This also clears
the separate
`OpenSSF Scorecard Enforcer` run failure.
**Checked before deleting:** the Base ruleset (`14285163`) requires only
`Dependabot`,
`Hypatia Neurosymbolic Analysis` and `Hypatia`. `Scorecard Enforcer` is
not a required
context, so removing the workflow cannot strand a PR on a
permanently-"Expected" check —
the failure mode this repo's `CLAUDE.md` warns about.
## Deliberately out of scope
The staleness gate raises two further complaints that concern **shared
CI fate** and want
coordination rather than a drive-by fix:
- `governance-reusable.yml` / `scorecard-reusable.yml` pin
`d135b05bfc64` is **75 commits /
26 days** behind `standards` HEAD (refresh toward `8813ecf2a841`).
Re-pinning consumers
changes behaviour estate-wide, and at least one reusable
(secret-scanner) is known not to
inherit its config to callers — so a re-pin can make a gate stricter
without giving it the
configuration it needs.
- OSSF Scorecard uploads SARIF to Code Scanning while not running for
every PR head commit.
## Verification
Replicated the linter's own check across all 25 remaining workflows —
every one carries an
SPDX header and a top-level `permissions:` block. `pages.yml` still
parses as valid YAML.
`actionlint` reports one **pre-existing** `SC2086` (info) in
`pages.yml`, untouched by this
change.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent 123aa1f commit e54b17a
2 files changed
Lines changed: 5 additions & 124 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
1 | 6 | | |
2 | 7 | | |
3 | 8 | | |
| |||
This file was deleted.
0 commit comments