Skip to content

fix(ci): re-point validate-action references at the ecosystem repos - #296

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/repoint-validate-actions
Jul 27, 2026
Merged

fix(ci): re-point validate-action references at the ecosystem repos#296
hyperpolymath merged 1 commit into
mainfrom
fix/repoint-validate-actions

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

hyperpolymath/k9-validate-action and hyperpolymath/a2ml-validate-action no longer exist as standalone repositories. Both were consolidated into k9-ecosystem / a2ml-ecosystem as real top-level directories and the originals deleted.

The content is intact — 302 and 306 files respectively. Only these references are stale.

Any workflow reaching them fails at job setup:

Unable to resolve action hyperpolymath/k9-validate-action, repository not found

The fix — a path change, not a restore

GitHub resolves an action held in a subdirectory as owner/repo/path@ref:

- uses: hyperpolymath/a2ml-validate-action@<old-sha>
+ uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836b
- uses: hyperpolymath/k9-validate-action@<old-sha>
+ uses: hyperpolymath/k9-ecosystem/validate-action@89f3c270

Both targets verified to hold a real action.ymlValidate A2ML Manifests and Validate K9 Configurations.

How this stayed hidden

dogfood-gate.yml was itself invalid YAML in 71 repos, so the workflow had never run and never attempted to resolve these actions. Repairing the parse error exposed the stale reference underneath — one layer of silent breakage concealing another.

Verified before push

  • every edited file still parses and still yields a jobs: mapping
  • no *-validate-action@ reference remains
  • 1 file(s) changed, all under .github/workflows

🤖 Generated with Claude Code

`hyperpolymath/k9-validate-action` and `hyperpolymath/a2ml-validate-action`
no longer exist as standalone repositories. Both were consolidated INTO
`k9-ecosystem` / `a2ml-ecosystem` as real top-level directories and the
originals deleted. The content is intact — 302 and 306 files respectively —
only these references are stale.

Any workflow reaching them fails at job setup with:

    Unable to resolve action hyperpolymath/k9-validate-action,
    repository not found

GitHub resolves an action held in a subdirectory as `owner/repo/path@ref`, so
this is a path change, not a restore:

    hyperpolymath/a2ml-validate-action@<old>
      -> hyperpolymath/a2ml-ecosystem@aa4b836b
    hyperpolymath/k9-validate-action@<old>
      -> hyperpolymath/k9-ecosystem@89f3c270

Both targets are verified to hold a real `action.yml`
('Validate A2ML Manifests' / 'Validate K9 Configurations').

This surfaced only because `dogfood-gate.yml` was itself invalid YAML in 71
repos, so the workflow had never run and never attempted to resolve these
actions. Repairing the parse error exposed the stale reference beneath it.

Verified before push: every edited file still parses and still yields a
`jobs:` mapping, and no `*-validate-action@` reference remains. 1
file(s) changed, all under .github/workflows.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 244 issues detected

Severity Count
🔴 Critical 15
🟠 High 163
🟡 Medium 66

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Issue in build.yml",
    "type": "missing_timeout_minutes",
    "file": "build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in pages-deploy.yml",
    "type": "missing_timeout_minutes",
    "file": "pages-deploy.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in push-email-notify.yml",
    "type": "missing_timeout_minutes",
    "file": "push-email-notify.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in instant-sync.yml",
    "type": "secret_action_without_presence_gate",
    "file": "instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "codeql_missing_actions_language",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/boj-server/boj-server/cartridges/academic-workflow-mcp/adapter/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/boj-server/boj-server/cartridges/sanctify-mcp/adapter/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/boj-server/boj-server/cartridges/bofig-mcp/adapter/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/boj-server/boj-server/cartridges/ephapax-mcp/adapter/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/boj-server/boj-server/cartridges/hesiod-mcp/adapter/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 43b8b37 into main Jul 27, 2026
50 of 51 checks passed
@hyperpolymath
hyperpolymath deleted the fix/repoint-validate-actions branch July 27, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant