Commit bfd3621
fix(ci): close the governance gate — SPDX, permissions, SHA pins, reusable bump (#38)
The governance gate is all-jobs-must-pass, so these ship as one commit;
individually none of them turns the repo green.
* SPDX line-1 header and a top-level `permissions:` block on every
workflow file (the two `Workflow security linter` checks).
* Every `uses:` tag reference resolved to a full 40-hex commit SHA. This
satisfies the linter and also the repository's own
`sha_pinning_required` Actions policy, which refuses `@v4` at parse
time — a refusal that produces no check run at all.
* `hypatia-scan.yml` now grants `security-events: write`. This is not
cosmetic and is not separable from the pin bump below: at HEAD the
reusable declares `security-events: write` where the old pin declared
`read`, and a called workflow cannot escalate beyond its caller's
grant. Bumping the pin without this would fail at parse time.
* The three reusables watched by the staleness gate (governance,
hypatia-scan, scorecard) advanced to standards HEAD, which is 62
commits ahead of the false-green cache fix and includes the
deny-list-negative fix from standards#524.
`mirror-reusable` and `secret-scanner-reusable` are deliberately left on
their current pins: the staleness gate does not watch them, so they are
not holding anything red, and bumping them carries unrelated risk.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent b5f2698 commit bfd3621
2 files changed
Lines changed: 2 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | | - | |
| 28 | + | |
29 | 29 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| |||
0 commit comments