Skip to content

chore(security): fill the security-contact placeholders (owner-supplied values) - #27

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/security-contact-fill
Jul 28, 2026
Merged

chore(security): fill the security-contact placeholders (owner-supplied values)#27
hyperpolymath merged 1 commit into
mainfrom
chore/security-contact-fill

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Mirror of systemet PR #33 — same owner-ruled values, same three judgement calls (see commit message). Should turn openssf-compliance green here too.

…ed values)

Same fill as systemet PR #33, same three judgement calls (template block
deleted per its own instruction; gpg examples keyed on the fingerprint
ABF3ECD932C2A04345EC9B3D2E725C6B831EA2B8 because the key UID is jonathan@,
not security@; optional Hiring: line dropped — no /careers page).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

Running post-merge workflows

CI failed: Multiple CI validation checks failed due to unallowlisted root files, missing K9 contract formatting, a banned Nix file, and a missing SonarQube authentication token.

Overview

Multiple distinct validation failures occurred across CI jobs, including violations of repository root shape allowlists, K9 contract validation errors, a banned Nix file check failure, and an authentication failure for SonarQube scanning across 4 unique error logs.

Failures

K9 Contract Validation Failure (confidence: high)

  • Type: tooling
  • Affected jobs: 90186734795
  • Related to change: unclear
  • Root cause: The K9 contract files lack required formatting and fields, such as the mandatory 'K9!' magic number string on the first non-empty line and required pedigree blocks.
  • Suggested fix: Update the K9 contract files to include the 'K9!' magic number and valid pedigree blocks, or run the local generator tool (k9iser).

Banned Nix File Policy Violation (confidence: high)

  • Type: tooling
  • Affected jobs: 90186734370
  • Related to change: unclear
  • Root cause: The repository contains flake.nix, triggering a hard-fail because Nix is banned estate-wide in favor of Guix.
  • Suggested fix: Remove flake.nix and use Guix (guix.scm) exclusively.

SonarQube Authentication Failure (confidence: high)

  • Type: authentication
  • Affected jobs: 90186734926
  • Related to change: no
  • Root cause: The SonarScanner action executed without a valid SONAR_TOKEN environment variable or with insufficient permissions.
  • Suggested fix: Configure a valid SONAR_TOKEN secret in GitHub Actions.

Root Shape Allowlist Violation (confidence: high)

  • Type: tooling
  • Affected jobs: 90186734536
  • Related to change: unclear
  • Root cause: Unauthorized root entries (e.g., .githooks/, ARCHITECTURE.md, GOVERNANCE.md, MAINTAINERS, mise.toml) were added to the repository root without updating the allowlist.
  • Suggested fix: Add the newly introduced root entries to .machine_readable/root-allow.txt or move them into appropriate subdirectories.

Summary

  • Change-related failures: 0 (Authentication and policy checks are environmental/repository configuration issues)
  • Infrastructure/flaky failures: 0
  • Recommended action: Update the repository root allowlist and K9 files to comply with repository standards, remove flake.nix, and configure the missing SonarQube token secret.
Code Review ✅ Approved

Fills security-contact placeholders with owner-supplied values to satisfy OpenSSF compliance requirements. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot

gitar-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Jul 28, 2026
@hyperpolymath
hyperpolymath merged commit 37f8c7c into main Jul 28, 2026
41 of 46 checks passed
@hyperpolymath
hyperpolymath deleted the chore/security-contact-fill branch July 28, 2026 05:21
hyperpolymath added a commit that referenced this pull request Jul 28, 2026
Re-pins the ANCHOR off the dead `ba5930dc` side lineage onto systemet
mainline — which now actually contains the ET ledger, the proven ET-2,
and accepted ADR-0002. This was the standing "come back down" step; it
costs nothing (the old lineage's content was rescued via anytype PR #12
+ systemet #17/#24/#27).

Closes #13.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant