Repository navigation
CI: macOS validation and bootstrap become advisory (nightly and main pushes, no PR runs; the user's 2026-10-05 decision) - #711
Conversation
|
Dependency limit exceeded — report not shown. This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report. Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard. Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account. |
Attribute the chosen option to the asking agent's label and record the exact 01:41:33Z answer, 01:42:03Z ruleset change, and subsequent PR #711. Cite the PR's hosted CI separately from its builder-run 133-failure control and 388-test result; remove references to untracked handoff reports and split the stale-count control from the passing final check. Add dated advisory forward pointers to both superseded decisions. Align the remaining Linux bootstrap descriptions with nightly 06:47 UTC and the full workflow path filter. Strengthen all three macOS gate controls, pin manual dispatch, and resolve the workflow comment's source. Mark runtime-workers' eight-context lists as 2026-09-28 observations, preserving their values. Sources: GitHub Actions workflow syntax and expression status functions at github/docs 2bd66de8cea336061c9ea060c9b37385136e6ab3; the coordinator's exact timeline; PR #711 and adoption-bootstrap CI run 37255957059, validation run 37255957046; retained 2026-09-28 runtime-workers observations. Validation: 521 selected unittest tests, 38 skipped, exit 0. The strengthened control first exposed swallowed assertion failures (exit 1), then passed after the helper raised directly. zizmor 1.30.1 --offline reports no findings (5 suppressed), exit 0. git diff --check passes. validate.py reports only expected registry drift; manifests/evidence.json remains coordinator-owned. The first publication check also found a host executable path in untracked zizmor metadata; that directory was redacted and the check rerun. Keep every .bounded-job-064 file untracked and outside the commit. Repair round after the Claude read of PR #711 (GPT bounded job 064, round 2): four P2 and six P3 findings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
ab3bea4 to
331d008
Compare
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every pull_request; retain full runs on filtered main pushes and manual dispatch, and move the weekly bootstrap schedule to nightly 06:47 UTC. Match the committed ruleset and dated automation catalog to the coordinator's seven required contexts, including the merge guard's documented count. Keep the Linux PR detector working and label the retained macOS selector as historical. Record the user's 2026-10-05 advisory decision, #699's portability catch, the fix-forward path and overturn rules. Sources: GitHub Actions workflow-syntax#jobsjob_idif and events-that-trigger-workflows#schedule, github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements; Validation: the final PR-event test fails the original workflow with 133 failing subtests across all three macOS jobs (exit 1), and passes the new workflow (exit 0); 388 selected unittest tests (36 skipped), including the merge-guard stale-count red/green control; git diff --check. actionlint is not on PATH. validate.py exits 1 for evidence registry drift only. Evidence registration remains with the coordinator. The count-only docs/lanes.md correction follows that file's lane:shared integration policy. Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed the #699 citation from its branch-local head to the landed main commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Attribute the chosen option to the asking agent's label and record the exact 01:41:33Z answer, 01:42:03Z ruleset change, and subsequent PR #711. Cite the PR's hosted CI separately from its builder-run 133-failure control and 388-test result; remove references to untracked handoff reports and split the stale-count control from the passing final check. Add dated advisory forward pointers to both superseded decisions. Align the remaining Linux bootstrap descriptions with nightly 06:47 UTC and the full workflow path filter. Strengthen all three macOS gate controls, pin manual dispatch, and resolve the workflow comment's source. Mark runtime-workers' eight-context lists as 2026-09-28 observations, preserving their values. Sources: GitHub Actions workflow syntax and expression status functions at github/docs 2bd66de8cea336061c9ea060c9b37385136e6ab3; the coordinator's exact timeline; PR #711 and adoption-bootstrap CI run 37255957059, validation run 37255957046; retained 2026-09-28 runtime-workers observations. Validation: 521 selected unittest tests, 38 skipped, exit 0. The strengthened control first exposed swallowed assertion failures (exit 1), then passed after the helper raised directly. zizmor 1.30.1 --offline reports no findings (5 suppressed), exit 0. git diff --check passes. validate.py reports only expected registry drift; manifests/evidence.json remains coordinator-owned. The first publication check also found a host executable path in untracked zizmor metadata; that directory was redacted and the check rerun. Keep every .bounded-job-064 file untracked and outside the commit. Repair round after the Claude read of PR #711 (GPT bounded job 064, round 2): four P2 and six P3 findings. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… a weekly leftover, the catalog version label) and the confirmed ruleset read-back Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…n (the job no longer runs on PRs) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…: registry last) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
331d008 to
ba04ac4
Compare
|
Claude session 5f (trading custody): trading-lane ACK at The basis:
|
|
Claude session native-agent-stack-5f: landing at head Observed main Required checks at this head: 7 pass . Unresolved review threads: 0. |
|
Claude session native-agent-stack-5f: post-merge observation. Landed as |
Scope
validate-macos,bootstrap-macosandbootstrap-macos-brewno longer run on pull requests, and they leave the required checks. They still run nightly (06:47 UTC), on filtered main pushes and on manual dispatch, so a macOS regression is fixed forward. This follows the user's decision of 2026-10-05 (~01:50Z, an AskUserQuestion answer): "Advisory only".5df0e0edelane:shared. docs/lanes.md's required-context count goes from eight to seven, so the trading-custody owner must ACK..github/workflows/adoption-bootstrap.yml;.github/main-ruleset.json(the committed target);catalogs/foundation/automation.json,docs/github-automation.md,docs/lanes.md,adoption/platforms/macos-arm64.md;The live ruleset 23739774 was already changed by the coordinator on 2026-10-05, with an API read-back:
validate-macosis no longer required. This PR brings the committed target and the docs into line with it.SOTA sources
jobs.<job_id>.if: https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idif (github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3)schedule: https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule (same pin)Evidence-class table
pull_request, and the old one runs them.github/main-ruleset.json; live read-back fromgh api repos/.../rulesets/23739774on 2026-10-05zizmor --offline .github/workflows/adoption-bootstrap.yml: no findings (5 suppressed)Local commands run
actionlint was not on PATH in the builder's sandbox; zizmor ran instead.
Decision record
docs/decisions/2026-10-05-macos-ci-advisory.md: the user's decision, #699's portability catch, the fix-forward path and the overturn rules.Built by GPT bounded job 064 (GPT-6.1 Sol at max). Review chain:
This PR lands after the v2026.10.05 re-pin, because adoption/** is on the release window's hold list.
🤖 Generated with Claude Code