Skip to content

chore: sync workflow templates - #54

Merged
stranske merged 1 commit into
mainfrom
sync/workflows-delivery
Aug 23, 2026
Merged

chore: sync workflow templates#54
stranske merged 1 commit into
mainfrom
sync/workflows-delivery

Conversation

@stranske

@stranske stranske commented Aug 23, 2026

Copy link
Copy Markdown
Owner

Sync Summary

Files Updated

  • agents-guard.yml: Agents guard - enforces agents workflow protections (Health 45)
  • maint-76-claude-code-review.yml: Claude Code review (opt-in) - runs only on labeled PRs or manual dispatch
  • maint-87-docs-drift-fix-agent.yml: Docs drift fix agent - reports deterministic documentation drift weekly and creates idempotent repair issues only on an explicit apply dispatch
  • sync_dev_dependencies.py: Syncs dev dependency versions from autofix-versions.env to pyproject.toml
  • check_docs_drift.py: Detects workflow-inventory and repository-path documentation drift for the docs drift fix agent
  • docs_drift_fix_agent.py: Builds bounded deterministic documentation-drift repair plans and idempotent issue batches
  • issue_format.py: Pure-stdlib validator for AGENT_ISSUE_FORMAT compliance. Single fleet definition of agent-processable; used by agents-issue-format-guard.yml and callable directly by local filers to pre-flight before gh issue create (non-zero exit = unfit). Do not fork per repo.
  • resolve_mypy_pin.py: Resolves mypy version pinning - required by reusable CI workflow
  • requirements-llm.txt: Pinned LLM dependencies - exact-sync guarded for agent workflows
  • state_fingerprint.py: Computes workflow state fingerprints for unchanged-state skip gates
  • check_deliberate_break.py: Opt-in Gate helper that proves named deliberate-break acceptance tests fail against the base implementation
  • runner_lib/ (1 files): Shared runner prompt assembly, output parsing, and dispatch debounce helpers
  • decode_raw_input.py: Decodes raw input from ChatGPT connector
  • verifier_config.py: Shared verifier prompt budgets, schema-repair policy, and terminal artifact validation
  • verdict_extract.py: Verdict extractor - parses verification verdicts from LLM output
  • llm_provider.py: LLM provider configuration - GitHub Models and OpenAI client setup
  • embedding_provider.py: Embedding provider registry used by synced semantic matching helpers
  • check_model_registry_freshness.py: Model-registry freshness gate - validates dated decisions, evidence, lifecycle, and profile-based slots
  • discover_model_catalog.py: Advisory provider-catalog discovery - proposes new model candidates without changing reviewed selections

Files Skipped

  • pr-00-gate.yml: File exists and sync_mode is create_only
  • ci.yml: File exists and sync_mode is create_only
  • renovate.json: File exists and sync_mode is create_only
  • cross-repo-smoke.yml: File exists and sync_mode is create_only
  • CLAUDE.md: Orchestrator is the local agent-orchestration TOOL, not a product consumer. Its CLAUDE.md is the tool's own safety net: the tool-vs-evidence split, the three-trees rule (clone / launchd mirror / $ORCH_STATE_DIR), and the requirement to verify with verify.py rather than a shell loop over test files. CLAUDE.md is the file agents auto-load every session, so it is the enforcement mechanism; overwriting it with the consumer template would silently remove those rules. Consumer conventions are referenced FROM that file instead.
  • llm_slots.json: None

Review Checklist

  • CI passes with updated workflows
  • No repo-specific customizations were overwritten

Source: stranske/Workflows
Source SHA: ebf666f28cf9196074640203e1f8d0978189f0ad
Template hash: 0092b4734e0c
Consumer-sync plan ID: sha256:0092b4734e0c819bde5ae812f61eb519d2cb17019e2f21dffd742e868f0e71cd
Plan scope: full
Scope base SHA: full
Sync phase: promote
Sync branch: sync/workflows-delivery
Consumer repo: stranske/Orchestrator
Manifest: .github/sync-manifest.yml

autofix: false

@stranske stranske added sync Automated sync from Workflows automated Automated sync from Workflows sync:delivery-staging Generated delivery is mutable and must not merge labels Aug 23, 2026
@coderabbitai

coderabbitai Bot commented Aug 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are limited based on label configuration.

🚫 Review skipped — only excluded labels are configured. (7)
  • sync
  • workflow:source-sync
  • workflow:source-maintenance
  • consumer-sync
  • integration-sync
  • workflows-sync
  • template-sync

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: c9ea7c24-2468-44ad-b970-f1c38424e17a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Keepalive Loop Reporter. Do not edit.

@stranske-keepalive

stranske-keepalive Bot commented Aug 23, 2026

Copy link
Copy Markdown

Automated Status Summary

Head SHA: 4209b0c
Latest Runs: ⏳ pending — Gate
Required: core tests (3.12): ⏳ pending, core tests (3.13): ⏳ pending, docker smoke: ⏳ pending, gate: ⏳ pending

Workflow / Job Result Logs
(no jobs reported) ⏳ pending

Updated automatically; will refresh on subsequent CI/Docker completions.


Keepalive checklist

Scope

No scope information available

Tasks

  • No tasks defined

Acceptance criteria

  • No acceptance criteria defined

@github-actions

github-actions Bot commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Workflow state fingerprint for Agents Gate Followups. Do not edit.

@stranske stranske added the sync:delivery-ready Generated delivery is sealed to its exact reviewed head label Aug 23, 2026
@stranske
stranske temporarily deployed to agent-high-privilege August 23, 2026 07:54 — with GitHub Actions Inactive
@stranske stranske removed the sync:delivery-ready Generated delivery is sealed to its exact reviewed head label Aug 23, 2026
Automated sync from stranske/Workflows
Template hash: 0092b4734e0c

Changes synced from sync-manifest.yml
Consumer-sync plan ID: sha256:0092b4734e0c819bde5ae812f61eb519d2cb17019e2f21dffd742e868f0e71cd
Plan scope: full
Scope base SHA: full
Source commit: ebf666f28cf9196074640203e1f8d0978189f0ad
Canary evidence JSON (base64): eyJzY2hlbWEiOiJ3b3JrZmxvd3MuY29uc3VtZXItc3luYy1jYW5hcnktZXZpZGVuY2UvdjEiLCJ2ZXJzaW9uIjoxLCJyZXN1bHRzIjpbeyJyZXBvIjoic3RyYW5za2UvVHJhdmVsLVBsYW4tUGVybWlzc2lvbiIsInBsYW5faWQiOiJzaGEyNTY6MDA5MmI0NzM0ZTBjODE5YmRlNWFlODEyZjYxZWI1MTlkMmNiMTcwMTllMmYyMWRmZmQ3NDJlODY4ZjBlNzFjZCIsInBsYW5fc2NvcGUiOiJmdWxsIiwic2NvcGVfYmFzZV9zaGEiOiIiLCJzb3VyY2VfY29tbWl0IjoiZWJmNjY2ZjI4Y2Y5MTk2MDc0NjQwMjAzZTFmOGQwOTc4MTg5ZjBhZCIsInByIjoxNDY4LCJoZWFkX3NoYSI6IjBhNTNkODljOWVjYTIyZGZkODY0ZmJlZDg1NjdhZmQwNTk2ZDA1NWQiLCJldmlkZW5jZV9zb3VyY2UiOiJvcGVuLWNhbmRpZGF0ZSIsInJlcXVpcmVkX2NoZWNrX3N0YXRlIjoic3VjY2VzcyIsImFjdGl2ZV9yZXZpZXdfdGhyZWFkX2NvdW50IjowfSx7InJlcG8iOiJzdHJhbnNrZS90cmlwLXBsYW5uZXIiLCJwbGFuX2lkIjoic2hhMjU2OjAwOTJiNDczNGUwYzgxOWJkZTVhZTgxMmY2MWViNTE5ZDJjYjE3MDE5ZTJmMjFkZmZkNzQyZTg2OGYwZTcxY2QiLCJwbGFuX3Njb3BlIjoiZnVsbCIsInNjb3BlX2Jhc2Vfc2hhIjoiIiwic291cmNlX2NvbW1pdCI6ImViZjY2NmYyOGNmOTE5NjA3NDY0MDIwM2UxZjhkMDk3ODE4OWYwYWQiLCJwciI6MTc1NywiaGVhZF9zaGEiOiIzYTZkNjNiNGZjMDU5ZGI5NTcxNzA1MDc2MmNiOGUxNTBlZGQxNmU1IiwiZXZpZGVuY2Vfc291cmNlIjoib3Blbi1jYW5kaWRhdGUiLCJyZXF1aXJlZF9jaGVja19zdGF0ZSI6InN1Y2Nlc3MiLCJhY3RpdmVfcmV2aWV3X3RocmVhZF9jb3VudCI6MH0seyJyZXBvIjoic3RyYW5za2UvUG9ydGFibGUtQWxwaGEtRXh0ZW5zaW9uLU1vZGVsIiwicGxhbl9pZCI6InNoYTI1NjowMDkyYjQ3MzRlMGM4MTliZGU1YWU4MTJmNjFlYjUxOWQyY2IxNzAxOWUyZjIxZGZmZDc0MmU4NjhmMGU3MWNkIiwicGxhbl9zY29wZSI6ImZ1bGwiLCJzY29wZV9iYXNlX3NoYSI6IiIsInNvdXJjZV9jb21taXQiOiJlYmY2NjZmMjhjZjkxOTYwNzQ2NDAyMDNlMWY4ZDA5NzgxODlmMGFkIiwicHIiOjIyMzcsImhlYWRfc2hhIjoiNTcxMGEwNGY1M2EzMjMyYjExZTYxZmU1YzY5OTE1ODE0NzYxMmJjOSIsImV2aWRlbmNlX3NvdXJjZSI6Im9wZW4tY2FuZGlkYXRlIiwicmVxdWlyZWRfY2hlY2tfc3RhdGUiOiJzdWNjZXNzIiwiYWN0aXZlX3Jldmlld190aHJlYWRfY291bnQiOjB9XX0=
@stranske
stranske force-pushed the sync/workflows-delivery branch from 9f70556 to bfb6fb1 Compare August 23, 2026 18:55
stranske added a commit that referenced this pull request Aug 23, 2026
…ate (#73)

`Backplane Conformance / emit-reference-run` has failed on every recent branch
here (4 of 4 runs). It dies at

    pip install -e .
    ERROR: ... does not appear to be a Python project: neither 'setup.py' nor
    'pyproject.toml' found.

This repo is deliberately not a distribution — 129 flat root modules, no build
backend — so an unconditional editable install cannot succeed. The job fails,
and `conformance` fails with it via `needs`, which turns the workflow's own
documented opt-in skip into a hard gate failure. The step that would have
skipped cleanly ("No emitter wired yet") was never reached.

DEDUP: not a new fix. stranske/Workflows#3201 already guarded this in
`templates/consumer-repo/.github/workflows/backplane-conformance.yml`. This
file is synced from that template (`.github/sync-manifest.yml`), and its entry
carries no `create_only`, so a future sync overwrites this copy wholesale. The
Orchestrator copy is simply stale: the open sync PR #54 was cut at 07:24, before
#3201 merged, and does not carry it.

So this adopts the upstream content rather than inventing a local variant — the
new file is byte-identical to the template (`cmp` clean), which makes the next
sync a no-op instead of a conflict.

Verified by executing the two shipped steps verbatim in this tree: no packaging
metadata -> "skipping editable install", no emitter -> "the conformance gate
will skip (opt-in)", exit 0. The old step reproduces the CI error exactly.

Scope, deliberately narrow. #3201 also guarded four sibling workflows
(agents-auto-label, agents-capability-check, agents-decompose, agents-dedup),
whose copies here are likewise stale and carry an unguarded
`pip install -e ".[langchain]"`. They are NOT touched: none has ever run in this
repo, so the defect is latent rather than active, and every workflow file
touched risks arming GitHub's suspicious-workflow hold — which costs an owner
click each. The pending sync delivers those guards without spending any.

Co-authored-by: Tim Stranske <tim@stranskemo.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
@stranske stranske added the sync:delivery-ready Generated delivery is sealed to its exact reviewed head label Aug 23, 2026
@stranske
stranske temporarily deployed to agent-high-privilege August 23, 2026 19:28 — with GitHub Actions Inactive
@stranske
stranske temporarily deployed to agent-high-privilege August 23, 2026 19:32 — with GitHub Actions Inactive
@stranske
stranske merged commit 9f59e6c into main Aug 23, 2026
146 of 151 checks passed
@stranske stranske removed the sync:delivery-staging Generated delivery is mutable and must not merge label Aug 23, 2026
@stranske
stranske deleted the sync/workflows-delivery branch August 23, 2026 19:42
stranske added a commit that referenced this pull request Aug 23, 2026
…ite statuses (#81)

A green Gate run left a RED `Gate / gate` status on PR #54, and nothing could clear it.
The summary job computed `STATE: success`, then:

    Token registry initialized with 7 tokens
    Selected token: WORKFLOWS_APP (4645 remaining, 92.9% capacity)
    POST /repos/stranske/Orchestrator/statuses/bfb6fb1... - 403
    ##[warning]Gate commit status update blocked by permissions; leaving existing status untouched.

`createTokenAwareRetry` defaults to `env: process.env`, so it collected every App and PAT
secret this job exposes and picked by remaining CAPACITY. `POST /statuses/{sha}` needs the
`statuses` scope: `GITHUB_TOKEN` has it here (the job declares `statuses: write`, and the
runner printed `Statuses: write` for both runs), the WORKFLOWS App installation does not.
So the token that posts the Gate's status was chosen by rate-limit headroom, and when the
App won, the post 403'd and `isIntegrationPermissionError` swallowed it as best-effort.

That is a latched gate. Maint 71 will not merge a sync PR without `Gate / gate = success`;
the only writer of that status is this step; and the step was refused the write — so the
stale failure outlived its evidence and waiting could not fix it. It failed toward SILENCE:
a warning inside a run whose 18 jobs were all green.

Non-deterministic by construction, which is why it looked intermittent: run 32659615306
posted fine at 18:56 and 32661355234 was refused at 19:28/19:34 with identical declared
permissions, because the balancer picked differently. Other PRs' statuses posted normally
all day.

`env: {}` pins this one call to the workflow token. Retries still apply; only the token
source is fixed. Declaring `capabilities: ['statuses:write']` would NOT have worked:
token_load_balancer aliases that to the generic `write-repo`, which all three token types
claim, so the App stays eligible. That alias is the upstream half of this defect and is
untouched here.

Also: the mypy figure was stale in six places and disagreed with itself. Measured on 24cb115
with `python3 scripts/ci_lint_baseline.py` (pinned mypy 2.3.1): 608 errors across 89 of 189
files, 19 codes, top 15 covering 603. Recorded was 604/90 in the toggle and both 604/89 and
601/89 in the baseline doc. It read 601 -> 604 -> 607 -> 608 during 2026-08-23 alone, and
nothing couples it to a measurement, so the illustrative prose that restated it ("a bare
'604 errors' reads as be-patient") is now generic — that phrasing was manufacturing the next
stale figure every time the count moved. The drift itself is recorded where the number is.

Verified: test_ci_gate_config.py 12 passed; ruff and black -l 100 clean over 196 files;
pr-00-gate.yml parses (11 jobs); collection unchanged at 416 = the recorded floor, so no
floor edit. No behaviour change outside the token source and the prose.

Co-authored-by: Tim Stranske <tim@stranskemo.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automated Automated sync from Workflows sync:delivery-ready Generated delivery is sealed to its exact reviewed head sync Automated sync from Workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant