fix(ci): repair workflows that are not valid YAML and have never run - #297
Conversation
The `security-codeql` job declared `permissions:` twice:
permissions:
contents: read
permissions:
security-events: write
actions: read
contents: read
GitHub Actions rejects a workflow with duplicate keys outright — the run is
`failure` with no jobs, no log and no check run. This file has never executed.
The FIRST block is removed rather than the second, because the second is a
strict superset: it already grants `contents: read` alongside the two
permissions CodeQL actually needs to upload results. Keeping the first would
have left the job unable to write security events, so the choice is not
arbitrary — it is the only one that preserves what the job is for.
Verified: every workflow in the repository parses after the change, and the
surviving declaration is
{security-events: write, actions: read, contents: read}.
Part of an estate-wide repair: 67 repositories and 100 workflow files were
left unparseable by sweeps that edited by line position rather than by parsing.
Detection is being added upstream (hyperpolymath/standards#582) — ordinary
validation cannot see this, because yaml.safe_load silently keeps the last
duplicate and reports success.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedRemoves duplicated permissions blocks and fixes indentation errors to restore valid YAML parsing in CI workflow files. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
🔍 Hypatia Security ScanFindings: 259 issues detected
View findings[
{
"reason": "Action actions/checkout@v4.1.7 needs attention",
"type": "unpinned_action",
"file": "boj-build.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/checkout@v4.3.1 needs attention",
"type": "unpinned_action",
"file": "build.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action SonarSource/sonarqube-scan-action@v8.1.0 needs attention",
"type": "unpinned_action",
"file": "build.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/checkout@v4.1.1 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/checkout@v4.1.1 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action haskell-actions/setup@v2.7.5 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/cache@v4.3.0 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/configure-pages@v5.0.0 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/upload-pages-artifact@v3.0.1 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
},
{
"reason": "Action actions/deploy-pages@v4.0.5 needs attention",
"type": "unpinned_action",
"file": "casket-pages.yml",
"action": "pin_sha",
"rule_module": "workflow_audit",
"severity": "medium"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
These workflow files are not valid YAML, so they have never run. Not "ran and failed" — never ran. GitHub Actions rejects the file before creating any job: the run is recorded as
failurewith no jobs, no log and no check run, andgh pr checksshows no row at all. A red mark with nothing behind it to read.Cause
A sweep added permission declarations by line position rather than by parsing the document. Three invalid shapes resulted:
A — a mapping indented under a scalar value
read-allalready grants everythingactions: readwould, so the orphaned line is dropped and nothing is lost.B — injected inside another block
C — a literal
\nthat was never interpreted, gluing the escape'snto the key:Only a text-level writer emitting an uninterpreted escape can produce that.
Verified, not assumed
Every workflow in this repository parses after the change. The repairer refuses to write any file that does not parse and still contain jobs afterwards.
Where a job-level
permissions:line was removed, a read-only top-levelpermissions:remains, so nothing is widened — and if none would remain, the tool reports that rather than inventing one. Guessing a permission set is how you silently over-grant.Estate context
67 repositories and 100 workflow files are in this state. The most frequently broken file is
workflow-linter.yml, in 22 repositories — followed byscorecard.yml(20) anddogfood-gate.yml(13).The workflow whose job is to lint workflows was itself unparseable, so it never ran, and never caught this or anything else. The check that would have found the damage was destroyed by the same sweep that caused it.
So it cannot recur invisibly
Detection is being added upstream: a strict-YAML check in the governance reusable — hyperpolymath/standards#582. Ordinary validation cannot see this class of fault, because
yaml.safe_loadsilently accepts duplicate keys and only a full parse catches the malformed indentation.Expect this repository to get louder
Workflows that have been failing silently will now actually run, and some will find real problems that have been invisible for as long as the files have been broken.
🤖 Generated with Claude Code