From 9ae920b06b8342af47b1869715e558323299c1ee Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 9 Sep 2026 02:18:54 +0100 Subject: [PATCH 1/2] fix(ci): pin standards reusables to main HEAD 8f2ee508 This repo's standards reusable pins are re-pointed at the standards default-branch HEAD, resolved live at sweep time. The prior refs are recorded in the verification line below. Three kinds of drift are repaired together and the body does not claim which one this repo had: an UNREACHABLE sha kills the run at workflow STARTUP, so GitHub reports no check at all rather than a failing one and the gate disappears instead of going red; a FLOATING ref (@main) is unpinned supply chain; a merely STALE but reachable sha silently reintroduces every bug fixed since it. files=5 pins=5 perms=0 permlines=0 from=257869d3061d5a8ed1529bf34225d90a2416d51a,fad242d35291de1898242d6737ba02b74a59a2f2 target=8f2ee508 Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_0178nN4Nm3neFRy5K9StZKnB --- .github/workflows/elixir-ci.yml | 2 +- .github/workflows/governance.yml | 2 +- .github/workflows/mirror.yml | 2 +- .github/workflows/scorecard.yml | 2 +- .github/workflows/secret-scanner.yml | 2 +- 5 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/elixir-ci.yml b/.github/workflows/elixir-ci.yml index a6e1bb6..dae1197 100644 --- a/.github/workflows/elixir-ci.yml +++ b/.github/workflows/elixir-ci.yml @@ -20,7 +20,7 @@ permissions: jobs: elixir-ci: - uses: hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a + uses: hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@8f2ee50841e216cd8c192eeb68953118190f105c with: otp-version: "27.2.1" elixir-version: "1.18.2" diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 026822a..5922883 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -32,4 +32,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fad242d35291de1898242d6737ba02b74a59a2f2 + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@8f2ee50841e216cd8c192eeb68953118190f105c diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 9bce625..cde47d6 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -12,5 +12,5 @@ permissions: jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@8f2ee50841e216cd8c192eeb68953118190f105c secrets: inherit diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index d05b79e..ba41df0 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -20,5 +20,5 @@ jobs: contents: read security-events: write id-token: write - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@8f2ee50841e216cd8c192eeb68953118190f105c secrets: inherit diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 043df99..5dc5595 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -19,5 +19,5 @@ jobs: permissions: actions: read contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@257869d3061d5a8ed1529bf34225d90a2416d51a + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@8f2ee50841e216cd8c192eeb68953118190f105c secrets: inherit From 3227c04a2f4380e7e437acf48a62a9de86407da8 Mon Sep 17 00:00:00 2001 From: "coderabbitai[bot]" <136622811+coderabbitai[bot]@users.noreply.github.com> Date: Wed, 9 Sep 2026 09:30:14 +0000 Subject: [PATCH 2/2] Add metadata and structured suppressions to ASSAIL classifications --- audits/assail-classifications.a2ml | 77 ++++++++++++++++-------------- 1 file changed, 41 insertions(+), 36 deletions(-) diff --git a/audits/assail-classifications.a2ml b/audits/assail-classifications.a2ml index 458a29a..e805c50 100644 --- a/audits/assail-classifications.a2ml +++ b/audits/assail-classifications.a2ml @@ -1,37 +1,42 @@ %A2ML -- suppression: - file: 'assets/js/hooks/prompt_radar_hook.js' - rule: 'DynamicCodeExecution' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'assets/js/hooks/evidence_graph_hook.js' - rule: 'DynamicCodeExecution' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'assets/js/hooks/timeline_hook.js' - rule: 'DynamicCodeExecution' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'config/test.exs' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'config/dev.exs' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'test/evidence_graph/accounts_test.exs' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'lib/evidence_graph/zotero/client.ex' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'lib/evidence_graph/accounts.ex' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' -- suppression: - file: 'lib/evidence_graph/lithoglyph/client.ex' - rule: 'HardcodedSecret' - justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' +# SPDX-License-Identifier: MPL-2.0 +name: 'assail-classifications' +project: 'bofig' +version: '1.0.0' +suppressions: + - suppression: + file: 'assets/js/hooks/prompt_radar_hook.js' + rule: 'DynamicCodeExecution' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'assets/js/hooks/evidence_graph_hook.js' + rule: 'DynamicCodeExecution' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'assets/js/hooks/timeline_hook.js' + rule: 'DynamicCodeExecution' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'config/test.exs' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'config/dev.exs' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'test/evidence_graph/accounts_test.exs' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'lib/evidence_graph/zotero/client.ex' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'lib/evidence_graph/accounts.ex' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).' + - suppression: + file: 'lib/evidence_graph/lithoglyph/client.ex' + rule: 'HardcodedSecret' + justification: 'Automated estate triage: reviewed as safe within its architectural boundary (e.g. local tooling, bounded reads, expected metaprogramming).'