Skip to content

Governance/Hypatia hygiene: stale GEMINI.md, unpinned action, workflow timeouts, shellcheck #218

Description

@hyperpolymath

Pre-existing Hypatia baseline findings (272 total; non-blocking — the Validate Hypatia baseline check passes) in boj-server. Mechanical cleanup, surfaced during the required-gate skip-shim work (#216) and deliberately left out of scope there.

Items

  • Delete stale GEMINI.md (root_hygiene / stale) — leftover AI-session file.
  • Pin the unpinned action in governance.yml to a commit SHA (estate action-pinning policy).
  • missing_timeout_minutes — add timeout-minutes to jobs lacking it: abi-drift.yml (the verify job), codeql.yml, container-publish.yml, dogfood-gate.yml (6 jobs), and the heavy test job in zig-test.yml.
  • Pre-existing shellcheck infos (from actionlint): abi-drift.yml (SC2046/SC2012/SC2086 in the emit/verify loop) and zig-test.yml (SC2012/SC2046 in the scope/test steps) — quote / find-ify as appropriate.

Done-when

  • actionlint clean on the touched workflows.
  • A fresh Hypatia scan no longer reports these items.

https://claude.ai/code/session_019tMcRS1Dm1nWjjYP4WvbJa

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    automationBots, schedulers, dispatch, self-healing, fan-outcicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementtech-debtKnown shortcut, drift, or hygiene owed - includes cleanup

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions