Skip to content

fix(ci): repair workflows made unparseable by a blind permissions insertion - #32

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/unparseable-workflows
Aug 6, 2026
Merged

fix(ci): repair workflows made unparseable by a blind permissions insertion#32
hyperpolymath merged 1 commit into
mainfrom
fix/unparseable-workflows

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

These workflow files are not valid YAML, so they have never run. Not "ran and failed" — never ran. GitHub Actions rejects the file before creating any job: the run is recorded as failure with no jobs, no log and no check run, and gh pr checks shows no row at all. A red mark with nothing behind it to read.

Cause

A sweep added permission declarations by line position rather than by parsing the document. Three invalid shapes resulted:

A — a mapping indented under a scalar value

permissions: read-all
  actions: read        # read-all is a SCALAR; it cannot take children

read-all already grants everything actions: read would, so the orphaned line is dropped and nothing is lost.

B — injected inside another block

on:
  permissions: contents: read     # two colons, and illegal under `on:` anyway
  push:

C — a literal \n that was never interpreted, gluing the escape's n to the key:

    runs-on: ubuntu-latest
npermissions:                     # "\npermissions:" written literally

Only a text-level writer emitting an uninterpreted escape can produce that.

Verified, not assumed

Every workflow in this repository parses after the change. The repairer refuses to write any file that does not parse and still contain jobs afterwards.

Where a job-level permissions: line was removed, a read-only top-level permissions: remains, so nothing is widened — and if none would remain, the tool reports that rather than inventing one. Guessing a permission set is how you silently over-grant.

Estate context

67 repositories and 100 workflow files are in this state. The most frequently broken file is workflow-linter.yml, in 22 repositories — followed by scorecard.yml (20) and dogfood-gate.yml (13).

The workflow whose job is to lint workflows was itself unparseable, so it never ran, and never caught this or anything else. The check that would have found the damage was destroyed by the same sweep that caused it.

So it cannot recur invisibly

Detection is being added upstream: a strict-YAML check in the governance reusable — hyperpolymath/standards#582. Ordinary validation cannot see this class of fault, because yaml.safe_load silently accepts duplicate keys and only a full parse catches the malformed indentation.

Expect this repository to get louder

Workflows that have been failing silently will now actually run, and some will find real problems that have been invisible for as long as the files have been broken.

🤖 Generated with Claude Code

…ertion

These workflow files are not valid YAML, so they have NEVER run. GitHub
Actions rejects the file before creating any job: the run is recorded as
`failure` with no jobs, no log and no check run, and `gh pr checks` shows no
row at all. A red mark with nothing behind it to read.

The cause is a sweep that added permission declarations by LINE POSITION
rather than by parsing the document. Two invalid shapes resulted.

  permissions: read-all
    actions: read            <- a mapping indented under a SCALAR value

`read-all` is a scalar and cannot take children. It also already grants
everything `actions: read` would, so the orphaned line is dropped and nothing
is lost.

  on:
    permissions: contents: read     <- two colons on one line, and
    push:                              `permissions` is not a valid key here

Dropped entirely.

VERIFIED, not assumed. Every workflow in this repository parses after the
change, and the repairer refuses to write any file that does not parse and
still contain jobs afterwards. Where a job-level permissions line was removed,
a top-level `permissions:` remains and is read-only, so nothing is widened —
and if none remained the tool reports that rather than inventing one, because
guessing a permission set is how you silently over-grant.

ESTATE CONTEXT: 67 repositories and 100 workflow files are in this state.
The most frequently broken file is workflow-linter.yml, in 22 repositories —
the workflow whose job is to lint workflows was itself unparseable, so it
never ran and never caught this.

Detection is being added upstream so it cannot recur invisibly: a strict YAML
loader in the governance reusable (hyperpolymath/standards#582). Ordinary
validation cannot see this class of fault, because yaml.safe_load accepts
duplicate keys and only a full parse catches the malformed indentation.

EXPECT THIS REPOSITORY TO GET LOUDER. Workflows that have been failing
silently will now actually run, and some will find real problems.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@gitar-bot

gitar-bot Bot commented Aug 6, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Repairs YAML syntax errors in GitHub Actions workflow files caused by malformed permissions insertions. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Important

Your trial ends in 4 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot

gitar-bot Bot commented Aug 6, 2026

Copy link
Copy Markdown

⚠️ Gitar auto-approved this PR but could not enable auto-merge: auto-merge is disabled for this repository — enable "Allow auto-merge" in the repository settings.

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Aug 6, 2026
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 62 issues detected

Severity Count
🔴 Critical 1
🟠 High 22
🟡 Medium 39

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "codeql.yml lists `language: javascript-typescript` but the repo has no source files in any CodeQL-scannable language. The analyze job will exit 'no source files' on every run. Switch the matrix to `actions` (which scans workflow files — every repo has those).",
    "type": "codeql_language_matrix_mismatch",
    "file": "codeql.yml",
    "action": "switch_codeql_matrix_to_actions",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dependabot-automerge.yml",
    "type": "missing_timeout_minutes",
    "file": "dependabot-automerge.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit f76a7b0 into main Aug 6, 2026
24 of 25 checks passed
@hyperpolymath
hyperpolymath deleted the fix/unparseable-workflows branch August 6, 2026 04:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant