Repository navigation
actions-lock cliff: ENFORCE_ACTIONS_LOCK_FROM=2026-10-01 reddens 163 callers with no human action #903
Description
Activity
- addedcicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatespriority:p0Critical - drop other workCritical - drop other workscope:estateAffects many or all repos across the estateAffects many or all repos across the estatestatus:readyFully specified and ready to be picked upFully specified and ready to be picked up
on Sep 30, 2026 Status (estate issue census, 2026-09-30, read from
origin/main):- AC1 is met.
.machine_readable/lock-allow.txtexists with 163 entries — the full lockless population from the 09-22 census — landed in 4f7f02c (ci: zero-cost quality/security/coverage/mirroring pipeline, Deno ratchet, RSR seed rewrites #899).governance-reusable.ymlexempts a ledgered repo only on gate exit 3 (missing-lock debt), never on exit 1/2. - The date is still live:
scripts/check-actions-lock-gate.sh:39defaultsENFORCE_ACTIONS_LOCK_FROMto 2026-10-01. For callers pinned at or after ci: zero-cost quality/security/coverage/mirroring pipeline, Deno ratchet, RSR seed rewrites #899 the cliff therefore becomes a ledgered pass, not a red run. - ⚠ Not verified: callers pinned to a governance SHA older than ci: zero-cost quality/security/coverage/mirroring pipeline, Deno ratchet, RSR seed rewrites #899 run the old gate without the ledger path. How many such callers exist was not measured here — that is the residual exposure on 10-01.
- AC3 (move the date out of the pinned artefact) and the cutover choice remain open.
- AC1 is met.
Status 2026-09-30 ~15:45Z — 27 lock PRs merged ahead of the 2026-10-01 00:00Z enforcement date
Why merge rather than move the date: callers pin the governance reusable by SHA, so changing
ENFORCE_ACTIONS_LOCK_FROMon main reaches no caller. Committingactions.lockis the only cure that lands before midnight. No repo requires the lockfile check, so the midnight red is noise and blocks no merge.Owner-approved scope: plain
--squashmerges with--match-head-commitand no--admin, limited to PRs whose lock check passed and which added no new red (29 candidates).Merged (27). Every squash commit is signed and verifies.
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate aggregate-library#61 →
f9ee069006 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate docmatrix#80 →
0f2a72c112 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate excel-economic-numbers-tool#77 →
5068329ea7 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate explicit-trust-plane#75 →
75cc9059d6 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate ffmpeg-ffi#54 →
d944a7d605 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate formatrix-docs#62 →
33f6c998e0 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate hesiod-dns-map#98 →
3c9fa05690 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate http-capability-gateway#118 →
c5e9bedeb6 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate im-docs#74 →
7eb93ba1aa - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate intsoc-transactor#79 →
fc6c2f5d39 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate metadata-grammar#82 →
e16c55d238 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate branch-newspaper#97 →
76e3f8ab94 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate nafa-app#71 →
3dd6c62140 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate resource-record-fluctuator#85 →
dcd75fbf9d - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate ssg-collection#65 →
717727c15c - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate tree-navigator#95 →
906bacbd75 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate twingate-helm-deploy#144 →
e33957496a - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate unified-dataset-vocab#74 →
81b1c96928 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate universal-extension-format#72 →
3940ccc14a - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate universal-language-server-plugin#97 →
b0bf0d8db6 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate cccp#84 →
10c4092119 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate checky-monkey#94 →
2f6f3aaa70 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate chimichanga#101 →
66016b9463 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate cloudflare-dns-terraform#57 →
dc91dc6ba2 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate cloudguard-cli#64 →
af8b9b6378 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate cloud-sync-tuner#68 →
fcf23b7678 - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate cyo#48 →
98bb400bca
Post-merge check (15:41Z): I compared failing workflows on each merge commit against its parent on main. Zero new reds in 23 of 23 checked (the last 4 merged later). A positive control confirmed the diff detects an injected new red. Path-named failures (for example
excel-economic-numbers-toolmirror.yml,tree-navigatorcomprehensive-quality.yml) were already red before the merge. ⚠ 12–21 suites per repo were still running, so this verdict covers startup only.Held back from the 29 (2) — not bypassed
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate network-dashboard#109: CodeRabbit CHANGES_REQUESTED (🟠 Major).
actions.locklists 4 workflow paths, but 7 more active workflows are absent. Under per-workflow lock keying those 7 would be unmanaged. Regenerate, then merge. - metadatastician/bowtie-workbench#6: base-branch policy refuses the merge. main has a
CODE_SCANNING(CodeQL) rule, and the head also showsprototypeand anti-pattern reds. This is the known code_scanning deadlock and needs a ruleset decision, not--admin.
Merged despite a CodeRabbit change request — follow-up needed
Neither repo has a rule that blocks on reviews, so these landed. Neither shows a new red.
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate im-docs#74: CodeRabbit says 5
hyperpolymath/standardsreusable-workflow calls have noactions.lockentry. Verify againstgh actions-lock --verify, which is known to be blind to job-level reusables. - chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate metadata-grammar#82: the "managed by gh actions-lock" sentinel lands on line 2, after SPDX. A later
gh actions-lockwrite-mode run may add a duplicate sentinel. This is an idempotency bug in the generator, and the same shape is on all 27 merges.
Left for the campaign owner (14 problem PRs, not merged)
- hyperpolymath/achievements-lab#35 — lock=failure, new-red=governance / Actions lockfile verify (+13 more)
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate aerie#97 — lock=success, new-red=SonarQube
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate anvomidav#89 — lock=none, new-red=-
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate civic-connect#103 — lock=none, new-red=-
- hyperpolymath/contractiles-a2-lab#19 — lock=failure, new-red=governance / Actions lockfile verify (+13 more)
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate developer-ecosystem#217 — lock=none, new-red=governance / Workflow security linter
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate dicti0nary-attack#89 — lock=success, new-red=Test (3.10)|Test (3.12)
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate docudactyl#85 — lock=success, new-red=hypatia / Hypatia Neurosymbolic Analysis|Zig FFI Build & Test
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate grim-repo#91 — lock=none, new-red=governance / Workflow security linter
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate i-human#55 — lock=none, new-red=-
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate misinformation-defence-platform#82 — lock=success, new-red=governance / Guix packaging policy (Nix retired)
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate boinc-boinc#83 — lock=none, new-red=Hypatia
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate zerostep#100 — lock=success, new-red=PR (address)
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate candy-crash#102 — lock=success, new-red=Hypatia
lock=nonemeans no lockfile check ran on the head.lock=failuremeans the lockfile verify itself fails.Peer campaign (
go-rest, 28 repos) — still opening PRs51 PRs opened in total, 8 skipped because a PR was already open, 7 generation failures (polyglot-formalisms-gleam, project-wharf, sanctify-php, snapcreate, …). At least snapcreate's failure is the shared secondary REST rate limit (
listing branches for dependabot/fetch-metadata: HTTP 403), not a lockfile defect, so retry it after a cooldown rather than recording it as broken.Repos without a merged lock by 00:00Z will show a red, non-required governance check. It does not block merges.
- chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate aggregate-library#61 →
- added 14 commits that reference this issue
on Oct 1, 2026
Finding
The actions-lock cliff is dated and unsurvivable as set.
ENFORCE_ACTIONS_LOCK_FROMdefaults to 2026-10-01. Source:developer/.claude/checkpoints/2026-09-22-cicd-pipeline-delivery.md§5-1(duplicate of
developer/.claude/checkpoints/2026-09-22-pipeline-delivery-summary.md§7-12).Complete census,
gh apion default branches, 2026-09-22:actions.lockThe lockless 163 split 154 ALLPINNED / 9 UNPINNED. So arming the gate
estate-wide reddens 9 today and 163 on 2026-10-01, with no human action in
between and no merge required: all 368 callers are SHA-pinned, so merging to
standardsmainreaches nobody — but a runtime date baked into analready-distributed SHA needs no bump to fire.
Why this is the dangerous shape
A date inside a pinned artefact is the one mechanism in this estate that can change
caller behaviour with nobody in the loop. Everything else requires a deliberate pin
bump.
Acceptance criteria
.machine_readable/, registered inscripts/check-exemption-ratchet.shENFORCE_ACTIONS_LOCK_FROMis moved out of the pinned artefact into anenv/ledger input, so the date is not distributed inside a SHA
arrives first
lock debt: N callers) on every runDecision sheet: #787