Skip to content

Governance/Hypatia hygiene: stale GEMINI.md, unpinned action, workflow timeouts, shellcheck #218

@hyperpolymath

Description

@hyperpolymath

Pre-existing Hypatia baseline findings (272 total; non-blocking — the Validate Hypatia baseline check passes) in boj-server. Mechanical cleanup, surfaced during the required-gate skip-shim work (#216) and deliberately left out of scope there.

Items

  • Delete stale GEMINI.md (root_hygiene / stale) — leftover AI-session file.
  • Pin the unpinned action in governance.yml to a commit SHA (estate action-pinning policy).
  • missing_timeout_minutes — add timeout-minutes to jobs lacking it: abi-drift.yml (the verify job), codeql.yml, container-publish.yml, dogfood-gate.yml (6 jobs), and the heavy test job in zig-test.yml.
  • Pre-existing shellcheck infos (from actionlint): abi-drift.yml (SC2046/SC2012/SC2086 in the emit/verify loop) and zig-test.yml (SC2012/SC2046 in the scope/test steps) — quote / find-ify as appropriate.

Done-when

  • actionlint clean on the touched workflows.
  • A fresh Hypatia scan no longer reports these items.

https://claude.ai/code/session_019tMcRS1Dm1nWjjYP4WvbJa

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions