ci(hypatia): standardise the wrapper caller id to the canonical `hypa… #71
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| # This workflow is managed by gh actions-lock. | |
| # governance.yml — single wrapper calling the shared estate governance bundle | |
| # in hyperpolymath/standards instead of carrying per-repo copies. | |
| # | |
| # Replaces the per-repo governance scaffolding removed in the same commit: | |
| # quality.yml, guix-nix-policy.yml, npm-bun-blocker.yml, ts-blocker.yml, | |
| # security-policy.yml, rsr-antipattern.yml, wellknown-enforcement.yml, | |
| # workflow-linter.yml | |
| # | |
| # Load-bearing build/security workflows stay standalone in the repo | |
| # (rust-ci, codeql, dependabot, release, scan/mirror/pages plumbing). | |
| name: Governance | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| workflow_dispatch: | |
| # A called reusable workflow cannot request MORE permissions than its caller | |
| # grants — if it does, the run is rejected before any job starts | |
| # (startup_failure, zero jobs, no check run to inspect). | |
| # | |
| # standards@0ced540e ("chore: estate-wide security compliance", 2026-07-26) | |
| # added `actions: read` to governance-reusable.yml's own permissions block. | |
| # Because this caller pins the reusable at @main rather than a SHA, that change | |
| # arrived immediately and broke Governance here. `actions: read` is mirrored | |
| # below to match. | |
| permissions: | |
| actions: read | |
| contents: read | |
| jobs: | |
| governance: | |
| uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb566cfb8a86cea2d3666bf65a4f177a49b1313 |