Skip to content

Pre-existing red checks on main (Governance/Guix+lockfile, Mirror x4, Hypatia, CodeQL startup_failure) #141

Description

@hyperpolymath

What

As of main@ccef0f7 (2026-09-30), several required-adjacent checks are already red on the default branch, independent of any specific PR:

  • governance / Guix packaging policy (Nix retired) — FAILURE
  • governance / Actions lockfile verify — FAILURE
  • mirror / mirror-disroot — FAILURE
  • mirror / mirror-bitbucket — FAILURE
  • mirror / mirror-gitea — FAILURE
  • mirror / mirror-codeberg — FAILURE
  • hypatia / Hypatia Neurosymbolic Analysis — FAILURE
  • CodeQL Security Analysis workflow — STARTUP_FAILURE (no check runs recorded)

Found while verifying that PR fix/launcher-xdg-state (predictable /tmp log path in check-language-compliance.sh, CWE-377) did not introduce new red checks: these same checks are red at the tip of main itself, so they are inherited, not caused by that PR.

Acceptance criteria

  • Each listed check either passes on main, or has a documented, owner-accepted reason it stays red (e.g. a retired mirror target, a known Guix/Nix transition item).
  • CodeQL Security Analysis's STARTUP_FAILURE is root-caused (workflow config vs. permissions vs. missing language) and either fixed or the workflow is removed if no longer applicable.
  • No PR is asked to "fix" one of these as a side effect of an unrelated change; this issue is the single place that tracks them.

Filed per estate doctrine: a new/pre-existing red check is not a merge blocker in itself, but must be tracked as an issue with acceptance criteria rather than silently ignored.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions