ci: drop embedded Python YAML parsing; gate inline Python - #1119
Merged
Merged
Conversation
Python is banned estate-wide, yet every Python detector matches `*.py` only, so Python embedded in workflows, scripts and justfiles was invisible. The governance reusable's R5 gate parsed YAML with a `python3 - <<'PY'` heredoc importing PyYAML, against YAML-POLICY Y-1 (read YAML with yq). - governance-reusable.yml R5: ported to bash + yq + jq. Known-answer equality: the old Python step and the new step produce byte-identical output and exit codes on five fixture trees (no dir, empty dir, clean rule, and a mixed tree with hits, a non-mapping, missing patterns, a bad regex, an id-less rule, a numeric id, self-references, changelogs and a missing include). An unparseable rule file now prints one counted R5 error instead of a Python traceback; both exit 1. - tests/test_secret_scanner_canary.sh: step extraction via yq; the extracted script is byte-identical to the Python one, and a reusable without the step still fails the canary. - self-test.yml: drop `pip install pyyaml`. - justfile.template: `python3 -c json.dumps` -> `jq -Rs .` (identical encoding on quotes, backslashes, tabs, ESC and newlines); REGISTRY.a2ml regenerated for the RSR source hash. - scripts/check-inline-python.sh: flags python[3] -c/-m/-/<</x.py, <<'PY' heredocs and pip install on non-comment lines of *.yml, *.yaml, *.sh, *.template, Justfile/justfile, Containerfile. Remaining debt is the shrink-only ledger .machine_readable/inline-python-allow.txt (12 files, 19 lines); a new path, a grown count or a stale entry fails. - scripts/tests/check-inline-python-test.sh: 24 cases incl. two killed mutants and an exact-ledger check of this repo; discovered by run-shell-test-suite.sh. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 53 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
enabled auto-merge (squash)
October 1, 2026 22:24
hyperpolymath
added a commit
that referenced
this pull request
Oct 1, 2026
…ate (#1121) Follow-up to #1120. It clears the two remaining reds on `main`. **Validate Hypatia Baseline (red on main):** - hypatia#895 maps severity `warn` to `medium`. Since then, the 20 RE001/RE005 acknowledgements in `.hypatia-baseline.json` (recorded as `warn`) no longer match, so every caller whose baseline has `warn` entries breaks. - `scripts/apply-baseline.sh` now treats `warn` and `medium` as one tier. - Measured on the failing run's 20 kept findings: 20 suppressed, 0 kept. - New tests: warn↔medium matches in both directions, and a different tier stays unmatched. Main's matcher fails both new positive cases (mutant). - The governance-reusable baseline job also floated on hypatia HEAD. It now pins through a `hypatia-ref` input (default `51ab6496`). `HEAD` remains accepted as an explicit opt-in for canaries. **Repo self-tests (red on main):** - The lock gate staged standards at a hardcoded third pin (`5f82b635`). That pin was one change behind by construction and went stale again with #1119. - It now stages at `${{ job.workflow_sha }}`, the reusable's own commit, which is exactly what the caller pinned. - `check-lock-gate-pin-freshness.sh` and both contract tests accept that expression. They still refuse `github.workflow_sha`/`github.sha`, which name the caller's commit (planted negatives: all three guards go red). **Package policy:** a caller pinned before the capability resolver existed now gets a warning and is treated as undeclared, instead of failing. Local: `run-shell-test-suite.sh`, all 69 files pass. `docstring-scan --check` passes. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Python is banned estate-wide, but every Python detector matches
*.pyonly. Python embedded in workflows, scripts and justfiles was invisible, and that is how the governance reusable's R5 gate came to parse YAML with apython3 - <<'PY'/import yamlheredoc, against YAML-POLICY Y-1 (read YAML with yq).This PR removes that heredoc and the canary's Python YAML parser, and adds a gate so embedded Python cannot come back unseen.
governance-reusable.ymlR5 → bash +yq -o json+jq❌ [R5]error instead of a Python traceback; both exit 1.tests/test_secret_scanner_canary.shextraction →yq::error::canary: could not extract…, rc 1).self-test.ymlpip install pyyaml; yq is preinstalled onubuntu-latest.justfile.templatepython3 -c json.dumps→jq -Rs .REGISTRY.a2mlregenerated (RSRsource_hash).scripts/check-inline-python.shpython[3] -c,-m,-(stdin),<<,x.py,<<'PY'heredocs andpip[3] installon non-comment lines of*.yml *.yaml *.sh *.template Justfile justfile Containerfile..machine_readable/inline-python-allow.txtscripts/tests/check-inline-python-test.sh(100755)-cform removed), and an exact-ledger check of this repo. Discovered byrun-shell-test-suite.sh, so it runs in Repo self-tests.-mand barepython3 <<go beyond the originally scoped list. A broad sweep surfacedpython3 -m json.tool/-m http.server, which execute Python just the same. The.a2mlscorecardcheck =strings and.githooks/post-checkout(only anecho) are outside the gate's file set. That is a known horizon, not a claim of zero.Pin lines 417/1248/1355 of
governance-reusable.ymlare untouched. Local: full shell suite 67/67, docstring scan 100% (10/10).🤖 Generated with Claude Code
https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS