Skip to content

fix(ci): security facade startup failure and ratchet-report on a new baseline - #32

Merged
CMaintz merged 1 commit into
mainfrom
fix/facade-permissions-and-ratchet
Sep 29, 2026
Merged

CMaintz merged 1 commit into
mainfrom
fix/facade-permissions-and-ratchet

Conversation

@CMaintz

@CMaintz CMaintz commented Sep 29, 2026

Copy link
Copy Markdown
Owner

Summary

Two bugs found while adopting v2.2.0 in tech-atlas (CMaintz/tech-atlas#94). Both are small workflow fixes with no interface change, so this is a patch release.

1. security.yml facade: every run ends in startup_failure

The facade's guards job calls _guards.yml without setting its own permissions, so it inherits the file-level contents: read. _guards.yml's Secret scan job asks for pull-requests: read, because gitleaks-action lists the PR's commits. A nested reusable workflow cannot ask for more than its calling job holds, so GitHub rejects the whole run before any job starts. The run shows only "This run likely failed because of a workflow file issue"; the reason is visible only in the Actions UI.

Fix: the guards job grants contents: read and pull-requests: read. The consumer's caller also has to grant these: a repo with the default read-only token has no pull-requests: read. So the usage example in security.yml, the caller that foundry-init.sh generates, and OVERVIEW §13 now include permissions: { contents: read, pull-requests: read }.

2. ratchet-report.yml fails while a baseline is not on the base yet

before=$(git show "$BASE:$f" 2>/dev/null | count) runs under set -euo pipefail. When the baseline file does not exist at the base (the PR that adopts Foundry, or bootstrap's first seed PR), git show exits 128, and pipefail + -e fail the job instead of reporting before: 0. Fix: (git show … || true) | count.

Verification

tech-atlas#94 pinned to this branch's commit (5e16845): the security run starts and runs guards and SAST (it ended in startup_failure at v2.2.0, run 36547746514), and ratchet passes (it failed with exit 128 at v2.2.0, run 36547746161).

After merge

Cut a patch release and move v2. tech-atlas#94 is pinned to 5e16845 until then; re-pin it to the release.

…baseline

security.yml: the `guards` job calls _guards.yml without its own permissions, so it
inherits the facade's file-level `contents: read`. _guards' secret-scan job asks for
`pull-requests: read` (gitleaks-action lists the PR's commits), which is more than its
calling job holds, so GitHub rejects the run before it starts (`startup_failure`, with
the reason visible only in the Actions UI). Found adopting v2.2.0 in tech-atlas. The
guards job now grants `contents: read` + `pull-requests: read`; the usage example,
foundry-init's generated caller and OVERVIEW §13 show the caller granting the same.

ratchet-report.yml: `git show "$BASE:$f"` exits 128 when the baseline is not on the
base yet (the PR adopting Foundry, or bootstrap's first seed). Under `set -euo
pipefail` that failed the job instead of reporting "before: 0".
@CMaintz
CMaintz merged commit ce67565 into main Sep 29, 2026
4 checks passed
@CMaintz
CMaintz deleted the fix/facade-permissions-and-ratchet branch September 30, 2026 12:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant