Skip to content

[Fleet incident] Disable orphaned release, PR repair, and hourly-loop workflow identities #38

Description

@seonghobae

Live Actions registry drift

The repository's Actions API currently reports 30 workflow identities. Numerous historical release-update, PR-specific repair, dependency-lock, sandbox, patch, and one-shot hourly-loop records remain in state: active, including examples such as:

Fresh protected-main contents lookup returns 404 Not Found for sampled active path .github/workflows/apply-hourly-loop-repair.yml. The source is absent, but GitHub still advertises the workflow identity as active.

The supported ci, Create RankWeave Release, and current hourly-commercialization-loop.yml workflow must be preserved. Issue #37 and PR #36 separately track the live hourly startup/reusable-workflow contract; this lifecycle issue does not duplicate or weaken that repair.

Root cause

Temporary release and PR-repair workflows were removed from the protected-main tree after their bounded use, while their independent GitHub Actions registry records were not disabled. File deletion was treated as complete workflow lifecycle cleanup. Current tree-level tests cannot detect orphaned control-plane identities after source removal.

Realistic remediation

Do not restore historical YAML and do not create another self-deleting cleanup workflow. Under RankWeave's normal owner/operations path:

  1. paginate the complete Actions registry;
  2. bind evidence to the exact protected-main SHA and tree;
  3. classify present repository workflows, active orphan records, disabled records, GitHub-owned dynamic workflows, intentionally pending supported integrations, and unresolved records;
  4. refetch exact branch/workflow state immediately before mutation;
  5. disable active orphan repository-path identities through an authorized operator or normal reviewed control-plane action;
  6. preserve all current supported CI/release/hourly workflows;
  7. retain immutable before/after evidence.

Coordinate with central lifecycle issue ContextualWisdomLab/.github#945 and AppGuardrail detector issue ContextualWisdomLab/appguardrail#929. Do not introduce another PAT, COPILOT_GITHUB_TOKEN, broad secrets: inherit, or workflow-disable authority into an untrusted scanner.

Acceptance criteria

  • complete paginated inventory and exact protected-main binding;
  • every reviewed active repository-path workflow absent from protected main disabled or explicitly justified;
  • no current CI/release/hourly workflow disabled through name-only matching;
  • no historical release/PR-repair source reintroduced;
  • read-only recurrence detector emits workflow ID, path, state, default-branch SHA, observation time, and pagination receipts;
  • adversarial tests cover pagination truncation, permission loss, transient 403/404/5xx, branch movement, path case/encoding, renamed/reused workflow IDs, GitHub dynamic workflows, and a currently present bounded repair still owned by an active PR;
  • exact-head CI/security/review gates;
  • normal protected-main integration;
  • post-remediation live inventory proves orphan identities disabled while the supported release and hourly paths remain operational;
  • final hourly acceptance remains coordinated with [Fleet incident] Remove credential-first and broad secret inheritance from hourly loop #37/fix(ci): restore executable hourly governance #36 and the central coverage/bootstrap owner fixes rather than bypassed.

This issue belongs to the organization-wide Hourly Product Development fleet incident.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions