5 Commits
Author SHA1 Message Date
Mumuni 52c41ca8fb fix(ci): install python3 via apk — act job container is alpine, not debian
CI / validate (pull_request) Successful in 14s
Run 467 log (job 1985): 'python3 missing — installing on alpine' then
'apt-get: command not found' → exit 127. The act_runner container is
node:20-alpine-ish; the provisioning step now detects apk first, apt
second, and fails loudly with a diagnostic if neither exists.
2026-09-25 19:39:36 +00:00
MumuniandClaude Opus 5 f477a6a252 fix(ci): install python3+PyYAML in the job when the runner image lacks them
CI / validate (pull_request) Failing after 5s
Runner probe on PR #35 (run 461, log job 1979): checkout@v4 succeeds (network
fine) but the act container has node:20 + git 2.52 and NO python3 — 'python3
--version' exited 127, which was the failing check. Every validation step is
python3-based, so make step 2 self-provisioning via apt when missing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-25 19:20:23 +00:00
Mumuni 9edc258245 fix(ci): make the validate job actually able to run — it never had
CI / validate (pull_request) Failing after 14s
ci.yml has been invalid YAML since introduction: the 'Config validation'
and old inline checks dedented out of their run:| block scalar, so Gitea
could never parse the workflow — CI never ran on any PR despite
CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always
passed (|| echo swallows the grep hit) and never scanned *.yml — where
six embedded credentials were living.

- validation logic moved to ci_check.py (testable locally: python3 ci_check.py all)
- secrets check now FAILS on embedded http-basic URLs and long api_keys,
  across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist
- added workflow-YAML parse gate so this class of breakage can't recur
- py_compile steps no longer swallow errors with '|| echo skipped'
- removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy
  pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml
  copy would have deployed Mumuni on rc tags too, breaking canary policy,
  and never ran anyway.
- CI_STATUS.md rewritten with the real state + caveats (history still
  contains the old creds — rotation is a server-side task)
2026-09-25 15:50:16 +00:00
Mumuni fb752be8c9 fix(zulip): @all-bots fallback default was user_id=1 — never valid in SyslogGH realm
Dynamic resolution (ADR-006) overrides this on connect, but when the
/api/v1/users call fails the adapter fell back to 1, silently dropping
every @all-bots mention. The realm's all-bots user is 20 (verified
2026-09-25: 'Resolved @all-bots user_id=20 from all-bots@chat.sysloggh.net';
CONTRACT_VERIFICATION_2026-06-29 fixed the Pi config to 20 for the same
reason). Align the Hermes-side fallback with the verified realm value.
2026-09-25 15:31:28 +00:00
Mumuni f0f82d904b security: remove hardcoded abiba-bot credentials from deploy workflow
Completes aeb79c6 (main): four more clone steps in deploy.yml still
embedded abiba-bot HTTP Basic credentials in plaintext. Runner already
auto-checkouts the repo, so the manual clone was redundant — replaced
with actions/checkout@v4, same pattern as ci.yml.

No secrets remain in tracked workflow files after this change.
2026-09-25 15:28:58 +00:00