Temporary diagnostic: runner image node:20-bullseye lacks python3 (kills run 461 at step 2). This PR only exists to get a log from the new probe.yml. DO NOT MERGE — delete after one run.
Temporary diagnostic: runner image node:20-bullseye lacks python3 (kills run 461 at step 2). This PR only exists to get a log from the new probe.yml. **DO NOT MERGE — delete after one run.**
Replaced manual 'git clone' with password in URL with actions/checkout@v4.
Runner already auto-checkouts the repo - manual clone was redundant.
Also fixed YAML syntax issues in Config validation and No secrets check steps.
Credentials were exposed in git history since initial commit.
(cherry picked from commit aeb79c6286)
The truncation notice '[...truncated at Zulip limit]' was appended AFTER
slicing at MAX_ZULIP_MESSAGE (10000), causing the final message to exceed
Zulip's API limit. This fix subtracts the notice length from the slice so
the total stays within bounds.
(cherry picked from commit 19c52a9425)
Completes aeb79c6 (main): four more clone steps in deploy.yml still
embedded abiba-bot HTTP Basic credentials in plaintext. Runner already
auto-checkouts the repo, so the manual clone was redundant — replaced
with actions/checkout@v4, same pattern as ci.yml.
No secrets remain in tracked workflow files after this change.
Dynamic resolution (ADR-006) overrides this on connect, but when the
/api/v1/users call fails the adapter fell back to 1, silently dropping
every @all-bots mention. The realm's all-bots user is 20 (verified
2026-09-25: 'Resolved @all-bots user_id=20 from all-bots@chat.sysloggh.net';
CONTRACT_VERIFICATION_2026-06-29 fixed the Pi config to 20 for the same
reason). Align the Hermes-side fallback with the verified realm value.
ci.yml has been invalid YAML since introduction: the 'Config validation'
and old inline checks dedented out of their run:| block scalar, so Gitea
could never parse the workflow — CI never ran on any PR despite
CI_STATUS.md claiming 'Active'. The old 'No secrets check' also always
passed (|| echo swallows the grep hit) and never scanned *.yml — where
six embedded credentials were living.
- validation logic moved to ci_check.py (testable locally: python3 ci_check.py all)
- secrets check now FAILS on embedded http-basic URLs and long api_keys,
across .py/.ts/.yaml/.yml/.cjs/.sh, with placeholder allowlist
- added workflow-YAML parse gate so this class of breakage can't recur
- py_compile steps no longer swallow errors with '|| echo skipped'
- removed ci.yml's duplicate deploy job: deploy.yml is the sole deploy
pipeline (rc tags → Tanko canary only; stable → all agents). The ci.yml
copy would have deployed Mumuni on rc tags too, breaking canary policy,
and never ran anyway.
- CI_STATUS.md rewritten with the real state + caveats (history still
contains the old creds — rotation is a server-side task)
Closed — served its purpose. The probe proved the act container is alpine (apt-get absent, exit 127) and that checkout@v4 works. Real fix landed on PR #35 commit 52c41ca (apk-based python3 provisioning); validate run 468 is green.
Closed — served its purpose. The probe proved the act container is alpine (apt-get absent, exit 127) and that checkout@v4 works. Real fix landed on PR #35 commit 52c41ca (apk-based python3 provisioning); validate run 468 is green.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Temporary diagnostic: runner image node:20-bullseye lacks python3 (kills run 461 at step 2). This PR only exists to get a log from the new probe.yml. DO NOT MERGE — delete after one run.
Closed — served its purpose. The probe proved the act container is alpine (apt-get absent, exit 127) and that checkout@v4 works. Real fix landed on PR #35 commit
52c41ca(apk-based python3 provisioning); validate run 468 is green.Pull request closed