Skip to content

chore(dependabot): cap open pull requests per update block - #69

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/dependabot-pr-caps-2026-09-08
Sep 12, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/dependabot-pr-caps-2026-09-08

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds open-pull-requests-limit to Dependabot update blocks that had no cap, following the estate per-ecosystem cap doctrine (task #37). No other line in the file is touched.

Claude-Session: https://claude.ai/code/session_011eQ7hibx92N7fBDtwgReWk

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

Adds `open-pull-requests-limit` to Dependabot update blocks that had no
cap, following the estate per-ecosystem cap doctrine (task #37).
No other line in the file is touched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011eQ7hibx92N7fBDtwgReWk
@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b78853f1-dad8-4b39-ab83-69ec6117efca

📥 Commits

Reviewing files that changed from the base of the PR and between d5c0de9 and aa69149.

📒 Files selected for processing (1)
  • .github/dependabot.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (3)
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: Analyze (javascript-typescript)
  • GitHub Check: Analyze (javascript-typescript)
⚠️ CI failures not shown inline (16)

GitHub Actions: ReScript/Deno CI / 0_build.txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m **Containment**: Air-gap for most sensitive data�[0m
 435�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Check qube states (nothing unexpected running)�[0m
 439�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Check qube states (nothing unexpected running)�[0m
 436�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Review qrexec policy prompts�[0m
 440�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Review qrexec policy prompts�[0m
 437�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Verify vault has no network�[0m
 441�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Verify vault has no network�[0m
 441�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Update templates�[0m
 445�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Update templates�[0m
 442�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Review logs for anomalies�[0m
 446�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Review logs for anomalies�[0m
 443�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Test backups�[0m
 447�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Test backups�[0m
 444�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Check firewall rules�[0m
 448�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Check firewall rules�[0m
 448�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Full security audit�[0m
 452�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Full security audit�[0m...

GitHub Actions: ReScript/Deno CI / build: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m **Containment**: Air-gap for most sensitive data�[0m
 435�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Check qube states (nothing unexpected running)�[0m
 439�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Check qube states (nothing unexpected running)�[0m
 436�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Review qrexec policy prompts�[0m
 440�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Review qrexec policy prompts�[0m
 437�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Verify vault has no network�[0m
 441�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Verify vault has no network�[0m
 441�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Update templates�[0m
 445�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Update templates�[0m
 442�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Review logs for anomalies�[0m
 446�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Review logs for anomalies�[0m
 443�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Test backups�[0m
 447�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Test backups�[0m
 444�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Check firewall rules�[0m
 448�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Check firewall rules�[0m
 448�[0m�[38;5;245m |�[0m �[0m�[1m�[31m-�[0m�[0m�[31m�[0m�[0m�[37m�[41m*�[0m�[0m�[31m [ ] Full security audit�[0m
 452�[0m�[38;5;245m |�[0m �[0m�[1m�[32m+�[0m�[0m�[32m�[0m�[0m�[30m�[42m-�[0m�[0m�[32m [ ] Full security audit�[0m...

GitHub Actions: Governance / 1_governance _ Guix packaging policy (Nix retired).txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run # Move the checker OUT of the scanned tree and delete the standards
 �[36;1m# Move the checker OUT of the scanned tree and delete the standards�[0m
 �[36;1m# checkout before scanning: the gate walks the whole caller tree, so�[0m
 �[36;1m# a packaging file shipped inside .standards-checkout/ would satisfy�[0m
 �[36;1m# the policy on the caller's behalf (same trap as the baseline job).�[0m
 �[36;1mcp .standards-checkout/scripts/check-package-policy.sh "$RUNNER_TEMP/"�[0m
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-package-policy.sh" .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ##[error]Package policy violation: no packaging found.

GitHub Actions: Governance / governance _ Guix packaging policy (Nix retired): chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run # Move the checker OUT of the scanned tree and delete the standards
 �[36;1m# Move the checker OUT of the scanned tree and delete the standards�[0m
 �[36;1m# checkout before scanning: the gate walks the whole caller tree, so�[0m
 �[36;1m# a packaging file shipped inside .standards-checkout/ would satisfy�[0m
 �[36;1m# the policy on the caller's behalf (same trap as the baseline job).�[0m
 �[36;1mcp .standards-checkout/scripts/check-package-policy.sh "$RUNNER_TEMP/"�[0m
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-package-policy.sh" .�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ##[error]Package policy violation: no packaging found.

GitHub Actions: Governance / 4_governance _ Allowlist Preflight.txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run rm -rf .standards-checkout
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-actions-policy.sh" \�[0m
 �[36;1m  "$GITHUB_REPOSITORY" "$RUNNER_TEMP/allowed-actions.json"�[0m
 shell: /usr/bin/bash -e {0}
 env:
   GH_***REDACTED_SECRET_ASSIGNMENT***
 gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variable. Example:
   env:
     GH_***REDACTED_SECRET_ASSIGNMENT*** github.token }}
 ERROR: could not read live Actions permissions for hyperpolymath/qubes-sdp
 ##[error]Process completed with exit code 3.

GitHub Actions: Governance / governance _ Allowlist Preflight: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run rm -rf .standards-checkout
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-actions-policy.sh" \�[0m
 �[36;1m  "$GITHUB_REPOSITORY" "$RUNNER_TEMP/allowed-actions.json"�[0m
 shell: /usr/bin/bash -e {0}
 env:
   GH_***REDACTED_SECRET_ASSIGNMENT***
 gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variable. Example:
   env:
     GH_***REDACTED_SECRET_ASSIGNMENT*** github.token }}
 ERROR: could not read live Actions permissions for hyperpolymath/qubes-sdp
 ##[error]Process completed with exit code 3.

GitHub Actions: Governance / 5_governance _ Security policy checks.txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / governance _ Security policy checks: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / 6_governance _ Well-Known (RFC 9116 + RSR).txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run MIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)
 �[36;1mMIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)�[0m
 �[36;1mif [ -n "$MIXED" ]; then�[0m
 �[36;1m  echo "::error::Mixed content (HTTP in HTML)"�[0m

GitHub Actions: Governance / 7_governance _ Code quality + docs.txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / governance _ Code quality + docs: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / 10_governance _ Workflow security linter.txt: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1mSCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m# Self-hosting fallback: when THIS repository is standards, its own�[0m
 �[36;1m# working tree already holds the script, and during a rename that copy�[0m
 �[36;1m# is the only correct one — the pinned main checkout still has the old�[0m
 �[36;1m# name. Preferring the fetched copy keeps every other caller on the�[0m
 �[36;1m# canonical version.�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f scripts/check-workflow-duplicate-keys.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / governance _ Workflow security linter: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1mSCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m# Self-hosting fallback: when THIS repository is standards, its own�[0m
 �[36;1m# working tree already holds the script, and during a rename that copy�[0m
 �[36;1m# is the only correct one — the pinned main checkout still has the old�[0m
 �[36;1m# name. Preferring the fetched copy keeps every other caller on the�[0m
 �[36;1m# canonical version.�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f scripts/check-workflow-duplicate-keys.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / governance _ Workflow security linter: chore(dependabot): cap open pull requests per update block

Conclusion: failure

View job details

##[group]Run if [ -f .github/workflows/actions.lock ]; then
 �[36;1mif [ -f .github/workflows/actions.lock ]; then�[0m
 �[36;1m  # The lockfile records transitive dependency evidence, while direct�[0m
 �[36;1m  # workflow references remain visibly SHA-pinned. Keep both layers:�[0m
 �[36;1m  # external analysers and GitHub's sha_pinning_required setting do�[0m
 �[36;1m  # not infer direct pins from actions.lock.�[0m
 �[36;1m  gh extension install github/gh-actions-lock�[0m
 �[36;1m  bash scripts/update-actions-lock.sh --verify-local�[0m
 �[36;1m  unpinned=$(grep -rnE --include='*.yml' --include='*.yaml' \�[0m
 �[36;1m    "^[[:space:]]+uses:" .github/workflows/ | \�[0m
 �[36;1m    grep -v "@[a-f0-9]\{40\}" | \�[0m
 �[36;1m    grep -v "uses: \./\|uses: docker://\|uses: hyperpolymath/standards/" || true)�[0m
 �[36;1m  if [ -n "$unpinned" ]; then�[0m
 �[36;1m    echo "ERROR: direct workflow references not SHA-pinned:"�[0m
 �[36;1m    echo "$unpinned"�[0m
 �[36;1m    exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m  echo "Lockfile coverage verified; direct references SHA-pinned"�[0m
 �[36;1melse�[0m
 �[36;1m  unpinned=$(grep -rnE --include='*.yml' --include='*.yaml' \�[0m
 �[36;1m    "^[[:space:]]+uses:" .github/workflows/ | \�[0m
 �[36;1m    grep -v "@[a-f0-9]\{40\}" | \�[0m
 �[36;1m    grep -v "uses: \./\|uses: docker://\|uses: actions/github-script\|uses: hyperpolymath/standards/" || true)�[0m
 �[36;1m  if [ -n "$unpinned" ]; then�[0m
 �[36;1m    echo "ERROR: no .github/workflows/actions.lock in THIS TREE, and these refs are not SHA-pinned."�[0m
 �[36;1m  echo "  Prefer \`gh actions-lock\` — it also locks the transitive dependencies"�[0m
 �[36;1m  echo "  of composite actions, which an inline SHA cannot express."�[0m
 �[36;1m  echo "  Do NOT do both: gh actions-lock refuses a ref no tag or branch contains,"�[0m
 �[36;1m  echo "  so inline pinning REMOVES actions from the lockfile."�[0m
 �[36;1m    echo "$unpinned"�[0m
 �[36;1m    exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m  echo "All ...
🔇 Additional comments (1)
.github/dependabot.yml (1)

12-12: LGTM!


📝 Summary

Summary by CodeRabbit

  • Chores
    • Limited Dependabot to opening a maximum of two concurrent pull requests for GitHub Actions updates.

Walkthrough

The Dependabot configuration limits the GitHub Actions update group to two open pull requests.

Changes

Dependabot configuration

Layer / File(s) Summary
Set GitHub Actions pull request limit
.github/dependabot.yml
The github-actions update group sets open-pull-requests-limit to 2.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Other

Suggested reviewers: metadatastician

Merge Risk: ⚪ Minimal · up to aa691

The GitHub Actions update limit is narrowly scoped and presents no actionable merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check ✅ Passed The description clearly states that the pull request adds open-pull-requests-limit to Dependabot update blocks and follows the per-ecosystem cap policy.
Title check ✅ Passed The title clearly and concisely summarises the main change: limiting the number of open Dependabot pull requests.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reviews the limit with care
Two update hops now wait in the queue
Dependabot keeps its numbers fair
GitHub Actions know what to do
Ears up for a tidy view

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit cafcf82 into main Sep 12, 2026
22 of 26 checks passed
@hyperpolymath
hyperpolymath deleted the chore/dependabot-pr-caps-2026-09-08 branch September 12, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant