From c61f099f66bc7720920dc365c4ed519b28ffcfcc Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 14:47:55 +0100
Subject: [PATCH 1/6] chore: estate-wide security compliance
---
.github/workflows/boj-build.yml | 1 +
.github/workflows/casket-pages.yml | 1 +
.github/workflows/codeql.yml | 1 +
.github/workflows/dependabot-automerge.yml | 1 +
.github/workflows/dogfood-gate.yml | 1 +
.github/workflows/governance.yml | 1 +
.github/workflows/hypatia-scan.yml | 1 +
.github/workflows/instant-sync.yml | 1 +
.github/workflows/mirror.yml | 1 +
.github/workflows/push-email-notify.yml | 1 +
.github/workflows/release.yml | 1 +
.github/workflows/rhodibot.yml | 1 +
.github/workflows/scorecard.yml | 1 +
.github/workflows/secret-scanner.yml | 1 +
.github/workflows/static-analysis-gate.yml | 1 +
15 files changed, 15 insertions(+)
diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml
index 9ea31b7..77bd4b2 100644
--- a/.github/workflows/boj-build.yml
+++ b/.github/workflows/boj-build.yml
@@ -31,4 +31,5 @@ jobs:
-d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\"}" \
|| echo "BoJ server unreachable — skipping (non-fatal)"
permissions:
+ actions: read
contents: read
diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml
index 751e879..aef7e09 100644
--- a/.github/workflows/casket-pages.yml
+++ b/.github/workflows/casket-pages.yml
@@ -7,6 +7,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
pages: write
id-token: write
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index bcc0526..88e4574 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -18,6 +18,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml
index ca86baa..ef640a5 100644
--- a/.github/workflows/dependabot-automerge.yml
+++ b/.github/workflows/dependabot-automerge.yml
@@ -41,6 +41,7 @@ on:
types: [opened, reopened, synchronize]
permissions:
+ actions: read
contents: write # needed to enable auto-merge
pull-requests: write # needed to approve
# NB: keep narrow — do NOT add secrets: read or id-token: write here.
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index 84e0229..2f4235c 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -13,6 +13,7 @@ on:
branches: [main, master]
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml
index 8776de0..966a16e 100644
--- a/.github/workflows/governance.yml
+++ b/.github/workflows/governance.yml
@@ -9,6 +9,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 9dde27a..556e8e0 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -11,6 +11,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
security-events: write
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index 228dc43..0f86f6c 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -9,6 +9,7 @@ on:
types: [published]
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index 81e9903..c25d3bc 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -7,6 +7,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 0816771..ce036e2 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -7,6 +7,7 @@ name: Push email notification
on:
push: {}
permissions:
+ actions: read
contents: read
jobs:
notify:
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 0782ea5..36aa6ba 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -12,6 +12,7 @@ on:
- 'v*'
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml
index ac17441..35090f6 100644
--- a/.github/workflows/rhodibot.yml
+++ b/.github/workflows/rhodibot.yml
@@ -21,6 +21,7 @@ on:
types: [completed]
permissions:
+ actions: read
contents: write
pull-requests: write
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index b97e2cb..cede40a 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -9,6 +9,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml
index b3486fc..4839d60 100644
--- a/.github/workflows/secret-scanner.yml
+++ b/.github/workflows/secret-scanner.yml
@@ -11,6 +11,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml
index 0f1282e..6de5b2e 100644
--- a/.github/workflows/static-analysis-gate.yml
+++ b/.github/workflows/static-analysis-gate.yml
@@ -10,6 +10,7 @@ on:
branches: [main, master]
permissions:
+ actions: read
contents: read
jobs:
From 6869332cde72a003cb291170f6c96118e8bb1f6e Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 15:10:08 +0100
Subject: [PATCH 2/6] chore: remove duplicate GOVERNANCE files, keep
GOVERNANCE.md
---
.github/GOVERNANCE.md | 158 ------------------------------------------
1 file changed, 158 deletions(-)
delete mode 100644 .github/GOVERNANCE.md
diff --git a/.github/GOVERNANCE.md b/.github/GOVERNANCE.md
deleted file mode 100644
index 5f082df..0000000
--- a/.github/GOVERNANCE.md
+++ /dev/null
@@ -1,158 +0,0 @@
-
-
-# Project Governance
-
-This document describes the governance model for **{{PROJECT_NAME}}**.
-
----
-
-## Project Governance Model
-
-{{PROJECT_NAME}} follows a **Benevolent Dictator For Life (BDFL)** governance model.
-This model is well-suited for solo maintainers and small project teams where rapid,
-consistent decision-making is more valuable than formal consensus processes.
-
-The BDFL has final authority on all project decisions, including technical direction,
-release schedules, contributor access, and community standards.
-
-> **Transition clause:** When the core team exceeds three active maintainers, this
-> project should transition to a **consensus-based governance model** with documented
-> voting procedures. That transition should itself be recorded as an Architecture
-> Decision Record (ADR) in `docs/decisions/`.
-
----
-
-## Decision Making
-
-### Day-to-day decisions
-
-- The BDFL makes final decisions on all matters.
-- Routine decisions (bug fixes, dependency updates, minor improvements) may be made
- by any maintainer with commit access.
-- Maintainers are expected to use good judgement and seek input on non-trivial changes.
-
-### Proposing changes
-
-- Contributors can propose changes by opening issues or pull requests.
-- Significant changes (new features, breaking changes, architectural shifts) should
- be discussed in an issue before implementation begins.
-- The BDFL will provide a clear accept/reject decision with reasoning.
-
-### Architecture Decision Records (ADRs)
-
-- Significant technical decisions are documented as ADRs in `docs/decisions/`.
-- ADR statuses: `proposed`, `accepted`, `deprecated`, `superseded`, `rejected`.
-- ADRs provide a historical record of why decisions were made and what alternatives
- were considered.
-- See `.machine_readable/META.a2ml` for the machine-readable ADR index.
-
----
-
-## Roles
-
-### BDFL (Benevolent Dictator For Life)
-
-- The project creator and ultimate decision-maker.
-- Sets the project's technical direction and long-term vision.
-- Has final say on all matters, including maintainer appointments and removals.
-- Responsible for ensuring the project adheres to RSR standards.
-
-### Maintainer
-
-- Has commit access to the repository.
-- Reviews and merges pull requests.
-- Triages issues and manages releases.
-- Upholds code quality, security standards, and the Code of Conduct.
-- Listed in [MAINTAINERS.md](MAINTAINERS.md).
-
-### Contributor
-
-- Anyone who submits pull requests, opens issues, or participates in discussions.
-- Does not have direct commit access.
-- Contributions are reviewed by maintainers before merging.
-- All contributors must follow the [Code of Conduct](CODE_OF_CONDUCT.md).
-
-### Bot
-
-- Automated agents managed via your bot orchestration system.
-- Perform automated code review, security scanning, dependency updates, and
- standards enforcement.
-- Bot actions are subject to the same quality and review standards as human
- contributions.
-- Configure your bots in `.machine_readable/bot_directives/`.
-
----
-
-## Becoming a Maintainer
-
-A contributor may be nominated to become a maintainer when they demonstrate:
-
-1. **Sustained quality contributions** -- a track record of well-crafted pull requests
- that follow project conventions and require minimal revision.
-2. **Understanding of RSR standards** -- familiarity with the Repository Structure
- Requirements, security policies, and CI/CD workflows used across the project.
-3. **Constructive participation** -- helpful issue triage, thoughtful code review
- comments, and mentoring of other contributors.
-4. **Reliability** -- consistent engagement over a meaningful period (typically 3+
- months of active contribution).
-
-### Process
-
-1. An existing maintainer nominates the candidate by opening a private discussion
- with the BDFL.
-2. The BDFL reviews the candidate's contribution history and community interactions.
-3. The BDFL approves or declines the nomination, with reasoning provided to the
- nominator.
-4. If approved, the new maintainer is added to [MAINTAINERS.md](MAINTAINERS.md) and
- granted appropriate repository access.
-
----
-
-## Removing a Maintainer
-
-A maintainer may be removed under the following circumstances:
-
-- **Inactivity**: No meaningful contributions or reviews for 12 or more consecutive
- months. The maintainer will be contacted before removal and offered the option to
- move to emeritus status voluntarily.
-- **Code of Conduct violation**: Behaviour that violates the
- [Code of Conduct](CODE_OF_CONDUCT.md), as determined through the enforcement
- process described therein.
-- **BDFL discretion**: The BDFL may remove a maintainer for other reasons (e.g.,
- repeated disregard for project standards, loss of trust). Reasoning will be
- documented privately.
-
-Removed maintainers are moved to the Emeritus section of
-[MAINTAINERS.md](MAINTAINERS.md) unless removal was due to a serious Code of Conduct
-violation.
-
----
-
-## Code of Conduct
-
-All participants in this project are expected to follow the
-[Code of Conduct](CODE_OF_CONDUCT.md). The Code of Conduct applies to all project
-spaces, including issues, pull requests, discussions, and any forum where the project
-is represented.
-
-Enforcement of the Code of Conduct is described in that document. The BDFL serves as
-the final arbiter in conduct disputes.
-
----
-
-## Amendments
-
-This governance document may be amended by the BDFL at any time. All amendments will
-be:
-
-1. Documented as an ADR in `docs/decisions/` explaining the rationale for the change.
-2. Committed to the repository with a clear commit message.
-3. Communicated to existing maintainers and contributors via the project's usual
- channels.
-
-Substantive changes (e.g., changing the governance model itself) should be discussed
-with the community before adoption, even though the BDFL retains final authority.
-
----
-
-Copyright (c) {{CURRENT_YEAR}} {{OWNER}}. Licensed under MPL-2.0.
From 4907f2713811220f24a8a7a31a2f803fa18da0a2 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 16:01:46 +0100
Subject: [PATCH 3/6] chore: update guix.scm from squisher-corpus
---
guix.scm | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/guix.scm b/guix.scm
index dbbec67..c6dd7be 100644
--- a/guix.scm
+++ b/guix.scm
@@ -1,5 +1,5 @@
; SPDX-License-Identifier: MPL-2.0
-;; guix.scm — GNU Guix package definition for methodologies
+;; guix.scm — GNU Guix package definition for squisher-corpus
;; Usage: guix shell -f guix.scm
(use-modules (guix packages)
@@ -7,12 +7,12 @@
(guix licenses))
(package
- (name "methodologies")
+ (name "squisher-corpus")
(version "0.1.0")
(source #f)
(build-system gnu-build-system)
- (synopsis "methodologies")
- (description "methodologies — part of the hyperpolymath ecosystem.")
- (home-page "https://github.com/hyperpolymath/methodologies")
- (license ((@@ (guix licenses) license) "MPL-2.0"
+ (synopsis "squisher-corpus")
+ (description "squisher-corpus — part of the hyperpolymath ecosystem.")
+ (home-page "https://github.com/hyperpolymath/squisher-corpus")
+ (license ((@@ (guix licenses) license) "PMPL-1.0-or-later"
"https://github.com/hyperpolymath/palimpsest-license")))
From 320ceb5e2bba58ed7fcca4d77dd12ba2bdb98814 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Thu, 13 Aug 2026 01:43:28 +0100
Subject: [PATCH 4/6] fix(ci): remove erroneous squisher-corpus guix.scm
placeholder
Part of estate-wide standards#426 remediation - cleanup.
Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe
---
guix.scm | 18 ------------------
1 file changed, 18 deletions(-)
delete mode 100644 guix.scm
diff --git a/guix.scm b/guix.scm
deleted file mode 100644
index c6dd7be..0000000
--- a/guix.scm
+++ /dev/null
@@ -1,18 +0,0 @@
-; SPDX-License-Identifier: MPL-2.0
-;; guix.scm — GNU Guix package definition for squisher-corpus
-;; Usage: guix shell -f guix.scm
-
-(use-modules (guix packages)
- (guix build-system gnu)
- (guix licenses))
-
-(package
- (name "squisher-corpus")
- (version "0.1.0")
- (source #f)
- (build-system gnu-build-system)
- (synopsis "squisher-corpus")
- (description "squisher-corpus — part of the hyperpolymath ecosystem.")
- (home-page "https://github.com/hyperpolymath/squisher-corpus")
- (license ((@@ (guix licenses) license) "PMPL-1.0-or-later"
- "https://github.com/hyperpolymath/palimpsest-license")))
From a576c711d3cb8075af512ebc466abc150685996f Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Thu, 13 Aug 2026 03:42:28 +0100
Subject: [PATCH 5/6] fix(ci): update reusable workflow SHAs to
@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
Part of estate-wide standards#426 remediation - Batch 11 SHA update.
Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe
---
.github/workflows/mirror.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index c25d3bc..72824fb 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -12,5 +12,5 @@ permissions:
jobs:
mirror:
- uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
+ uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
secrets: inherit
From 1fcf0945b314e74710e13cc0b55c6668f8a5e573 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Thu, 13 Aug 2026 04:09:56 +0100
Subject: [PATCH 6/6] fix(ci): update reusable workflow SHAs to
@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
Part of estate-wide standards#426 remediation - Batch 12 SHA update.
Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe
---
.github/workflows/secret-scanner.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml
index 4839d60..0c35e6b 100644
--- a/.github/workflows/secret-scanner.yml
+++ b/.github/workflows/secret-scanner.yml
@@ -18,5 +18,5 @@ jobs:
scan:
permissions:
contents: read
- uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@c65436ee3351cd6b0fa14b142938b195efc77586
+ uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
secrets: inherit
\ No newline at end of file