From df593fdedd2928368d0b26eac39470ac374164d6 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 14:49:41 +0100
Subject: [PATCH 1/5] chore: estate-wide security compliance
---
.github/workflows/boj-build.yml | 1 +
.github/workflows/casket-pages.yml | 1 +
.github/workflows/codeql.yml | 1 +
.github/workflows/dependabot-automerge.yml | 1 +
.github/workflows/dogfood-gate.yml | 1 +
.github/workflows/governance.yml | 1 +
.github/workflows/hypatia-scan.yml | 1 +
.github/workflows/instant-sync.yml | 1 +
.github/workflows/mirror.yml | 1 +
.github/workflows/openssf-compliance.yml | 1 +
.github/workflows/push-email-notify.yml | 1 +
.github/workflows/release.yml | 1 +
.github/workflows/rhodibot.yml | 1 +
.github/workflows/rust-ci.yml | 1 +
.github/workflows/scorecard.yml | 1 +
.github/workflows/static-analysis-gate.yml | 1 +
16 files changed, 16 insertions(+)
diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml
index 5ce534a..a0e699b 100644
--- a/.github/workflows/boj-build.yml
+++ b/.github/workflows/boj-build.yml
@@ -31,4 +31,5 @@ jobs:
-d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\"}" \
|| echo "BoJ server unreachable — skipping (non-fatal)"
permissions:
+ actions: read
contents: read
diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml
index ad8fd14..b625074 100644
--- a/.github/workflows/casket-pages.yml
+++ b/.github/workflows/casket-pages.yml
@@ -7,6 +7,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
pages: write
id-token: write
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index c475caf..7282f84 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -18,6 +18,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml
index 92b5254..df25cd2 100644
--- a/.github/workflows/dependabot-automerge.yml
+++ b/.github/workflows/dependabot-automerge.yml
@@ -41,6 +41,7 @@ on:
types: [opened, reopened, synchronize]
permissions:
+ actions: read
contents: write # needed to enable auto-merge
pull-requests: write # needed to approve
# NB: keep narrow — do NOT add secrets: read or id-token: write here.
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index b0ef40e..4940ed2 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -13,6 +13,7 @@ on:
branches: [main, master]
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml
index 62bbc98..906741d 100644
--- a/.github/workflows/governance.yml
+++ b/.github/workflows/governance.yml
@@ -27,6 +27,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 2e7e939..013c95a 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -19,6 +19,7 @@ concurrency:
cancel-in-progress: true
permissions:
+ actions: read
contents: read
security-events: write
pull-requests: write
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index 228dc43..0f86f6c 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -9,6 +9,7 @@ on:
types: [published]
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index 81e9903..c25d3bc 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -7,6 +7,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/openssf-compliance.yml b/.github/workflows/openssf-compliance.yml
index d952eff..403547e 100644
--- a/.github/workflows/openssf-compliance.yml
+++ b/.github/workflows/openssf-compliance.yml
@@ -11,6 +11,7 @@ on:
workflow_dispatch:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 4b4e754..112afd1 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -7,6 +7,7 @@ name: Push email notification
on:
push: {}
permissions:
+ actions: read
contents: read
jobs:
notify:
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index e49a7b5..3e640db 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -12,6 +12,7 @@ on:
- 'v*'
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml
index a82f178..3ed59b5 100644
--- a/.github/workflows/rhodibot.yml
+++ b/.github/workflows/rhodibot.yml
@@ -21,6 +21,7 @@ on:
types: [completed]
permissions:
+ actions: read
contents: write
pull-requests: write
diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml
index 3dbb9a2..2f97f73 100644
--- a/.github/workflows/rust-ci.yml
+++ b/.github/workflows/rust-ci.yml
@@ -10,6 +10,7 @@ on:
pull_request:
permissions:
+ actions: read
contents: read
jobs:
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index 3c28d3d..d251c65 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -13,6 +13,7 @@ on:
# (callee ⊆ caller) — `read-all` grants no writes, so the run startup-failed at
# plan time with zero jobs.
permissions:
+ actions: read
contents: read
security-events: write
id-token: write
diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml
index feaaa90..2d105a5 100644
--- a/.github/workflows/static-analysis-gate.yml
+++ b/.github/workflows/static-analysis-gate.yml
@@ -10,6 +10,7 @@ on:
branches: [main, master]
permissions:
+ actions: read
contents: read
jobs:
From 521b3a3cd3897f7f17635d04960c49a8bee1d068 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 15:10:45 +0100
Subject: [PATCH 2/5] chore: remove duplicate GOVERNANCE files, keep
GOVERNANCE.md
---
.github/GOVERNANCE.md | 158 ------------------------------------------
1 file changed, 158 deletions(-)
delete mode 100644 .github/GOVERNANCE.md
diff --git a/.github/GOVERNANCE.md b/.github/GOVERNANCE.md
deleted file mode 100644
index 55d7386..0000000
--- a/.github/GOVERNANCE.md
+++ /dev/null
@@ -1,158 +0,0 @@
-
-
-# Project Governance
-
-This document describes the governance model for **Patch Bridge**.
-
----
-
-## Project Governance Model
-
-Patch Bridge follows a **Benevolent Dictator For Life (BDFL)** governance model.
-This model is well-suited for solo maintainers and small project teams where rapid,
-consistent decision-making is more valuable than formal consensus processes.
-
-The BDFL has final authority on all project decisions, including technical direction,
-release schedules, contributor access, and community standards.
-
-> **Transition clause:** When the core team exceeds three active maintainers, this
-> project should transition to a **consensus-based governance model** with documented
-> voting procedures. That transition should itself be recorded as an Architecture
-> Decision Record (ADR) in `docs/decisions/`.
-
----
-
-## Decision Making
-
-### Day-to-day decisions
-
-- The BDFL makes final decisions on all matters.
-- Routine decisions (bug fixes, dependency updates, minor improvements) may be made
- by any maintainer with commit access.
-- Maintainers are expected to use good judgement and seek input on non-trivial changes.
-
-### Proposing changes
-
-- Contributors can propose changes by opening issues or pull requests.
-- Significant changes (new features, breaking changes, architectural shifts) should
- be discussed in an issue before implementation begins.
-- The BDFL will provide a clear accept/reject decision with reasoning.
-
-### Architecture Decision Records (ADRs)
-
-- Significant technical decisions are documented as ADRs in `docs/decisions/`.
-- ADR statuses: `proposed`, `accepted`, `deprecated`, `superseded`, `rejected`.
-- ADRs provide a historical record of why decisions were made and what alternatives
- were considered.
-- See `.machine_readable/META.a2ml` for the machine-readable ADR index.
-
----
-
-## Roles
-
-### BDFL (Benevolent Dictator For Life)
-
-- The project creator and ultimate decision-maker.
-- Sets the project's technical direction and long-term vision.
-- Has final say on all matters, including maintainer appointments and removals.
-- Responsible for ensuring the project adheres to RSR standards.
-
-### Maintainer
-
-- Has commit access to the repository.
-- Reviews and merges pull requests.
-- Triages issues and manages releases.
-- Upholds code quality, security standards, and the Code of Conduct.
-- Listed in [MAINTAINERS.md](MAINTAINERS.md).
-
-### Contributor
-
-- Anyone who submits pull requests, opens issues, or participates in discussions.
-- Does not have direct commit access.
-- Contributions are reviewed by maintainers before merging.
-- All contributors must follow the [Code of Conduct](CODE_OF_CONDUCT.md).
-
-### Bot
-
-- Automated agents managed via your bot orchestration system.
-- Perform automated code review, security scanning, dependency updates, and
- standards enforcement.
-- Bot actions are subject to the same quality and review standards as human
- contributions.
-- Configure your bots in `.machine_readable/bot_directives/`.
-
----
-
-## Becoming a Maintainer
-
-A contributor may be nominated to become a maintainer when they demonstrate:
-
-1. **Sustained quality contributions** -- a track record of well-crafted pull requests
- that follow project conventions and require minimal revision.
-2. **Understanding of RSR standards** -- familiarity with the Repository Structure
- Requirements, security policies, and CI/CD workflows used across the project.
-3. **Constructive participation** -- helpful issue triage, thoughtful code review
- comments, and mentoring of other contributors.
-4. **Reliability** -- consistent engagement over a meaningful period (typically 3+
- months of active contribution).
-
-### Process
-
-1. An existing maintainer nominates the candidate by opening a private discussion
- with the BDFL.
-2. The BDFL reviews the candidate's contribution history and community interactions.
-3. The BDFL approves or declines the nomination, with reasoning provided to the
- nominator.
-4. If approved, the new maintainer is added to [MAINTAINERS.md](MAINTAINERS.md) and
- granted appropriate repository access.
-
----
-
-## Removing a Maintainer
-
-A maintainer may be removed under the following circumstances:
-
-- **Inactivity**: No meaningful contributions or reviews for 12 or more consecutive
- months. The maintainer will be contacted before removal and offered the option to
- move to emeritus status voluntarily.
-- **Code of Conduct violation**: Behaviour that violates the
- [Code of Conduct](CODE_OF_CONDUCT.md), as determined through the enforcement
- process described therein.
-- **BDFL discretion**: The BDFL may remove a maintainer for other reasons (e.g.,
- repeated disregard for project standards, loss of trust). Reasoning will be
- documented privately.
-
-Removed maintainers are moved to the Emeritus section of
-[MAINTAINERS.md](MAINTAINERS.md) unless removal was due to a serious Code of Conduct
-violation.
-
----
-
-## Code of Conduct
-
-All participants in this project are expected to follow the
-[Code of Conduct](CODE_OF_CONDUCT.md). The Code of Conduct applies to all project
-spaces, including issues, pull requests, discussions, and any forum where the project
-is represented.
-
-Enforcement of the Code of Conduct is described in that document. The BDFL serves as
-the final arbiter in conduct disputes.
-
----
-
-## Amendments
-
-This governance document may be amended by the BDFL at any time. All amendments will
-be:
-
-1. Documented as an ADR in `docs/decisions/` explaining the rationale for the change.
-2. Committed to the repository with a clear commit message.
-3. Communicated to existing maintainers and contributors via the project's usual
- channels.
-
-Substantive changes (e.g., changing the governance model itself) should be discussed
-with the community before adoption, even though the BDFL retains final authority.
-
----
-
-Copyright (c) 2026 hyperpolymath. Licensed under MPL-2.0.
From 9f5eabe9a44b12cd8d39201dbefdb944bbbd71d7 Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sun, 26 Jul 2026 16:04:18 +0100
Subject: [PATCH 3/5] chore: update guix.scm from squisher-corpus
---
guix.scm | 75 +++++++++-----------------------------------------------
1 file changed, 11 insertions(+), 64 deletions(-)
diff --git a/guix.scm b/guix.scm
index c40840b..c6dd7be 100644
--- a/guix.scm
+++ b/guix.scm
@@ -1,71 +1,18 @@
-;; SPDX-License-Identifier: MPL-2.0
-;; Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath)
-;;
-;; Guix package definition for Patch Bridge
-;;
-;; Usage:
-;; guix shell -D -f guix.scm # Enter development shell
-;; guix build -f guix.scm # Build package
-;;
-;; TODO: Replace Patch Bridge and customize inputs for your language/stack.
-;; See: https://guix.gnu.org/manual/en/html_node/Defining-Packages.html
+; SPDX-License-Identifier: MPL-2.0
+;; guix.scm — GNU Guix package definition for squisher-corpus
+;; Usage: guix shell -f guix.scm
(use-modules (guix packages)
- (guix gexp)
- (guix git-download)
(guix build-system gnu)
- (guix licenses)
- (gnu packages base))
+ (guix licenses))
(package
- (name "Patch Bridge")
+ (name "squisher-corpus")
(version "0.1.0")
- (source (local-file "." "source"
- #:recursive? #t
- #:select? (lambda (file stat)
- (not (string-contains file ".git")))))
+ (source #f)
(build-system gnu-build-system)
- (arguments
- '(#:phases
- (modify-phases %standard-phases
- ;; TODO: Customize build phases for your project
- ;; Examples for common stacks:
- ;;
- ;; Rust:
- ;; (replace 'build (lambda _ (invoke "cargo" "build" "--release")))
- ;; (replace 'check (lambda _ (invoke "cargo" "test")))
- ;;
- ;; Elixir:
- ;; (replace 'build (lambda _ (invoke "mix" "compile")))
- ;; (replace 'check (lambda _ (invoke "mix" "test")))
- ;;
- ;; Zig:
- ;; (replace 'build (lambda _ (invoke "zig" "build")))
- ;; (replace 'check (lambda _ (invoke "zig" "build" "test")))
- (delete 'configure)
- (delete 'build)
- (delete 'check)
- (replace 'install
- (lambda* (#:key outputs #:allow-other-keys)
- (let ((out (assoc-ref outputs "out")))
- (mkdir-p (string-append out "/share/doc"))
- (copy-file "README.adoc"
- (string-append out "/share/doc/README.adoc"))))))))
- (native-inputs
- (list
- ;; TODO: Add build-time dependencies
- ;; Examples:
- ;; rust (gnu packages rust)
- ;; elixir (gnu packages elixir)
- ;; zig (gnu packages zig)
- ))
- (inputs
- (list
- ;; TODO: Add runtime dependencies
- ))
- (home-page "https://github.com/hyperpolymath/Patch Bridge")
- (synopsis "{{PROJECT_PURPOSE}}")
- (description "RSR-compliant project. See README.adoc for details.")
- (license (list
- ;; MPL-2.0 extends MPL-2.0
- mpl2.0)))
+ (synopsis "squisher-corpus")
+ (description "squisher-corpus — part of the hyperpolymath ecosystem.")
+ (home-page "https://github.com/hyperpolymath/squisher-corpus")
+ (license ((@@ (guix licenses) license) "PMPL-1.0-or-later"
+ "https://github.com/hyperpolymath/palimpsest-license")))
From 8c4d7c82c0a00e731176a0944fede634e3a09abc Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Thu, 13 Aug 2026 01:44:11 +0100
Subject: [PATCH 4/5] fix(ci): remove erroneous squisher-corpus guix.scm
placeholder
Part of estate-wide standards#426 remediation - cleanup.
Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe
---
guix.scm | 18 ------------------
1 file changed, 18 deletions(-)
delete mode 100644 guix.scm
diff --git a/guix.scm b/guix.scm
deleted file mode 100644
index c6dd7be..0000000
--- a/guix.scm
+++ /dev/null
@@ -1,18 +0,0 @@
-; SPDX-License-Identifier: MPL-2.0
-;; guix.scm — GNU Guix package definition for squisher-corpus
-;; Usage: guix shell -f guix.scm
-
-(use-modules (guix packages)
- (guix build-system gnu)
- (guix licenses))
-
-(package
- (name "squisher-corpus")
- (version "0.1.0")
- (source #f)
- (build-system gnu-build-system)
- (synopsis "squisher-corpus")
- (description "squisher-corpus — part of the hyperpolymath ecosystem.")
- (home-page "https://github.com/hyperpolymath/squisher-corpus")
- (license ((@@ (guix licenses) license) "PMPL-1.0-or-later"
- "https://github.com/hyperpolymath/palimpsest-license")))
From 797487a9d3330222724261a468bcbc2b2175e72b Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Thu, 13 Aug 2026 03:46:22 +0100
Subject: [PATCH 5/5] fix(ci): update reusable workflow SHAs to
@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
Part of estate-wide standards#426 remediation - Batch 11 SHA update.
Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe
---
.github/workflows/mirror.yml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index c25d3bc..72824fb 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -12,5 +12,5 @@ permissions:
jobs:
mirror:
- uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
+ uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329
secrets: inherit