Chore/training infrastructure cleanups - #334
Conversation
EchidnaML.jl: CUDA.version() was removed in CUDA.jl 5.x; replace with runtime_version() / driver_version() wrapped in try/catch so a logging-only probe failure can't kill the init path. Surfaced during first owner-authorised GNN training run as a MethodError log noise. docs/training-runs/2026-06-02.md: per-stage run-log scaffold for the 2026-06-02 GNN training run (reactive doc — placeholders for stages 3/4/5 to be filled in as they complete; stage 0/1/2 outcomes already captured). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…tructure-cleanups # Conflicts: # docs/training-runs/2026-06-02.md
…complete must/trust/dust/intend tridents
Discard the rsr-template flat residue that had been staged on this branch
(the Mustfile still read "contract for rsr-template-repo") and restore the
canonical per-verb subdir layout defined by
standards/contractiles/CANONICAL-TEMPLATES.adoc.
Complete the four missing tridents with bespoke runner/.k9/manifest
companions, mirroring the existing adjust/bust pattern and matching each
verb's INDEX.a2ml entry:
- must: Hunt-read-only, blocking (exit-nonzero); LICENSE/README/banned-path
invariants; subtle invariant-erosion focus
- trust: Hunt, blocking; T### namespace, dispatcher-trust boundary,
threat-model foregrounding
- dust: Yard, advisory; D### broom-and-pan recovery, --apply + per-item
approval, audit-trail preservation
- intend: Hunt, non-gating; dual [[intents]]/[[wishes]] schema (absorbed lust)
Add a bespoke contractiles/README.adoc (MPL-2.0, matching the sibling files
in the directory) and refresh the now-stale INDEX.a2ml note.
All six runner .ncl files nickel typecheck clean; the four Xfile declarations
are byte-identical to HEAD. The shared ../k9/ Hunt base import remains a known
estate-wide gap (tracked by the respec programme), not patched per-repo here.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…rnance-docs check) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Finish the half-applied gitleaks -> TruffleHog swap and repair the botched parts of the 2026-06-11 sweep: - .pre-commit-config.yaml: remove the orphaned/broken gitleaks block (dangling rev:/hooks: after the repo/id lines were stripped). Secret scanning is enforced CI-side via TruffleHog. - echidna-playground/.github/workflows/security-checks.yml: replace the broken gitleaks step (name + env, no uses:) with a SHA-pinned TruffleHog step (@8a8ef85 # v3); drop the redundant unpinned trufflehog@main job. - echidna-playground/.github/workflows/secret-scanner.yml: gitleaks job removed; SHA-pinned TruffleHog retained. - .gitlab-ci.yml: TruffleHog job in the existing `security` stage (image :latest, matching the estate's existing references). - Justfile: local `secret-scan-trufflehog` convenience recipe. The redundant unpinned inline trufflehog@main that the sweep added to the main secret-scanner.yml was dropped — that workflow already runs TruffleHog via the standards secret-scanner-reusable.yml. NOTE: the shared standards/secret-scanner-reusable.yml still bundles gitleaks; removing it there (estate-wide, separate repo) is the remaining step for the reusable path to be fully gitleaks-free. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ Approved 3 resolved / 3 findingsAdopts standard reusable workflows and migrates CI security tooling while adding governance documentation and training fixes, but requires fixing permission grants in the Scorecard and Hypatia callers and addressing shallow-clone history limits in TruffleHog. ✅ 3 resolved✅ Bug: Scorecard reusable caller no longer grants upload permissions
✅ Bug: Hypatia scan downgrades security-events to read, blocking SARIF upload
✅ Bug: GitLab TruffleHog scan misses history under default shallow clone
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Gitar |
Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers
Summary by Gitar
must,trust,adjust,dust,bust,intend) with coherence manifestsGOVERNANCE.adoc)This will update automatically on new commits.