Captured from the Hypatia neurosymbolic scan on PR #40 so the proofs work stays focused and this debt has a home. These findings are pre-existing and repo-wide — PR #40 adds none (its new proofs.yml is already timeout-minutes-pinned).
Baseline (PR #40 scan)
194 findings — 🔴 44 critical · 🟠 133 high · 🟡 17 medium.
root_hygiene
workflow_audit
Not yet enumerated
The 44 critical + 133 high are mostly per-cartridge hygiene; only ~10 items are shown in the PR comment. The full machine-readable list is the hypatia-scan artifact on the PR #40 run — enumerate + triage from there before fixing.
Relationship to other work
Overlaps the planned .machine_readable scaffold for this repo (STATE/META/ECOSYSTEM/AGENTIC/NEUROSYM/PLAYBOOK + contractiles + anchors + bot_directives/), which is blocked on access to hyperpolymath/standards (canonical source + divergence check). The root_hygiene AI-MANIFEST item is part of that scaffold; do them together.
Also fold in
zig-test.yml still pins the dead Zig 0.15.2 nightly (boj-server #205 moved to 0.15.1) — fix in the same workflow-hygiene pass.
Done when
- Hypatia critical count = 0; highs triaged/justified; the 7 workflow timeouts + the action-pin + the zig pin landed; AI-MANIFEST reconciled.
Governance track (the catch-all "scope e" for this repo). Filed because Hypatia is non-blocking (the check passes) but the debt is real.
Filed via Claude Code · https://claude.ai/code/session_019tMcRS1Dm1nWjjYP4WvbJa
Captured from the Hypatia neurosymbolic scan on PR #40 so the proofs work stays focused and this debt has a home. These findings are pre-existing and repo-wide — PR #40 adds none (its new
proofs.ymlis alreadytimeout-minutes-pinned).Baseline (PR #40 scan)
194 findings — 🔴 44 critical · 🟠 133 high · 🟡 17 medium.
root_hygiene0-AI-MANIFEST.a2mlmissing (high). NB the repo already has0.1-AI-MANIFEST.a2ml— reconcile the expected canonical filename against what the rule wants (don't blindly add a duplicate).workflow_auditcodeql.ymlmissing (high) — add a CodeQL workflow (mirror boj-server's pinned one).governance.ymlunpinned reusable actionhyperpolymath/standards/.github/workflows/governance-reusable.yml@main(medium) — pin to a commit SHA.missing_timeout_minutes(medium ×7):cartridge-schema.yml,governance.yml,hypatia-scan.yml,mirror.yml,scorecard.yml,secret-scanner.yml,zig-test.yml— addtimeout-minutes:to each job (same mechanical fix as boj-server #205).Not yet enumerated
The 44 critical + 133 high are mostly per-cartridge hygiene; only ~10 items are shown in the PR comment. The full machine-readable list is the
hypatia-scanartifact on the PR #40 run — enumerate + triage from there before fixing.Relationship to other work
Overlaps the planned
.machine_readablescaffold for this repo (STATE/META/ECOSYSTEM/AGENTIC/NEUROSYM/PLAYBOOK + contractiles + anchors +bot_directives/), which is blocked on access tohyperpolymath/standards(canonical source + divergence check). Theroot_hygieneAI-MANIFEST item is part of that scaffold; do them together.Also fold in
zig-test.ymlstill pins the dead Zig0.15.2nightly (boj-server #205 moved to0.15.1) — fix in the same workflow-hygiene pass.Done when
Governance track (the catch-all "scope e" for this repo). Filed because Hypatia is non-blocking (the check passes) but the debt is real.
Filed via Claude Code · https://claude.ai/code/session_019tMcRS1Dm1nWjjYP4WvbJa