Skip to content

cicd: carve out zotpress/** from ReScript anti-pattern policy - #20

Merged
hyperpolymath merged 1 commit into
mainfrom
cicd/zotpress-carveout
Jun 2, 2026
Merged

cicd: carve out zotpress/** from ReScript anti-pattern policy#20
hyperpolymath merged 1 commit into
mainfrom
cicd/zotpress-carveout

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

  • Add .hypatia-ignore with 6 per-file exemptions for zotpress/**/*.res under the cicd_rules/banned_language_file rule.
  • Unblocks PR chore: purge nix per 2026-06-01 owner directive (guix-only) #18 (chore: purge nix per 2026-06-01 owner directive) which is currently red on governance / Language / package anti-pattern policy for these 6 grandfathered files that the PR's diff does not touch.

Rationale

zotpress/ is a WordPress plugin (composer.json type: wordpress-plugin) that runs inside the WordPress host runtime — not estate-authored AffineScript-bound application code. The 6 in-tree .res files are auto-translated TypeScript placeholders (each carrying /* Auto-translated placeholder from TypeScript. */) awaiting the estate-wide ReScript→AffineScript migration umbrella (hyperpolymath/standards#252).

The per-file .hypatia-ignore mechanism is the workflow's documented escape (hyperpolymath/standards/.github/workflows/governance-reusable.yml lines 298-300, grep -qxF).

Files exempted

cicd_rules/banned_language_file:zotpress/scripts/build-css.res
cicd_rules/banned_language_file:zotpress/scripts/build-js.res
cicd_rules/banned_language_file:zotpress/scripts/build.res
cicd_rules/banned_language_file:zotpress/src/js/zotpress.res
cicd_rules/banned_language_file:zotpress/src/rescript/Utils.res
cicd_rules/banned_language_file:zotpress/src/rescript/Zotpress.res

Sibling PR

hyperpolymath/standards branch docs/zotpress-rescript-carveout adds zotpress/** to the upstream-fork/WordPress-plugin row of the ReScript Exemptions table in .claude/CLAUDE.md (and parallel TS / JS / npm tables) so the estate-wide manifest stays in sync with this per-repo escape.

Test plan

Co-Authored-By: Claude Opus 4.7 (1M context) noreply@anthropic.com

`zotpress/` is a WordPress plugin (composer.json `type: wordpress-plugin`)
shipped under `hyperpolymath/zotpress` — it runs inside the WordPress
host runtime, not as estate-authored AffineScript-bound application
code. Its 6 in-tree `.res` files are auto-translated TypeScript
placeholders (`/* Auto-translated placeholder from TypeScript. */`)
awaiting the estate-wide ReScript→AffineScript migration umbrella
(`hyperpolymath/standards#252`), but failing PR #18 (`chore: purge
nix per 2026-06-01 owner directive`) on `governance / Language /
package anti-pattern policy` solely on these grandfathered files is
noise — the PR's diff does not introduce them.

This commit lands the per-file exemption mechanism documented at
`hyperpolymath/standards/.github/workflows/governance-reusable.yml`
lines 298-300 (`grep -qxF "${rule}:${f}" .hypatia-ignore`). Sibling
`hyperpolymath/standards` PR `docs/zotpress-rescript-carveout` adds
the matching row to the ReScript Exemptions table in
`.claude/CLAUDE.md` (and the parallel TS / JS / npm tables) so the
estate-wide rule and per-repo escape stay aligned.

Files exempted:
  - zotpress/scripts/build-css.res
  - zotpress/scripts/build-js.res
  - zotpress/scripts/build.res
  - zotpress/src/js/zotpress.res
  - zotpress/src/rescript/Utils.res
  - zotpress/src/rescript/Zotpress.res

Local verification (replicated workflow logic at
`governance-reusable.yml:292-305`): all 6 .res files report EXEMPT.

Sibling PR: hyperpolymath/standards docs/zotpress-rescript-carveout
ReScript-exemption table: standards .claude/CLAUDE.md §"ReScript
Exemptions (Approved)" (line 155).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit dff8d6e into main Jun 2, 2026
11 of 19 checks passed
@hyperpolymath
hyperpolymath deleted the cicd/zotpress-carveout branch June 2, 2026 09:30
@github-actions

github-actions Bot commented Jun 2, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 64 issues detected

Severity Count
🔴 Critical 1
🟠 High 16
🟡 Medium 47

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Action perpolymath/standards/.github/workflows/governance-reusable.yml@main\n needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in boj-build.yml",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in casket-pages.yml",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in codeql.yml",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Issue in dogfood-gate.yml",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit to hyperpolymath/standards that referenced this pull request Jun 2, 2026
Mirrors hyperpolymath/hyperpolymath#20.

Adds `zotpress/**` to the ReScript Exemptions table in
`.claude/CLAUDE.md` as an upstream-fork carve-out. This formalises the
per-repo `.hypatia-ignore` entry estate-wide so future-cloned hypatia
instances inherit the rule via `hypatia/scanner_suppression` without
needing per-repo configuration.

zotpress is an upstream WordPress plugin fork
(`hyperpolymath/hyperpolymath/zotpress`) — not estate-authored, kept in
tree as a vendored fork.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant