Repository navigation
CI: seven checks are red on main (lint-workflows, governance, Hypatia, build, elixir-ci, SonarQube on PRs) #210
Copy link
Copy link
Open
Labels
automationBots, schedulers, dispatch, self-healing, fan-outBots, schedulers, dispatch, self-healing, fan-outchoreRoutine maintenance with no behaviour changeRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementPolicy, rulesets, standards, compliance, and their enforcement
Description
Activity
- addedautomationBots, schedulers, dispatch, self-healing, fan-outBots, schedulers, dispatch, self-healing, fan-outchoreRoutine maintenance with no behaviour changeRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementPolicy, rulesets, standards, compliance, and their enforcement
on Oct 2, 2026 - added a commit that references this issue
on Oct 2, 2026 SonarQube now fails for a different reason: the token is rejected (measured 2026-10-09).
- Last success: Build run 37614986543 (push to
008665f8, 2026-10-07T11:34Z). - First failure seen: run 37892421445 (PR chore(deps-dev): bump lazy_html from 0.1.12 to 0.1.13 #213, 2026-10-09T06:13Z). The scanner reached SonarCloud, then
Create analysisfailed withERROR Not authorized. Please check the 'sonar.token' property or the 'SONAR_TOKEN' environment variable. Exit code 3. - By run 37907974087 (PR docs: affirm state at 008665f841bbaac6fe8d2d32cff2b9c3d04064e6 #217, 08:55Z), the scanner's first call already returned
GET https://api.sonarcloud.io/analysis/jres … HTTP 403 Forbidden. - The repo secret
SONAR_TOKENwas last set on 2026-09-23. The same 403 shows on boj-server (#338) and on metadatastician/marid (chore(deps): bump plug_cowboy from 2.8.0 to 2.8.1 #49). That points to the SonarCloud token, not to this repo's code. That is inferred: the token itself was not inspected.
The third acceptance criterion above still covers this, with one change: a fresh token comes first, then the PR binding. The other four contexts named here (
build,governance / Validate Hypatia Baseline,governance / Workflow security linter,Hypatia Neurosymbolic Analysis) fail on PR #217's head99f49d70and at its base008665f8alike. #217 defers all five to this issue.- Last success: Build run 37614986543 (push to
- added a commit that references this issue
on Oct 9, 2026
Metadata
Metadata
Assignees
Labels
automationBots, schedulers, dispatch, self-healing, fan-outBots, schedulers, dispatch, self-healing, fan-outchoreRoutine maintenance with no behaviour changeRoutine maintenance with no behaviour changecicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcementPolicy, rulesets, standards, compliance, and their enforcement
Measured 2026-10-02 on
main@7b7e928and on Dependabot PR #209 (identical failures; the PR's diff isactions.lockonly):lint-workflows(×2)ERROR: .github/workflows/boj-build.yml missing permissions declarationgovernance / Workflow security lintermaingovernance / Validate Hypatia BaselinemainHypatia Neurosymbolic Analysismainbuildmainelixir-ci / Compile + testmainSonarQubeSomething went wrong while trying to get the pullrequest with key 'N', exit 3. The SonarCloud project cannot see the PR (binding / PR-decoration config), not a code findingNone is a required context (required checks on
main:scan / gitleaksonly), so none blocks a merge, but every PR inherits all seven.Acceptance criteria
boj-build.ymldeclares top-levelpermissions:;lint-workflowsgreen onmain.governance / *,Hypatia Neurosymbolic Analysis,build,elixir-ci / Compile + testeach green onmain, or removed with a stated reason.SonarQubeeither analyses PRs (project bound to the repo for PR decoration) or is skipped on PRs where it cannot work.🤖 Generated with Claude Code