diff --git a/REPORT.md b/REPORT.md index 8a0d2c3..efaa77f 100644 --- a/REPORT.md +++ b/REPORT.md @@ -186,11 +186,27 @@ empty array, an absent classifier. So this step can only make CI as strict as it looser — **the untested direction is the safe one**, which is why shipping it before observing it is defensible. -**NOT VALIDATED: CI's actual behaviour, until a real push lands.** I have not confirmed that Gitea's -act-runner populates `GITHUB_EVENT_PATH` with a `commits` array carrying per-file lists. If it does -not, CI silently stays exactly as strict as it is now and the advisory never appears there. **The -first push after this one is the observation**, and the workflow prints the paths it found and the -scope it chose so the answer is readable in the log. +**MEASURED after the push, so this is no longer an assumption.** CI job **481** (`1e6c387a`, +felhom.eu) ran the new step and its log reads: + +``` +3 commit(s), 12 distinct path(s) in the payload +--- paths the push event reported --- +scripts/push_scope.py +scripts/test_push_scope.py +push_scope: CODE (12 file(s): 5 document, 7 code) +scope: code +::group::Run python3 scripts/repo_gates.py --fast --scope="${PUSH_SCOPE:-code}" +``` + +So Gitea's act-runner **does** populate `GITHUB_EVENT_PATH` with a `commits` array carrying per-file +lists; the classifier ran on it and returned `code` for a push that genuinely touched `scripts/`. +Job 481 is green. + +**STILL NOT OBSERVED: the `docs` branch in CI, and an advisory in a CI log.** The code path is proven; +a documents-only CI run has not happened yet, and an ADVISORY there additionally needs a golden debt +to exist at that moment. Neither is arranged artificially — the next documents-only push shows the +first, and the next release-without-a-bake shows the second. The compensating controls that make a green documents-only CI run honest are named in the workflow itself: the advisory block in the run's own log, `STATUS.md`, and the controller-side notice.