PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission
scope (verified list: actions, contents, issues, pull-requests, etc. - no
'workflows'). Merging it broke workflow_dispatch outright:
Invalid Argument - failed to parse workflow: (Line: 21, Col: 3):
Unexpected value 'workflows'
GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard
GitHub restriction, not something the permissions: block controls. The
correct fix is to never let the sync branch carry workflow-file changes in
the first place: after a clean merge, restore .github/workflows from
origin/main and amend. This also closes a latent risk - a clean upstream
merge could otherwise silently overwrite QualityHub's own CI files
(including this one) with whatever microsoft/BCQuality ships under the same
paths.
The last two scheduled runs (2026-07-13, 2026-07-20) failed silently: merge
was clean and validators green, but the push of the sync branch was rejected
by GitHub because upstream commits touch .github/workflows/*.yml and the
default token lacked the workflows scope. No issue was opened for this
failure mode, so the drift (now 3+ weeks / 31 commits) went unnoticed.
Michaels instinkt (Florence som upstream-vagt) realiseret efter ugens
staffing-lektion: opdagelse er mekanik, doemmekraft er menneske. En
cron ER et heartbeat - Florence gaar runden hver mandag 05:00 (eller
paa workflow_dispatch: Florence, gaa din runde) og taender lampen:
- Nye upstream-commits + rent merge + begge validatorer groenne over
det mergede korpus -> faerdigvalideret sync-PR (validatorer koerer
I workflowet, da GITHUB_TOKEN-PRs ikke trigger CI)
- Konflikt eller validator-fejl -> Issue med commit-liste og manuel
procedure
- Intet nyt -> een linje i summary, lampen forbliver slukket
(CURABIS-ROEMER-004-stil: orden faar tavshed)
Review, merge og promote forbliver Michaels. Florence lyser kun.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>