diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index dba7fc8..786b8fb 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -16,4 +16,5 @@ jobs: curl -X POST "http://boj-server.local:7700/cartridges/ssg-mcp/invoke" -H "Content-Type: application/json" -d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\\"}"} continue-on-error: true permissions: + actions: read contents: read diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index ad8fd14..b625074 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -7,6 +7,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read pages: write id-token: write diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ab8ae8b..fcd5400 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,6 +18,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index c9d8dfb..87796d5 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -13,6 +13,7 @@ on: branches: [main, master] permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 8776de0..966a16e 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -9,6 +9,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/hpc-ci.yml b/.github/workflows/hpc-ci.yml index 39ad57c..b133626 100644 --- a/.github/workflows/hpc-ci.yml +++ b/.github/workflows/hpc-ci.yml @@ -28,6 +28,7 @@ on: - '.github/workflows/hpc-ci.yml' permissions: + actions: read contents: read env: diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 9dde27a..556e8e0 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -11,6 +11,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read security-events: write diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index c013022..177614b 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -9,6 +9,7 @@ on: types: [published] permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 81e9903..72824fb 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -7,9 +7,10 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236 + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 secrets: inherit diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 4b4e754..112afd1 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -7,6 +7,7 @@ name: Push email notification on: push: {} permissions: + actions: read contents: read jobs: notify: diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b97e2cb..cede40a 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -9,6 +9,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 9ed74ef..010c16d 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -11,6 +11,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: @@ -19,5 +20,5 @@ jobs: contents: read pull-requests: write actions: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236 + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 secrets: inherit \ No newline at end of file diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 3bed9c5..57c5029 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -11,6 +11,7 @@ on: - '.github/workflows/**' permissions: read-all + actions: read jobs: lint-workflows: diff --git a/guix.scm b/guix.scm deleted file mode 100644 index 13eda72..0000000 --- a/guix.scm +++ /dev/null @@ -1,70 +0,0 @@ -;; SPDX-License-Identifier: MPL-2.0 -;; Docudactyl HPC — Guix development environment -;; -;; Usage: -;; guix shell -D -f guix.scm # Enter dev shell with all dependencies -;; guix build -f guix.scm # Build (placeholder — real build uses just) -;; -;; This defines the development environment for building Docudactyl HPC. -;; The actual build is driven by the Justfile (just build-hpc). -;; -;; Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) - -(use-modules (guix packages) - (guix build-system gnu) - (guix licenses) - (gnu packages) - (gnu packages gcc) - (gnu packages pkg-config) - (gnu packages glib) - (gnu packages pdf) - (gnu packages ocr) - (gnu packages image) - (gnu packages video) - (gnu packages xml) - (gnu packages geo) - (gnu packages image-processing) - (gnu packages databases)) - -(package - (name "docudactyl") - (version "0.4.0") - (source #f) - (build-system gnu-build-system) - (synopsis "Multi-format HPC document extraction engine") - (description - "Docudactyl is a distributed document processing engine targeting -British Library scale (~170M items). Chapel orchestrates across HPC -cluster nodes, dispatching to C libraries via a zero-cost Zig FFI layer. -Supports PDF, images (OCR), audio, video, EPUB, and geospatial formats.") - (home-page "https://github.com/hyperpolymath/docudactyl") - (license #f) ; MPL-2.0 (not in Guix license list) - - ;; Development inputs — these are the C libraries linked by the Zig FFI. - ;; Chapel and Zig are not yet packaged in Guix; install via asdf. - (native-inputs - (list pkg-config gcc-toolchain)) - (inputs - (list - ;; PDF extraction - poppler ; poppler-glib - glib ; glib-2.0, gobject-2.0 - - ;; OCR - tesseract-ocr ; libtesseract - leptonica ; liblept - - ;; Audio/Video - ffmpeg ; libavformat, libavcodec, libavutil - - ;; EPUB/XHTML - libxml2 ; libxml-2.0 - - ;; Geospatial - gdal ; libgdal - - ;; Image metadata - vips ; libvips - - ;; Result cache - lmdb))) ; liblmdb (zero-copy key-value store)