Summary
Depot CI's governance-enforce / enforce check-run fails on the newest commit (d1a752d6a) at the install step, before any governance rules actually run. This is invisible from GitHub Actions — it's a Depot-authored check-run only.
Receipt
Depot CIService/GetFailureDiagnosis for job 0k5p7r35pz (governance-enforce / enforce, workflow governance-enforce.yml):
The failed step, "fetch governance enforcer (isolated install)," ran npm install @wave-av/governance@0.4.6 after writing an npm registry configuration that references ${NODE_AUTH_TOKEN} (lines 5 and 13). npm then failed with E401 because no authentication token was provided for https://npm.pkg.github.com/@wave-av%2fgovernance, so the script exited 1; this is the command failure, not cleanup output.
Error message: npm error code E401.
Root cause
Same pattern as wave-av/wave-webhook-edge's deploy / deploy failure (see wave-av/claude-workstation#5340): the workflow step's NODE_AUTH_TOKEN resolves from a Depot-secret-store value (a GH_PACKAGES_TOKEN-style secret) needed to authenticate against npm.pkg.github.com for the private @wave-av/governance package. I queried Depot's SecretService/ListSecrets for the org and found no GH_PACKAGES_TOKEN (or equivalent NODE_AUTH_TOKEN-backing secret) scoped to repository=wave-av/cli at all — the only GH_PACKAGES_TOKEN entry in the store is scoped to wave-av/wave-dispatch. So the token resolves empty in this repo's Depot workflow context, and the private-package install gets no auth header (matches the E401 ... no authentication token was provided message).
Fix
Provision a GH_PACKAGES_TOKEN (or whatever secret name .depot/workflows/governance-enforce.yml expects for NODE_AUTH_TOKEN) in Depot's secret store, scoped repository=wave-av/cli, with read:packages on the wave-av org so it can pull @wave-av/governance.
Scope note
Found via a triage pass across multiple repos' Depot CI check-runs (wave-av/claude-workstation#5340 has the full cross-repo table and two sibling instances of this same missing-secret pattern).
Summary
Depot CI's
governance-enforce / enforcecheck-run fails on the newest commit (d1a752d6a) at the install step, before any governance rules actually run. This is invisible from GitHub Actions — it's a Depot-authored check-run only.Receipt
Depot
CIService/GetFailureDiagnosisfor job0k5p7r35pz(governance-enforce / enforce, workflowgovernance-enforce.yml):Error message:
npm error code E401.Root cause
Same pattern as wave-av/wave-webhook-edge's
deploy / deployfailure (see wave-av/claude-workstation#5340): the workflow step'sNODE_AUTH_TOKENresolves from a Depot-secret-store value (aGH_PACKAGES_TOKEN-style secret) needed to authenticate againstnpm.pkg.github.comfor the private@wave-av/governancepackage. I queried Depot'sSecretService/ListSecretsfor the org and found noGH_PACKAGES_TOKEN(or equivalentNODE_AUTH_TOKEN-backing secret) scoped torepository=wave-av/cliat all — the onlyGH_PACKAGES_TOKENentry in the store is scoped towave-av/wave-dispatch. So the token resolves empty in this repo's Depot workflow context, and the private-package install gets no auth header (matches theE401 ... no authentication token was providedmessage).Fix
Provision a
GH_PACKAGES_TOKEN(or whatever secret name.depot/workflows/governance-enforce.ymlexpects forNODE_AUTH_TOKEN) in Depot's secret store, scopedrepository=wave-av/cli, withread:packageson thewave-avorg so it can pull@wave-av/governance.Scope note
Found via a triage pass across multiple repos' Depot CI check-runs (wave-av/claude-workstation#5340 has the full cross-repo table and two sibling instances of this same missing-secret pattern).