From 2758b2b16767e45e74129cb29ebeb2643254664a Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 05:13:15 +0100 Subject: [PATCH 1/3] fix(ci): adopt Actions dependency lockfile (estate startup_failure remediation) Estate-wide sweep applying the haec-proven template (haec#46/#48, echidna#341): actions.lock via gh actions-lock; SPDX kept on line 1 above the locker marker; hand-added lockfile entries for workflows the tool skips (reusable-only / zero-dep); standards reusables re-pinned to fcb8669169b4 (first standards ref carrying its own lockfile); illegal timeout-minutes stripped from reusable-caller jobs; SHA-pin lint made lockfile-aware. Co-Authored-By: Claude Fable 5 --- .github/workflows/actions.lock | 297 ++++++++++++++++++++++++ .github/workflows/boj-build.yml | 3 +- .github/workflows/build.yml | 5 +- .github/workflows/casket-pages.yml | 15 +- .github/workflows/ci.yml | 135 +++++------ .github/workflows/codeql.yml | 7 +- .github/workflows/container-policy.yml | 3 +- .github/workflows/dogfood-gate.yml | 15 +- .github/workflows/governance.yml | 3 +- .github/workflows/hypatia-scan.yml | 11 +- .github/workflows/instant-sync.yml | 3 +- .github/workflows/language-policy.yml | 5 +- .github/workflows/mirror.yml | 29 +-- .github/workflows/pages.yml | 9 +- .github/workflows/push-email-notify.yml | 3 +- .github/workflows/scorecard.yml | 3 +- .github/workflows/secret-scanner.yml | 11 +- 17 files changed, 435 insertions(+), 122 deletions(-) create mode 100644 .github/workflows/actions.lock diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 00000000..a7354345 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,297 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/boj-build.yml': + - 'actions/checkout@v4.1.7' + '.github/workflows/build.yml': + - 'actions/checkout@v4.3.1' + - 'sonarsource/sonarqube-scan-action@v8.1.0' + '.github/workflows/casket-pages.yml': + - 'actions/cache@v4.3.0' + - 'actions/checkout@v4.1.1' + - 'actions/configure-pages@v5.0.0' + - 'actions/deploy-pages@v4.0.5' + - 'actions/upload-pages-artifact@v3.0.1' + - 'haskell-actions/setup@v2.7.5' + '.github/workflows/ci.yml': + - 'actions/attest-build-provenance@v2.4.0' + - 'actions/cache@v4.2.3' + - 'actions/checkout@v6.0.1' + - 'actions/download-artifact@v8.0.1' + - 'actions/setup-node@v4.0.2' + - 'actions/upload-artifact@v4.4.3' + - 'codecov/codecov-action@v3.1.4' + - 'docker/build-push-action@v6.19.2' + - 'docker/login-action@v3.1.0' + - 'docker/metadata-action@v5.5.1' + - 'docker/setup-buildx-action@v3.3.0' + - 'dtolnay/rust-toolchain@stable' + - 'erlef/setup-beam@v1.18.2' + - 'github/codeql-action@v3.31.10' + - 'ludeeus/action-shellcheck@2.0.0' + - 'returntocorp/semgrep-action@v1' + - 'rustsec/audit-check@v2.0.0' + - 'softprops/action-gh-release@v2.6.2' + '.github/workflows/codeql.yml': + - 'actions/checkout@v6.0.2' + - 'github/codeql-action@v4.34.0' + '.github/workflows/container-policy.yml': + - 'actions/checkout@v6.0.1' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@v4.3.1' + - 'hyperpolymath/a2ml-ecosystem@main' + - 'hyperpolymath/k9-ecosystem@main' + '.github/workflows/governance.yml': [] + '.github/workflows/hypatia-scan.yml': + - 'actions/checkout@v6.0.2' + - 'actions/github-script@v8.0.0' + - 'actions/upload-artifact@v4.6.2' + - 'erlef/setup-beam@v1.24.0' + - 'github/codeql-action@v4.32.6' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@v4.0.1' + '.github/workflows/language-policy.yml': + - 'actions/checkout@v6.0.2' + '.github/workflows/mirror.yml': + - 'actions/checkout@v6.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'webfactory/ssh-agent@v0.9.1' + '.github/workflows/pages.yml': + - 'actions/checkout@v4.4.0' + - 'actions/deploy-pages@v4.0.5' + - 'actions/upload-pages-artifact@v3.0.1' + '.github/workflows/push-email-notify.yml': + - 'dawidd6/action-send-mail@v3.12.0' + '.github/workflows/scorecard.yml': [] + '.github/workflows/secret-scanner.yml': + - 'actions/checkout@v6.0.2' + - 'gitleaks/gitleaks-action@v2.3.9' + - 'trufflesecurity/trufflehog@v3.93.8' +dependencies: + 'actions/attest-build-provenance@1176ef556905f349f669722abf30bce1a6e16e01': + ref: 'predicate@1.1.5' + commit: 'sha1-1176ef556905f349f669722abf30bce1a6e16e01' + owner_id: 44036562 + repo_id: 760702757 + 'actions/attest-build-provenance@v2.4.0': + ref: 'v2.4.0' + commit: 'sha1-e8998f949152b193b063cb0ec769d69d929409be' + owner_id: 44036562 + repo_id: 760702757 + uses: + - 'actions/attest-build-provenance@1176ef556905f349f669722abf30bce1a6e16e01' + - 'actions/attest@ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc' + 'actions/attest@ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc': + ref: 'v2.4.0' + commit: 'sha1-ce27ba3b4a9a139d9a20a4a07d69fabb52f1e5bc' + owner_id: 44036562 + repo_id: 760701061 + 'actions/cache@v4.2.3': + ref: 'v4.2.3' + commit: 'sha1-5a3ec84eff668545956fd18022155c47e93e2684' + owner_id: 44036562 + repo_id: 215566462 + 'actions/cache@v4.3.0': + ref: 'v4.3.0' + commit: 'sha1-0057852bfaa89a56745cba8c7296529d2fc39830' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@v4.1.1': + ref: 'v4.1.1' + commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v4.1.7': + ref: 'v4.1.7' + commit: 'sha1-692973e3d937129bcbf40652eb9f2f61becf3332' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v4.3.1': + ref: 'v4.3.1' + commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v6.0.1': + ref: 'v6.0.1' + commit: 'sha1-8e8c483db84b4bee98b60c0593521ed34d9990e8' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@v6.0.2': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@v5.0.0': + ref: 'v5.0.0' + commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b' + owner_id: 44036562 + repo_id: 513659658 + 'actions/deploy-pages@v4.0.5': + ref: 'v4.0.5' + commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + owner_id: 44036562 + repo_id: 438112499 + 'actions/download-artifact@v8.0.1': + ref: 'v8.0.1' + commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c' + owner_id: 44036562 + repo_id: 192626254 + 'actions/github-script@v8.0.0': + ref: 'v8.0.0' + commit: 'sha1-ed597411d8f924073f98dfc5c65a23a2325f34cd' + owner_id: 44036562 + repo_id: 205262760 + 'actions/setup-node@v4.0.2': + ref: 'v4.0.2' + commit: 'sha1-60edb5dd545a775178f52524783378180af0d1f8' + owner_id: 44036562 + repo_id: 189476904 + 'actions/upload-artifact@v4': + ref: 'v4' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v4.4.3': + ref: 'v4.4.3' + commit: 'sha1-b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v4.6.2': + ref: 'v4.6.2' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@v3.0.1': + ref: 'v3.0.1' + commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@v4' + 'codecov/codecov-action@v3.1.4': + ref: 'v3.1.4' + commit: 'sha1-eaaf4bedf32dbdc6b720b63067d99c4d77d6047d' + owner_id: 8226205 + repo_id: 200299178 + 'dawidd6/action-send-mail@v3.12.0': + ref: 'v3.12.0' + commit: 'sha1-6e502825a508b867ab2954ad6343b68787624c01' + owner_id: 9713907 + repo_id: 222439721 + 'docker/build-push-action@v6.19.2': + ref: 'v6.19.2' + commit: 'sha1-10e90e3645eae34f1e60eeb005ba3a3d33f178e8' + owner_id: 5429470 + repo_id: 241092383 + 'docker/login-action@v3.1.0': + ref: 'v3.1.0' + commit: 'sha1-e92390c5fb421da1463c202d546fed0ec5c39f20' + owner_id: 5429470 + repo_id: 287743349 + 'docker/metadata-action@v5.5.1': + ref: 'v5.5.1' + commit: 'sha1-8e5442c4ef9f78752691e2d8f8d19755c6f78e81' + owner_id: 5429470 + repo_id: 306769011 + 'docker/setup-buildx-action@v3.3.0': + ref: 'v3.3.0' + commit: 'sha1-d70bba72b1f3fd22344832f00baa16ece964efeb' + owner_id: 5429470 + repo_id: 288485773 + 'dtolnay/rust-toolchain@stable': + ref: 'stable' + commit: 'sha1-4cda84d5c5c54efe2404f9d843567869ab1699d4' + owner_id: 1940490 + repo_id: 260749683 + 'erlef/setup-beam@v1.18.2': + ref: 'v1.18.2' + commit: 'sha1-5304e04ea2b355f03681464e683d92e3b2f18451' + owner_id: 47606891 + repo_id: 331103973 + 'erlef/setup-beam@v1.24.0': + ref: 'v1.24.0' + commit: 'sha1-fc68ffb90438ef2936bbb3251622353b3dcb2f93' + owner_id: 47606891 + repo_id: 331103973 + 'github/codeql-action@v3.31.10': + ref: 'v3.31.10' + commit: 'sha1-4bdb89f48054571735e3792627da6195c57459e2' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@v4.32.6': + ref: 'v4.32.6' + commit: 'sha1-0d579ffd059c29b07949a3cce3983f0780820c98' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@v4.34.0': + ref: 'v4.34.0' + commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + owner_id: 9919 + repo_id: 259445878 + 'gitleaks/gitleaks-action@v2.3.9': + ref: 'v2.3.9' + commit: 'sha1-ff98106e4c7b2bc287b24eaf42907196329070c7' + owner_id: 90395851 + repo_id: 242854909 + 'haskell-actions/setup@v2.7.5': + ref: 'v2.7.5' + commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900' + owner_id: 75048950 + repo_id: 623796603 + 'hyperpolymath/a2ml-ecosystem@main': + ref: 'main' + commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@main': + ref: 'main' + commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562' + owner_id: 6759885 + repo_id: 1275650185 + 'ludeeus/action-shellcheck@2.0.0': + ref: '2.0.0' + commit: 'sha1-00b27aa7cb85167568cb48a3838b75f4265f2bca' + owner_id: 15093472 + repo_id: 174679242 + 'peter-evans/repository-dispatch@v4.0.1': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' + owner_id: 18365890 + repo_id: 220359305 + 'returntocorp/semgrep-action@v1': + ref: 'v1' + commit: 'sha1-713efdd345f3035192eaa63f56867b88e63e4e5d' + owner_id: 147861678 + repo_id: 715166645 + 'rustsec/audit-check@v2.0.0': + ref: 'v2.0.0' + commit: 'sha1-69366f33c96575abad1ee0dba8212993eecbe998' + owner_id: 25397242 + repo_id: 523199201 + 'softprops/action-gh-release@v2.6.2': + ref: 'v2.6.2' + commit: 'sha1-3bb12739c298aeb8a4eeaf626c5b8d85266b0e65' + owner_id: 2242 + repo_id: 204253808 + 'sonarsource/sonarqube-scan-action@v8.1.0': + ref: 'v8.1.0' + commit: 'sha1-7006c4492b2e0ee0f816d36501671557c97f5995' + owner_id: 545988 + repo_id: 366408409 + 'trufflesecurity/trufflehog@v3.93.8': + ref: 'v3.93.8' + commit: 'sha1-6c05c4a00b91aa542267d8e32a8254774799d68d' + owner_id: 79229934 + repo_id: 77726177 + 'webfactory/ssh-agent@v0.9.1': + ref: 'v0.9.1' + commit: 'sha1-a6f90b1f127823b31d4d4a8d96047790581349bd' + owner_id: 135788 + repo_id: 208510314 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index bda0eecc..0f4012de 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger on: push: @@ -10,7 +11,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 + uses: actions/checkout@v4.1.7 - name: Trigger BoJ Server (Casket/ssg-mcp) run: | # Send a secure trigger to boj-server to build this repository diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index bd9d05f5..74cd2102 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Build on: push: @@ -18,10 +19,10 @@ jobs: if: github.actor != 'dependabot[bot]' runs-on: ubuntu-latest steps: - - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1 + - uses: actions/checkout@v4.3.1 with: fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis - name: SonarQube Scan - uses: SonarSource/sonarqube-scan-action@7006c4492b2e0ee0f816d36501671557c97f5995 # v8.1.0 + uses: SonarSource/sonarqube-scan-action@v8.1.0 env: SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }} diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 87c1e3fb..0ddccb40 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages on: @@ -21,22 +22,22 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 + uses: actions/checkout@v4.1.1 - name: Checkout casket-ssg - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 + uses: actions/checkout@v4.1.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@ec49483bfc012387b227434aba94f59a6ecd0900 # v2 + uses: haskell-actions/setup@v2.7.5 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 + uses: actions/cache@v4.3.0 with: path: | ~/.cabal/packages @@ -98,10 +99,10 @@ jobs: touch ../_site/.nojekyll - name: Setup Pages - uses: actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b # v5 + uses: actions/configure-pages@v5.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3 + uses: actions/upload-pages-artifact@v3.0.1 with: path: '_site' @@ -115,4 +116,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 + uses: actions/deploy-pages@v4.0.5 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d5d8bdb5..8b8821ad 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # GitHub Actions CI/CD Pipeline for Academic Workflow Suite # Mirror pipeline for GitHub - Matrix builds across Windows, Linux, macOS @@ -37,15 +38,15 @@ jobs: component: [core, ai-jail] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable with: components: rustfmt, clippy - name: Cache Rust dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | ~/.cargo/bin/ @@ -71,16 +72,16 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Elixir - uses: erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451 + uses: erlef/setup-beam@v1.18.2 with: elixir-version: '1.15' otp-version: '26' - name: Cache Mix dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | components/backend/deps @@ -111,10 +112,10 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Node.js - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 + uses: actions/setup-node@v4.0.2 with: node-version: '20' cache: 'npm' @@ -137,10 +138,10 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Run ShellCheck - uses: ludeeus/action-shellcheck@00b27aa7cb85167568cb48a3838b75f4265f2bca # master + uses: ludeeus/action-shellcheck@2.0.0 with: scandir: './scripts' severity: warning @@ -161,13 +162,13 @@ jobs: component: [core, ai-jail] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Rust dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | ~/.cargo/bin/ @@ -182,7 +183,7 @@ jobs: run: cargo build --release --verbose - name: Upload artifacts - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: ${{ matrix.component }}-${{ runner.os }} path: | @@ -202,16 +203,16 @@ jobs: MIX_ENV: prod steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Elixir - uses: erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451 + uses: erlef/setup-beam@v1.18.2 with: elixir-version: '1.15' otp-version: '26' - name: Cache Mix dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | components/backend/deps @@ -235,7 +236,7 @@ jobs: continue-on-error: true - name: Upload artifacts - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: elixir-backend path: components/backend/_build/prod/ @@ -250,10 +251,10 @@ jobs: needs: [lint-node] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Node.js - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 + uses: actions/setup-node@v4.0.2 with: node-version: '20' cache: 'npm' @@ -269,7 +270,7 @@ jobs: continue-on-error: true - name: Upload artifacts - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: office-addin path: | @@ -293,13 +294,13 @@ jobs: component: [core, ai-jail] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Rust dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | ~/.cargo/bin/ @@ -315,7 +316,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: test-results-${{ matrix.component }}-${{ runner.os }} path: components/${{ matrix.component }}/target/nextest/ @@ -332,16 +333,16 @@ jobs: MIX_ENV: test steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Elixir - uses: erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451 + uses: erlef/setup-beam@v1.18.2 with: elixir-version: '1.15' otp-version: '26' - name: Cache Mix dependencies - uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4 + uses: actions/cache@v4.2.3 with: path: | components/backend/deps @@ -360,7 +361,7 @@ jobs: run: mix test --cover --trace - name: Upload coverage - uses: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d + uses: codecov/codecov-action@v3.1.4 with: token: ${{ secrets.CODECOV_TOKEN }} files: components/backend/cover/cobertura.xml @@ -376,10 +377,10 @@ jobs: needs: [build-office-addin] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Node.js - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 + uses: actions/setup-node@v4.0.2 with: node-version: '20' cache: 'npm' @@ -395,7 +396,7 @@ jobs: continue-on-error: true - name: Upload coverage - uses: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d + uses: codecov/codecov-action@v3.1.4 with: token: ${{ secrets.CODECOV_TOKEN }} files: components/office-addin/coverage/cobertura-coverage.xml @@ -412,22 +413,22 @@ jobs: needs: [build-rust, build-elixir] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download core artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: name: core-Linux path: components/core/target/release/ - name: Download AI jail artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: name: ai-jail-Linux path: components/ai-jail/target/release/ - name: Download backend artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: name: elixir-backend path: components/backend/_build/prod/ @@ -443,7 +444,7 @@ jobs: - name: Upload test results if: always() - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: integration-test-results path: tests/integration/results/ @@ -458,10 +459,10 @@ jobs: needs: [build-rust] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download AI jail artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: name: ai-jail-Linux path: components/ai-jail/target/release/ @@ -491,10 +492,10 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Run cargo-audit - uses: rustsec/audit-check@69366f33c96575abad1ee0dba8212993eecbe998 # v2 + uses: rustsec/audit-check@v2.0.0 with: token: ${{ secrets.GITHUB_TOKEN }} @@ -506,10 +507,10 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Setup Node.js - uses: actions/setup-node@60edb5dd545a775178f52524783378180af0d1f8 + uses: actions/setup-node@v4.0.2 with: node-version: '20' @@ -533,15 +534,15 @@ jobs: language: ['javascript', 'python'] steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@4bdb89f48054571735e3792627da6195c57459e2 # v3.31.10 + uses: github/codeql-action/init@v3.31.10 with: languages: ${{ matrix.language }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@4bdb89f48054571735e3792627da6195c57459e2 # v3.31.10 + uses: github/codeql-action/analyze@v3.31.10 security-semgrep: name: Semgrep SAST @@ -551,10 +552,10 @@ jobs: contents: read steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Run Semgrep - uses: returntocorp/semgrep-action@713efdd345f3035192eaa63f56867b88e63e4e5d # v1 + uses: returntocorp/semgrep-action@v1 with: config: >- p/security-audit @@ -575,10 +576,10 @@ jobs: if: github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v') steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download all artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 - name: Install packaging tools run: | @@ -591,7 +592,7 @@ jobs: ./scripts/ci/package.sh deb - name: Upload package - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: debian-package path: packages/*.deb @@ -605,10 +606,10 @@ jobs: if: github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v') steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download Windows artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: pattern: '*-Windows' @@ -619,7 +620,7 @@ jobs: # Add MSI creation logic here - name: Upload package - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: windows-installer path: packages/*.msi @@ -633,10 +634,10 @@ jobs: if: github.ref == 'refs/heads/main' || startsWith(github.ref, 'refs/tags/v') steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download macOS artifacts - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: pattern: '*-macOS' @@ -646,7 +647,7 @@ jobs: # Add DMG creation logic here - name: Upload package - uses: actions/upload-artifact@b4b15b8c7c6ac21ea08fcf65892d2ee8f75cf882 + uses: actions/upload-artifact@v4.4.3 with: name: macos-dmg path: packages/*.dmg @@ -665,13 +666,13 @@ jobs: attestations: write steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@d70bba72b1f3fd22344832f00baa16ece964efeb + uses: docker/setup-buildx-action@v3.3.0 - name: Login to GitHub Container Registry - uses: docker/login-action@e92390c5fb421da1463c202d546fed0ec5c39f20 + uses: docker/login-action@v3.1.0 with: registry: ghcr.io username: ${{ github.actor }} @@ -679,7 +680,7 @@ jobs: - name: Extract metadata id: meta - uses: docker/metadata-action@8e5442c4ef9f78752691e2d8f8d19755c6f78e81 + uses: docker/metadata-action@v5.5.1 with: images: ghcr.io/${{ github.repository }}/ai-jail tags: | @@ -691,7 +692,7 @@ jobs: - name: Build and push id: push - uses: docker/build-push-action@2cdde99a3119a254ab45fdc0080f486226e63283 + uses: docker/build-push-action@v6.19.2 with: context: components/ai-jail push: true @@ -701,7 +702,7 @@ jobs: cache-to: type=gha,mode=max - name: Attest container provenance - uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 + uses: actions/attest-build-provenance@v2.4.0 with: subject-name: ghcr.io/${{ github.repository }}/ai-jail subject-digest: ${{ steps.push.outputs.digest }} @@ -723,10 +724,10 @@ jobs: attestations: write steps: - name: Checkout code - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + uses: actions/checkout@v6.0.1 - name: Download all packages - uses: actions/download-artifact@c850b930e6ba138125429b7e5c93fc707cb86dac + uses: actions/download-artifact@v8.0.1 with: path: release-artifacts @@ -736,7 +737,7 @@ jobs: find . -type f \( -name "*.deb" -o -name "*.msi" -o -name "*.dmg" -o -name "*.tgz" \) -exec sha256sum {} \; > SHA256SUMS - name: Create Release - uses: softprops/action-gh-release@1e07f439872118af462529de807ee157f4951b14 + uses: softprops/action-gh-release@v2.6.2 with: files: | release-artifacts/**/*.deb @@ -751,7 +752,7 @@ jobs: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - name: Attest build provenance - uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2 + uses: actions/attest-build-provenance@v2.4.0 with: subject-path: | release-artifacts/**/*.deb diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b43f56e6..e6f88a0c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: @@ -36,15 +37,15 @@ jobs: steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@v6.0.2 - name: Initialize CodeQL - uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 + uses: github/codeql-action/init@v4.34.0 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 + uses: github/codeql-action/analyze@v4.34.0 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/container-policy.yml b/.github/workflows/container-policy.yml index 4e71098e..8aa83ba9 100644 --- a/.github/workflows/container-policy.yml +++ b/.github/workflows/container-policy.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Container Policy on: push: @@ -21,7 +22,7 @@ jobs: timeout-minutes: 15 steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 + - uses: actions/checkout@v6.0.1 - name: Enforce container policy run: | # Block new Dockerfiles diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 6651a21f..2f7f47e5 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate @@ -26,7 +27,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@v4.3.1 - name: Check for A2ML files id: detect @@ -39,7 +40,7 @@ jobs: - name: Validate A2ML manifests if: steps.detect.outputs.count > 0 - uses: hyperpolymath/a2ml-ecosystem/validate-action@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79 # main + uses: hyperpolymath/a2ml-ecosystem/validate-action@main with: path: '.' strict: 'false' @@ -71,7 +72,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@v4.3.1 - name: Check for K9 files id: detect @@ -88,7 +89,7 @@ jobs: - name: Validate K9 contracts if: steps.detect.outputs.k9_count > 0 - uses: hyperpolymath/k9-ecosystem/validate-action@89f3c2702f4f650a92aa7411502f38da06abd562 # main + uses: hyperpolymath/k9-ecosystem/validate-action@main with: path: '.' strict: 'false' @@ -121,7 +122,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@v4.3.1 - name: Scan for invisible characters id: lint @@ -186,7 +187,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@v4.3.1 - name: Check for Groove manifest id: groove @@ -247,7 +248,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 + uses: actions/checkout@v4.3.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 156264a8..eec5498d 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # governance.yml — single wrapper calling the shared estate governance bundle # in hyperpolymath/standards instead of carrying per-repo copies. # @@ -31,4 +32,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 127905d2..315ee08d 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Hypatia Neurosymbolic CI/CD Security Scan name: Hypatia Security Scan @@ -47,12 +48,12 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@v6.0.2 with: fetch-depth: 0 # Full history for better pattern analysis - name: Setup Elixir for Hypatia scanner - uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.18.2 + uses: erlef/setup-beam@v1.24.0 with: elixir-version: '1.18' otp-version: '27' @@ -106,7 +107,7 @@ jobs: echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY - name: Upload findings artifact - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2 + uses: actions/upload-artifact@v4.6.2 with: name: hypatia-findings path: hypatia-findings.json @@ -242,7 +243,7 @@ jobs: always() && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.fork != true) - uses: github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v3.28.1 + uses: github/codeql-action/upload-sarif@v4.32.6 with: sarif_file: hypatia.sarif # Distinct category so Hypatia results coexist with CodeQL's @@ -382,7 +383,7 @@ jobs: # the pull-requests: write permission above: a token/API hiccup or # a fork PR (read-only token) skips the comment, not the check. continue-on-error: true - uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v7 + uses: actions/github-script@v8.0.0 with: script: | const fs = require('fs'); diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 01646a74..2df97776 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync @@ -17,7 +18,7 @@ jobs: timeout-minutes: 15 steps: - name: Trigger Propagation - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3 + uses: peter-evans/repository-dispatch@v4.0.1 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/language-policy.yml b/.github/workflows/language-policy.yml index 86e3ba12..3f9256cc 100644 --- a/.github/workflows/language-policy.yml +++ b/.github/workflows/language-policy.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Language Policy Enforcement on: @@ -25,7 +26,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 + uses: actions/checkout@v6.0.2 # TypeScript check delegated to rsr-antipattern.yml (which honours the # universal allowlist and the .claude/CLAUDE.md exemptions table). The @@ -149,7 +150,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 + uses: actions/checkout@v6.0.2 - name: Check for .machine_readable directory run: | diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index b6317c3f..bebce710 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: @@ -15,11 +16,11 @@ jobs: timeout-minutes: 15 if: vars.GITLAB_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.GITLAB_SSH_KEY }} @@ -34,11 +35,11 @@ jobs: timeout-minutes: 15 if: vars.BITBUCKET_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.BITBUCKET_SSH_KEY }} @@ -53,11 +54,11 @@ jobs: timeout-minutes: 15 if: vars.CODEBERG_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.CODEBERG_SSH_KEY }} @@ -72,11 +73,11 @@ jobs: timeout-minutes: 15 if: vars.SOURCEHUT_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.SOURCEHUT_SSH_KEY }} @@ -91,11 +92,11 @@ jobs: timeout-minutes: 15 if: vars.DISROOT_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.DISROOT_SSH_KEY }} @@ -110,11 +111,11 @@ jobs: timeout-minutes: 15 if: vars.GITEA_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - - uses: webfactory/ssh-agent@a6f90b1f127823b31d4d4a8d96047790581349bd # v0.9.1 + - uses: webfactory/ssh-agent@v0.9.1 with: ssh-private-key: ${{ secrets.GITEA_SSH_KEY }} @@ -129,12 +130,12 @@ jobs: timeout-minutes: 15 if: vars.RADICLE_MIRROR_ENABLED == 'true' steps: - - uses: actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v4 + - uses: actions/checkout@v6.0.1 with: fetch-depth: 0 - name: Setup Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable # stable + uses: dtolnay/rust-toolchain@stable # stable with: toolchain: stable diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index c78489a6..bd3de647 100755 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages (Ddraig SSG) on: push: @@ -19,9 +20,9 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff steps: - name: Checkout Site - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@v4.4.0 - name: Checkout Ddraig SSG - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + uses: actions/checkout@v4.4.0 with: repository: hyperpolymath/ddraig-ssg path: .ddraig-ssg @@ -38,7 +39,7 @@ jobs: fi ./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/} - name: Upload artifact - uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3 + uses: actions/upload-pages-artifact@v3.0.1 with: path: '_site' deploy: @@ -51,4 +52,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4 + uses: actions/deploy-pages@v4.0.5 diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 4b4e754b..b69c87f3 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by @@ -15,7 +16,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Send push notification email - uses: dawidd6/action-send-mail@6e502825a508b867ab2954ad6343b68787624c01 # pinned + uses: dawidd6/action-send-mail@v3.12.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 64ac2acf..3e3a20c9 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Scorecards supply-chain security on: @@ -12,7 +13,7 @@ permissions: read-all jobs: analysis: - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 permissions: contents: read security-events: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index ea2fe8ae..13c3897e 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Secret Scanner on: @@ -18,12 +19,12 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 + - uses: actions/checkout@v6.0.2 with: fetch-depth: 0 # Full history for scanning - name: TruffleHog Secret Scan - uses: trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d # v3 + uses: trufflesecurity/trufflehog@v3.93.8 with: # The v3 action injects --fail automatically on pull_request events. # Passing --fail here triggers "flag 'fail' cannot be repeated". @@ -33,12 +34,12 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 + - uses: actions/checkout@v6.0.2 with: fetch-depth: 0 - name: Gitleaks Secret Scan - uses: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7 # v2 + uses: gitleaks/gitleaks-action@v2.3.9 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} @@ -47,7 +48,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 + - uses: actions/checkout@v6.0.2 - name: Check for hardcoded secrets in Rust run: | From 3c6fb7ac8f6d3125a2f18d53e086fbba4d760813 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 05:17:35 +0100 Subject: [PATCH 2/3] fix(ci): bump standards re-pin to bd0df9e (lockfile-aware governance lint) Co-Authored-By: Claude Fable 5 --- .github/workflows/governance.yml | 2 +- .github/workflows/scorecard.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index eec5498d..bfd41ed9 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -32,4 +32,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4 diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 3e3a20c9..31648029 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -13,7 +13,7 @@ permissions: read-all jobs: analysis: - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@fcb8669169b4e9f5d9848608df880ae5fae812b4 + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@bd0df9ead7faf0cdfe0e13e7966d91e28d0101d4 permissions: contents: read security-events: write From 2a830e601d8081389e017d512a5a0582c015b5b2 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 4 Aug 2026 05:31:20 +0100 Subject: [PATCH 3/3] fix(ci): grant wrappers the permission union their reusables demand MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit At standards >= fcb8669 the governance/hypatia/mirror/scorecard reusables declare actions: read (hypatia adds security-events: write; scorecard adds id-token/security-events write). A reusable requesting more than its caller grants is a startup_failure — the third enforcement layer after the lockfile and the caller entries. Co-Authored-By: Claude Fable 5 --- .github/workflows/governance.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index bfd41ed9..e978b3ff 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -28,6 +28,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: