Skip to content

chore(deps): bump haskell-actions/setup from 2.12.0 to 2.12.1 in the actions group - #70

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-c51f25f9ce
Sep 26, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-c51f25f9ce

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: haskell-actions/setup.

Updates haskell-actions/setup from 2.12.0 to 2.12.1

Release notes

Sourced from haskell-actions/setup's releases.

v2.12.1

Add Cabal 3.18.1.0 and Stack 3.11.1

What's Changed

Full Changelog: haskell-actions/setup@v2.12.0...v2.12.1

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [haskell-actions/setup](https://github.com/haskell-actions/setup).


Updates `haskell-actions/setup` from 2.12.0 to 2.12.1
- [Release notes](https://github.com/haskell-actions/setup/releases)
- [Commits](haskell-actions/setup@v2.12.0...v2.12.1)

---
updated-dependencies:
- dependency-name: haskell-actions/setup
  dependency-version: 2.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Sep 25, 2026
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 687e4a61-b66b-47a6-81d7-c2b70519ca3e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit a0e8674 into main Sep 26, 2026
22 of 26 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-c51f25f9ce branch September 26, 2026 00:25
hyperpolymath added a commit that referenced this pull request Sep 27, 2026
…s with a written determination (#67) (#72)

Closes #67.

## What #67 asked, and the answers

| Check | Determination | Red on `main` too? |
|---|---|---|
| `core-fill-tests` | **Retired** | Yes — since #43 (2026-08-24) deleted
`deno.json`, a month before #66. Its task was `cargo test …
fill_blocks_`, a strict subset of the `rust-core` job. |
| `extension-build` | **Retired** | Yes — same #43 deletion; the bundle
toolchain is not in the checkout at all. Comes back under a new name
when the frontend has a pipeline. |

Neither was in a required-check set (the repo's rulesets have no
`required_status_checks` rule). Nothing was muted: no
`continue-on-error`, no demotion, and the full ledger with a review date
is in `docs/ci/CHECK-DETERMINATIONS.adoc`.

## The larger thing underneath it

At `main` = d50a857, **all nine** push-triggered workflows were
`startup_failure`, jobs=0 — including the Lock Sync Gate and the CI
workflow that would run any check at all. Four consecutive merges after
#66 rewrote `uses:` refs without touching `actions.lock`:

- #69 (Dependabot) bumped codeql-action to `1c5b675` (= **v4.38.1**, the
held version) → killed `codeql.yml`, `hypatia-scan.yml`. It got through
the hold because the ignore was `github/codeql-action`, which does not
match the `/init`, `/analyze`, `/upload-sarif` subpath names Dependabot
tracks. Merged with the gate red.
- #70 (Dependabot) bumped haskell-actions/setup → killed
`casket-pages.yml`. Merged with the gate red.
- #71 replaced the `ci.yml` jobs, leaving stale
`setup-deno`/`wasm-pack-action` lock entries → killed `ci.yml`. By then
the gate was already dead from #69/#70, so nothing could flag it.

## Changes

- **`actions.lock`** resynchronised and transitively closed —
`scripts/check-lock-sync.sh` exits 0 on all four clauses.
- **`codeql.yml` / `hypatia-scan.yml`**: re-pinned to `b96794f` (true
v4.38.0), restoring the hold #64 set and #68 re-asserted. The `#
v4.38.0` comment Dependabot left next to the 4.38.1 SHA was false; it is
now true.
- **`dependabot.yml`**: ignore glob `github/codeql-action*`
(estate-canonical form from `hyperpolymath/standards`), weekly cadence,
`open-pull-requests-limit: 2`, header explaining the lock contract.
- **`ci.yml`**: `rust-core` kept; the duplicate `workflow-lock` job
dropped — it ran inside a workflow GitHub refuses to start on exactly
the fault it checked, so it could never report. `lock-sync-gate.yml` (no
`uses:`) is the authoritative gate.
- **`docs/ci/CHECK-DETERMINATIONS.adoc`**: the ledger, root-cause table,
standing rules, review date 2026-12-27.
- `TEST-NEEDS.adoc`, `TOPOLOGY.adoc`, `CHANGELOG.adoc`: stop describing
a Deno/Jest pipeline that does not exist.

## Verification

- `scripts/check-lock-sync.sh` → `actions.lock is in sync and
transitively closed` (run locally with gawk).
- All workflow YAML parses.
- `rust-core` has **never** had a run that reached execution (every
prior `ci.yml` run was a Deno failure or a startup failure), and this
sandbox cannot reach crates.io, so **this PR's checks are the first real
run**. If `rust-core` is red here, that is a genuine finding about the
crate and I will fix it in this PR rather than merge over it.

## Owner action that this PR cannot do (needs admin)

Add `actions.lock is in sync with the workflow YAML` and `Rust core
(tests, formatting, lint)` as **required status checks** on `main`. #69
and #70 were merged by hand with the gate red; without a required-check
rule the standing rule "never merge over a red gate" is a convention,
not an enforcement. This is the piece that makes the fix permanent.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant