chore(deps): bump haskell-actions/setup from 2.12.0 to 2.12.1 in the actions group - #70
Merged
Conversation
Bumps the actions group with 1 update: [haskell-actions/setup](https://github.com/haskell-actions/setup). Updates `haskell-actions/setup` from 2.12.0 to 2.12.1 - [Release notes](https://github.com/haskell-actions/setup/releases) - [Commits](haskell-actions/setup@v2.12.0...v2.12.1) --- updated-dependencies: - dependency-name: haskell-actions/setup dependency-version: 2.12.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 26, 2026
hyperpolymath
deleted the
dependabot/github_actions/actions-c51f25f9ce
branch
September 26, 2026 00:25
hyperpolymath
added a commit
that referenced
this pull request
Sep 27, 2026
…s with a written determination (#67) (#72) Closes #67. ## What #67 asked, and the answers | Check | Determination | Red on `main` too? | |---|---|---| | `core-fill-tests` | **Retired** | Yes — since #43 (2026-08-24) deleted `deno.json`, a month before #66. Its task was `cargo test … fill_blocks_`, a strict subset of the `rust-core` job. | | `extension-build` | **Retired** | Yes — same #43 deletion; the bundle toolchain is not in the checkout at all. Comes back under a new name when the frontend has a pipeline. | Neither was in a required-check set (the repo's rulesets have no `required_status_checks` rule). Nothing was muted: no `continue-on-error`, no demotion, and the full ledger with a review date is in `docs/ci/CHECK-DETERMINATIONS.adoc`. ## The larger thing underneath it At `main` = d50a857, **all nine** push-triggered workflows were `startup_failure`, jobs=0 — including the Lock Sync Gate and the CI workflow that would run any check at all. Four consecutive merges after #66 rewrote `uses:` refs without touching `actions.lock`: - #69 (Dependabot) bumped codeql-action to `1c5b675` (= **v4.38.1**, the held version) → killed `codeql.yml`, `hypatia-scan.yml`. It got through the hold because the ignore was `github/codeql-action`, which does not match the `/init`, `/analyze`, `/upload-sarif` subpath names Dependabot tracks. Merged with the gate red. - #70 (Dependabot) bumped haskell-actions/setup → killed `casket-pages.yml`. Merged with the gate red. - #71 replaced the `ci.yml` jobs, leaving stale `setup-deno`/`wasm-pack-action` lock entries → killed `ci.yml`. By then the gate was already dead from #69/#70, so nothing could flag it. ## Changes - **`actions.lock`** resynchronised and transitively closed — `scripts/check-lock-sync.sh` exits 0 on all four clauses. - **`codeql.yml` / `hypatia-scan.yml`**: re-pinned to `b96794f` (true v4.38.0), restoring the hold #64 set and #68 re-asserted. The `# v4.38.0` comment Dependabot left next to the 4.38.1 SHA was false; it is now true. - **`dependabot.yml`**: ignore glob `github/codeql-action*` (estate-canonical form from `hyperpolymath/standards`), weekly cadence, `open-pull-requests-limit: 2`, header explaining the lock contract. - **`ci.yml`**: `rust-core` kept; the duplicate `workflow-lock` job dropped — it ran inside a workflow GitHub refuses to start on exactly the fault it checked, so it could never report. `lock-sync-gate.yml` (no `uses:`) is the authoritative gate. - **`docs/ci/CHECK-DETERMINATIONS.adoc`**: the ledger, root-cause table, standing rules, review date 2026-12-27. - `TEST-NEEDS.adoc`, `TOPOLOGY.adoc`, `CHANGELOG.adoc`: stop describing a Deno/Jest pipeline that does not exist. ## Verification - `scripts/check-lock-sync.sh` → `actions.lock is in sync and transitively closed` (run locally with gawk). - All workflow YAML parses. - `rust-core` has **never** had a run that reached execution (every prior `ci.yml` run was a Deno failure or a startup failure), and this sandbox cannot reach crates.io, so **this PR's checks are the first real run**. If `rust-core` is red here, that is a genuine finding about the crate and I will fix it in this PR rather than merge over it. ## Owner action that this PR cannot do (needs admin) Add `actions.lock is in sync with the workflow YAML` and `Rust core (tests, formatting, lint)` as **required status checks** on `main`. #69 and #70 were merged by hand with the gate red; without a required-check rule the standing rule "never merge over a red gate" is a convention, not an enforcement. This is the piece that makes the fix permanent. --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 1 update: haskell-actions/setup.
Updates
haskell-actions/setupfrom 2.12.0 to 2.12.1Release notes
Sourced from haskell-actions/setup's releases.
Commits
0f8e8c9Add Cabal 3.18.1.0 and Stack 3.11.1Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions