Skip to content

fix(actions): validate composite dependencies under native runner locking - #6

Merged
hyperpolymath merged 5 commits into
mainfrom
codex/science-ci-20260909
Sep 10, 2026
Merged

fix(actions): validate composite dependencies under native runner locking#6
hyperpolymath merged 5 commits into
mainfrom
codex/science-ci-20260909

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Fraying PR #65 passed gh actions-lock verification but GitHub rejected startup because the nested K9 SHA reference had no matching runtime lock entry. Align nested validator refs with the native locked references, and onboard the suite self-tests and estate audit to GitHub action locking. The same composite gate now exercises valid A2ML/K9 fixtures and deliberate failures with runtime lock enforcement active. Full authoritative lock verification passes for all four workflows. This follows #5 and preserves real validator failures.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 60d9c6c5-4998-4237-a5d2-a5ce93eb731b

📥 Commits

Reviewing files that changed from the base of the PR and between 5eb5ae8 and f2e4f8c.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • .github/workflows/code-hygiene-self-test.yml
  • .github/workflows/label-triage.yml
  • .github/workflows/labels.yml
  • .github/workflows/main-estate-audit.yml
  • actions/manifest-check/action.yml

📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated workflow management metadata and action references.
    • Added a 10-minute limit to one automated validation workflow.
    • Updated checkout and validation action version references.
    • Standardised gate and manifest validation workflow references.

Walkthrough

The changes update workflow metadata and action references. They add a test timeout, replace local action paths, update checkout references, and change manifest validators to use their main branches.

Changes

Workflow maintenance

Layer / File(s) Summary
Workflow reference and execution updates
.github/workflows/*.yml
Workflows add gh actions-lock headers. The self-test adds a 10-minute timeout. Checkout references use v7.0.1, and local action paths use $/actions/....
Manifest validator references
actions/manifest-check/action.yml
The validation steps use hyperpolymath/deed-ecosystem/validate-action@main and hyperpolymath/k9-ecosystem/validate-action@main. Existing inputs remain unchanged.

Estimated code review effort: 2 (Simple) | ~10 minutes


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

I hop through workflows, neat and bright
Tags now guide the actions right
Validators follow branches green
Ten minutes guard the testing scene
Squeak, the manifests pass clean

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 0405f13 into main Sep 10, 2026
4 of 5 checks passed
@hyperpolymath
hyperpolymath deleted the codex/science-ci-20260909 branch September 10, 2026 01:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant