diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 0000000..ef1d66e --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,172 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/boj-build.yml': + - 'actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332' + '.github/workflows/casket-pages.yml': + - 'actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b' + - 'actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + - 'actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b' + - 'haskell-actions/setup@f9150cb1d140e9a9271700670baa38991e6fa25c' + '.github/workflows/cflite_batch.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@38697555549f1db7851b81482ff19f1fa5c4fedc' + - 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1' + '.github/workflows/cflite_pr.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@38697555549f1db7851b81482ff19f1fa5c4fedc' + - 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1' + '.github/workflows/codeql.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' + - 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + - 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562' + '.github/workflows/hypatia-scan.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd' + - 'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02' + - 'erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93' + - 'github/codeql-action@0d579ffd059c29b07949a3cce3983f0780820c98' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697' + '.github/workflows/mirror.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9' + - 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555' + '.github/workflows/pages.yml': + - 'actions/checkout@11d5960a326750d5838078e36cf38b85af677262' + - 'actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + - 'actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa' + '.github/workflows/push-email-notify.yml': + - 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' +dependencies: + 'actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7': + ref: 'v5.0.4' + commit: 'sha1-668228422ae6a00e4ad889ee87cd7109ec5666a7' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@11d5960a326750d5838078e36cf38b85af677262': + ref: 'v4.4.0' + commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5': + ref: 'v4.3.1' + commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332': + ref: 'v4.1.7' + commit: 'sha1-692973e3d937129bcbf40652eb9f2f61becf3332' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b': + ref: 'v5.0.0' + commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b' + owner_id: 44036562 + repo_id: 513659658 + 'actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e': + ref: 'v4.0.5' + commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + owner_id: 44036562 + repo_id: 438112499 + 'actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd': + ref: 'v8.0.0' + commit: 'sha1-ed597411d8f924073f98dfc5c65a23a2325f34cd' + owner_id: 44036562 + repo_id: 205262760 + 'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02': + ref: 'v4.6.2' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v4': + ref: 'v4' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa': + ref: 'v3.0.1' + commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@v4' + 'actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b': + ref: 'v4.0.0' + commit: 'sha1-7b1f4a764d45c48632c6b24a0339c27f5614fb0b' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02' + 'dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9': + ref: 'master' + commit: 'sha1-efa25f7f19611383d5b0ccf2d1c8914531636bf9' + owner_id: 1940490 + repo_id: 260749683 + 'erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93': + ref: 'v1.24.0' + commit: 'sha1-fc68ffb90438ef2936bbb3251622353b3dcb2f93' + owner_id: 47606891 + repo_id: 331103973 + 'github/codeql-action@0d579ffd059c29b07949a3cce3983f0780820c98': + ref: 'v4.32.6' + commit: 'sha1-0d579ffd059c29b07949a3cce3983f0780820c98' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@38697555549f1db7851b81482ff19f1fa5c4fedc': + ref: 'v4.34.1' + commit: 'sha1-38697555549f1db7851b81482ff19f1fa5c4fedc' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745': + ref: 'v4.34.0' + commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + owner_id: 9919 + repo_id: 259445878 + 'google/clusterfuzzlite@884713a6c30a92e5e8544c39945cd7cb630abcd1': + ref: 'v1' + commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1' + owner_id: 1342004 + repo_id: 400046858 + 'haskell-actions/setup@f9150cb1d140e9a9271700670baa38991e6fa25c': + ref: 'v2.10.3' + commit: 'sha1-f9150cb1d140e9a9271700670baa38991e6fa25c' + owner_id: 75048950 + repo_id: 623796603 + 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79': + ref: 'main' + commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562': + ref: 'main' + commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562' + owner_id: 6759885 + repo_id: 1275650185 + 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7': + ref: 'v0.2.0' + commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + owner_id: 6759885 + repo_id: 1352485172 + 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' + owner_id: 18365890 + repo_id: 220359305 + 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555': + ref: 'v0.10.0' + commit: 'sha1-e83874834305fe9a4a2997156cb26c5de65a8555' + owner_id: 135788 + repo_id: 208510314 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 1857846..e615b93 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: BoJ Server Build Trigger diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 1931ec5..d10edfe 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: GitHub Pages diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index 04ce6b1..00318a2 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: ClusterFuzzLite Batch diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 9e457fd..5e13f8d 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: ClusterFuzzLite PR diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 60d32e3..41aff70 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: CodeQL Security Analysis diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 9948d9c..a8d9986 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 0849576..f694815 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 # governance.yml — single wrapper calling the shared estate governance bundle diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 0e19a98..fba8274 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 # Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index cb1c54b..4ff9d25 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 # Instant Forge Sync - Triggers propagation to all forges on push/release diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..fc79947 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Label Triage # Classify newly-filed issues against the estate label taxonomy. diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..af34c6b 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Labels # Applies the canonical estate label set from .github/labels.json. diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index bca0066..7500820 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 name: Mirror to Git Forges diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml old mode 100755 new mode 100644 index 0273437..fb2b502 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages (Ddraig SSG) on: push: diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 0689291..80c6942 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 1ac0892..8f4cc22 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # // Copyright (c) Jonathan D.A. Jewell # SPDX-License-Identifier: MPL-2.0 # Rust CI — thin wrapper calling the shared estate reusable in diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 64ac2ac..7b61058 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Scorecards supply-chain security on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 437776e..d3f6bb1 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Calls the estate's shared secret scanner (gitleaks + rust-secrets + # shell-secrets). Replaces an inline trufflehog job: trufflehog was retired # estate-wide as redundant, and this repo had no other leak scanning, so the