Skip to content

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) - #113

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/sha-pin-actions
Sep 20, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/sha-pin-actions

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6)

actions.lock is authoritative: the workflows carry readable refs and the lock records the
commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable — startup_failure, "Invalid lockfile".

Regenerated with the official extension (github/gh-actions-lock). The hand-pinned SHA refs are
reverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.

…0.1.6)

`actions.lock` is authoritative: the workflows carry readable refs and the lock records the
commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable — `startup_failure`, "Invalid lockfile".

Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are
reverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 9a74ca66-cea6-49ed-8945-19cea85283bc

📥 Commits

Reviewing files that changed from the base of the PR and between f4725d2 and 249faac.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (20)
  • .github/workflows/bench.yml
  • .github/workflows/boj-build.yml
  • .github/workflows/casket-pages.yml
  • .github/workflows/ci.yml
  • .github/workflows/codeql.yml
  • .github/workflows/dependabot-automerge.yml
  • .github/workflows/dogfood-gate.yml
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/instant-sync.yml
  • .github/workflows/label-triage.yml
  • .github/workflows/labels.yml
  • .github/workflows/mirror.yml
  • .github/workflows/pages.yml
  • .github/workflows/push-email-notify.yml
  • .github/workflows/release.yml
  • .github/workflows/rust-ci.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml
  • .github/workflows/security.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (21)
  • GitHub Check: governance / Well-Known (RFC 9116 + RSR)
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Check Workflow Staleness
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Allowlist Preflight
  • GitHub Check: governance / Security policy checks
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: governance / Trusted-base reduction policy
  • GitHub Check: governance / Guix packaging policy (Nix retired)
  • GitHub Check: scan / gitleaks
  • GitHub Check: scan / rust-secrets
  • GitHub Check: scan / shell-secrets
  • GitHub Check: rust-ci / Detect Cargo.toml
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: Test
  • GitHub Check: analyze (actions, none)
⚠️ CI failures not shown inline (6)

GitHub Actions: Dogfood Gate / 1_Validate A2ML manifests.txt: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]GITHUB_TOKEN Permissions
 Actions: read
 Contents: read
 Metadata: read
 ##[endgroup]
 Secret source: Actions
 Cache mode: write
 Using locked action versions from the workflow's lockfile
 Prepare workflow directory
 Prepare all required actions
 Getting action download info
 ##[error]Unable to resolve action `hyperpolymath/a2ml-ecosystem`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile. lockfile verification did not produce a result for this action

GitHub Actions: Dogfood Gate / Validate A2ML manifests: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]GITHUB_TOKEN Permissions
 Actions: read
 Contents: read
 Metadata: read
 ##[endgroup]
 Secret source: Actions
 Cache mode: write
 Using locked action versions from the workflow's lockfile
 Prepare workflow directory
 Prepare all required actions
 Getting action download info
 ##[error]Unable to resolve action `hyperpolymath/a2ml-ecosystem`: the repository has been renamed or transferred. Run `gh actions-lock` to update the lockfile. lockfile verification did not produce a result for this action

GitHub Actions: Dogfood Gate / 2_Validate eclexiaiser manifest.txt: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]Run if [ ! -f "eclexiaiser.toml" ]; then
 �[36;1mif [ ! -f "eclexiaiser.toml" ]; then�[0m
 �[36;1m  # Check if repo has a Containerfile — if so, recommend eclexiaiser�[0m
 �[36;1m  if [ -f "Containerfile" ]; then�[0m
 �[36;1m    echo "::warning::Containerfile present but no eclexiaiser.toml. Run \`eclexiaiser init\` to scaffold energy/carbon budgets."�[0m
 �[36;1m  fi�[0m
 �[36;1m  echo "has_manifest=false" >> "$GITHUB_OUTPUT"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1m�[0m
 �[36;1mecho "has_manifest=true" >> "$GITHUB_OUTPUT"�[0m
 �[36;1m�[0m
 �[36;1m# Validate TOML structure using pre-installed yq�[0m
 �[36;1m(�[0m
 �[36;1m  PROJECT_NAME=$(yq -e '.project.name // ""' eclexiaiser.toml)�[0m
 �[36;1m  if [ -z "$PROJECT_NAME" ]; then�[0m
 �[36;1m      echo "ERROR: project.name is required" >&2�[0m
 �[36;1m      exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m�[0m
 �[36;1m  FUNCTIONS_LEN=$(yq -e '.functions | length' eclexiaiser.toml)�[0m
 �[36;1m  if [ -z "$FUNCTIONS_LEN" ] || [ "$FUNCTIONS_LEN" -eq 0 ]; then�[0m
 �[36;1m      echo "ERROR: at least one [[functions]] entry is required" >&2�[0m
 �[36;1m      exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m�[0m
 �[36;1m  for i in $(seq 0 $((FUNCTIONS_LEN - 1))); do�[0m
 �[36;1m      FN_NAME=$(yq -e ".functions[$i].name // \"\"" eclexiaiser.toml)�[0m
 �[36;1m      if [ -z "$FN_NAME" ]; then�[0m
 �[36;1m          echo "ERROR: function name cannot be empty" >&2�[0m
 �[36;1m          exit 1�[0m
 �[36;1m      fi�[0m
 �[36;1m      FN_SRC=$(yq -e ".functions[$i].source // \"\"" eclexiaiser.toml)�[0m
 �[36;1m      if [ -z "$FN_SRC" ]; then�[0m
 �[36;1m          echo "ERROR: function $FN_NAME has no source path" >&2�[0m
 �[36;1m          exit 1�[0m
 �[36;1m      fi�[0m
 �[36;1m  done�[0m
 �[36;1m  echo "Valid: $PROJECT_NAME ($FUNCTIONS_LEN function(s))"�[0m
 �[36;1m) || {�[0m
 �[36;1m  echo "::error file=eclexiaiser.toml::Invalid eclexiaiser.toml — see step output for details"�[0m

GitHub Actions: Dogfood Gate / Validate eclexiaiser manifest: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]Run if [ ! -f "eclexiaiser.toml" ]; then
 �[36;1mif [ ! -f "eclexiaiser.toml" ]; then�[0m
 �[36;1m  # Check if repo has a Containerfile — if so, recommend eclexiaiser�[0m
 �[36;1m  if [ -f "Containerfile" ]; then�[0m
 �[36;1m    echo "::warning::Containerfile present but no eclexiaiser.toml. Run \`eclexiaiser init\` to scaffold energy/carbon budgets."�[0m
 �[36;1m  fi�[0m
 �[36;1m  echo "has_manifest=false" >> "$GITHUB_OUTPUT"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1m�[0m
 �[36;1mecho "has_manifest=true" >> "$GITHUB_OUTPUT"�[0m
 �[36;1m�[0m
 �[36;1m# Validate TOML structure using pre-installed yq�[0m
 �[36;1m(�[0m
 �[36;1m  PROJECT_NAME=$(yq -e '.project.name // ""' eclexiaiser.toml)�[0m
 �[36;1m  if [ -z "$PROJECT_NAME" ]; then�[0m
 �[36;1m      echo "ERROR: project.name is required" >&2�[0m
 �[36;1m      exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m�[0m
 �[36;1m  FUNCTIONS_LEN=$(yq -e '.functions | length' eclexiaiser.toml)�[0m
 �[36;1m  if [ -z "$FUNCTIONS_LEN" ] || [ "$FUNCTIONS_LEN" -eq 0 ]; then�[0m
 �[36;1m      echo "ERROR: at least one [[functions]] entry is required" >&2�[0m
 �[36;1m      exit 1�[0m
 �[36;1m  fi�[0m
 �[36;1m�[0m
 �[36;1m  for i in $(seq 0 $((FUNCTIONS_LEN - 1))); do�[0m
 �[36;1m      FN_NAME=$(yq -e ".functions[$i].name // \"\"" eclexiaiser.toml)�[0m
 �[36;1m      if [ -z "$FN_NAME" ]; then�[0m
 �[36;1m          echo "ERROR: function name cannot be empty" >&2�[0m
 �[36;1m          exit 1�[0m
 �[36;1m      fi�[0m
 �[36;1m      FN_SRC=$(yq -e ".functions[$i].source // \"\"" eclexiaiser.toml)�[0m
 �[36;1m      if [ -z "$FN_SRC" ]; then�[0m
 �[36;1m          echo "ERROR: function $FN_NAME has no source path" >&2�[0m
 �[36;1m          exit 1�[0m
 �[36;1m      fi�[0m
 �[36;1m  done�[0m
 �[36;1m  echo "Valid: $PROJECT_NAME ($FUNCTIONS_LEN function(s))"�[0m
 �[36;1m) || {�[0m
 �[36;1m  echo "::error file=eclexiaiser.toml::Invalid eclexiaiser.toml — see step output for details"�[0m

GitHub Actions: Dogfood Gate / 3_Groove manifest check.txt: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m

GitHub Actions: Dogfood Gate / Groove manifest check: fix(ci): reconcile the workflows with actions.lock (gh-actions-lock)

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m
🔇 Additional comments (1)
.github/workflows/codeql.yml (1)

1-1: LGTM!

Also applies to: 51-51, 57-57


📝 Summary

Summary by CodeRabbit

  • Chores
    • Updated workflow action references to version tags while retaining existing action versions.
    • Added workflow-management markers across automation workflows.
    • Updated CodeQL actions to version 4.38.0.
    • Workflow logic, triggers, and observable behaviour remain unchanged.

Walkthrough

The pull request updates GitHub Actions workflow headers and replaces several commit-SHA action references with release or branch tags. Workflow steps, inputs, job structure, and other logic remain unchanged.

Changes

Workflow action reference reconciliation

Layer / File(s) Summary
Workflow management markers
.github/workflows/*.yml
Workflows now identify management by gh actions-lock. Duplicate management comments were removed where specified.
Single-workflow action reference updates
.github/workflows/bench.yml, .github/workflows/boj-build.yml, .github/workflows/ci.yml, .github/workflows/dependabot-automerge.yml, .github/workflows/instant-sync.yml, .github/workflows/pages.yml, .github/workflows/push-email-notify.yml
Individual action references now use the stated release tags instead of commit SHAs.
Multi-step workflow action reference updates
.github/workflows/casket-pages.yml, .github/workflows/dogfood-gate.yml, .github/workflows/release.yml, .github/workflows/security.yml
Multiple action references now use release or branch tags. Existing inputs, paths, names, and workflow structure remain unchanged.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Possibly related PRs

  • hyperpolymath/presswerk#91: Added workflow dependency locking coverage that this pull request reconciles with readable action tags.

Suggested reviewers: metadatastician

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarises the main change: reconciling CI workflows with actions.lock using gh-actions-lock.
Description check ✅ Passed The description directly explains the workflow reference changes, the authority of actions.lock, and the reason for the reconciliation.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks each workflow line,
Tags replace the hashes in a tidy design.
The lock marks shine at the top of the page,
While checkout hops across every stage.
No job changes course; the steps stay aligned.

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 9c6f5a6 into main Sep 20, 2026
26 of 30 checks passed
@hyperpolymath
hyperpolymath deleted the fix/sha-pin-actions branch September 20, 2026 02:16
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants