fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) - #113
Conversation
…0.1.6) `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (20)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details⏰ Context from checks skipped due to timeout. (21)
|
| Layer / File(s) | Summary |
|---|---|
Workflow management markers .github/workflows/*.yml |
Workflows now identify management by gh actions-lock. Duplicate management comments were removed where specified. |
Single-workflow action reference updates .github/workflows/bench.yml, .github/workflows/boj-build.yml, .github/workflows/ci.yml, .github/workflows/dependabot-automerge.yml, .github/workflows/instant-sync.yml, .github/workflows/pages.yml, .github/workflows/push-email-notify.yml |
Individual action references now use the stated release tags instead of commit SHAs. |
Multi-step workflow action reference updates .github/workflows/casket-pages.yml, .github/workflows/dogfood-gate.yml, .github/workflows/release.yml, .github/workflows/security.yml |
Multiple action references now use release or branch tags. Existing inputs, paths, names, and workflow structure remain unchanged. |
Priority: ➖ Normal
Estimated code review effort: 2 (Simple) | ~10 minutes
Change: Bug fix
Possibly related PRs
- hyperpolymath/presswerk#91: Added workflow dependency locking coverage that this pull request reconciles with readable action tags.
Suggested reviewers: metadatastician
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
| Check name | Status | Explanation |
|---|---|---|
| Title check | ✅ Passed | The title clearly summarises the main change: reconciling CI workflows with actions.lock using gh-actions-lock. |
| Description check | ✅ Passed | The description directly explains the workflow reference changes, the authority of actions.lock, and the reason for the reconciliation. |
| Docstring Coverage | ✅ Passed | No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0… |
| Linked Issues check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
| Out of Scope Changes check | ✅ Passed | Check skipped because no linked issues were found for this pull request. |
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
- Commit to this branch
- Create a new PR
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.
A rabbit checks each workflow line,
Tags replace the hashes in a tidy design.
The lock marks shine at the top of the page,
While checkout hops across every stage.
No job changes course; the steps stay aligned.
Comment @coderabbitai help to get the list of available commands.
| @@ -1,3 +1,4 @@ | |||
| # This workflow is managed by gh actions-lock. | |||
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6)
actions.lockis authoritative: the workflows carry readable refs and the lock records thecommit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable —
startup_failure, "Invalid lockfile".Regenerated with the official extension (
github/gh-actions-lock). The hand-pinned SHA refs arereverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.