From 5ff041b03097ae8765077f297f0fd5377806e3c4 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sun, 20 Sep 2026 02:13:59 +0000 Subject: [PATCH] fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them. --- .github/workflows/actions.lock | 142 +++++++++------------ .github/workflows/boj-build.yml | 3 +- .github/workflows/casket-pages.yml | 15 ++- .github/workflows/cflite_batch.yml | 5 +- .github/workflows/cflite_pr.yml | 5 +- .github/workflows/ci.yml | 3 +- .github/workflows/codeql.yml | 7 +- .github/workflows/dependabot-automerge.yml | 3 +- .github/workflows/dogfood-gate.yml | 17 +-- .github/workflows/finishingbot.yml | 9 +- .github/workflows/glambot.yml | 3 +- .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/instant-sync.yml | 3 +- .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/mirror.yml | 1 + .github/workflows/push-email-notify.yml | 3 +- .github/workflows/rhodibot.yml | 9 +- .github/workflows/scorecard.yml | 1 + .github/workflows/seambot.yml | 9 +- .github/workflows/secret-scanner.yml | 1 + .github/workflows/spark-theatre-gate.yml | 1 + .github/workflows/workflow-linter.yml | 3 +- 24 files changed, 125 insertions(+), 122 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index f3a2b59..b405a74 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -4,119 +4,99 @@ version: 'v0.0.2' workflows: '.github/workflows/boj-build.yml': - - 'actions/checkout@v4.1.7' + - 'actions/checkout@v7.0.1' '.github/workflows/casket-pages.yml': - - 'actions/cache@v4.3.0' - - 'actions/checkout@v4.1.1' - - 'actions/configure-pages@v5.0.0' - - 'actions/deploy-pages@v4.0.5' - - 'actions/upload-artifact@v4.6.2' - - 'haskell-actions/setup@v2.7.5' + - 'actions/cache@v6.1.0' + - 'actions/checkout@v7.0.1' + - 'actions/configure-pages@v6.0.0' + - 'actions/deploy-pages@v5.0.1' + - 'actions/upload-artifact@v7.0.1' + - 'haskell-actions/setup@v2.12.0' '.github/workflows/cflite_batch.yml': - 'google/clusterfuzzlite@v1' '.github/workflows/cflite_pr.yml': - 'google/clusterfuzzlite@v1' '.github/workflows/ci.yml': - - 'actions/checkout@v4.3.1' + - 'actions/checkout@v7.0.1' '.github/workflows/codeql.yml': - - 'actions/checkout@v6.0.2' - - 'github/codeql-action@v4.34.0' + - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.38.0' '.github/workflows/dependabot-automerge.yml': - - 'dependabot/fetch-metadata@v2.2.0' + - 'dependabot/fetch-metadata@v3.1.0' '.github/workflows/dogfood-gate.yml': - - 'actions/checkout@v4.3.1' + - 'actions/checkout@v7.0.1' - 'hyperpolymath/a2ml-ecosystem@main' - 'hyperpolymath/k9-ecosystem@main' '.github/workflows/finishingbot.yml': - - 'actions/checkout@v4.1.1' - - 'actions/upload-artifact@v4.1.0' + - 'actions/checkout@v7.0.1' + - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@v1' - - 'swatinem/rust-cache@v2.7.8' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/glambot.yml': - - 'actions/checkout@v4.1.1' + - 'actions/checkout@v7.0.1' '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': [] '.github/workflows/instant-sync.yml': - - 'peter-evans/repository-dispatch@v3.0.0' + - 'peter-evans/repository-dispatch@v4.0.1' '.github/workflows/label-triage.yml': [] '.github/workflows/labels.yml': [] '.github/workflows/mirror.yml': [] '.github/workflows/push-email-notify.yml': - - 'hyperpolymath/smtp-notify-action@v0.2.0' + - 'hyperpolymath/smtp-notify-action@v0.3.0' '.github/workflows/rhodibot.yml': - - 'actions/checkout@v4.1.1' - - 'actions/upload-artifact@v4.1.0' + - 'actions/checkout@v7.0.1' + - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@v1' - - 'swatinem/rust-cache@v2.7.8' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/scorecard.yml': [] '.github/workflows/seambot.yml': - - 'actions/checkout@v4.1.1' - - 'actions/upload-artifact@v4.1.0' + - 'actions/checkout@v7.0.1' + - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@v1' - - 'swatinem/rust-cache@v2.7.8' + - 'swatinem/rust-cache@v2.9.2' '.github/workflows/secret-scanner.yml': [] '.github/workflows/spark-theatre-gate.yml': [] '.github/workflows/workflow-linter.yml': - - 'actions/checkout@v4.1.1' + - 'actions/checkout@v7.0.1' dependencies: - 'actions/cache@v4.3.0': - ref: 'v4.3.0' - commit: 'sha1-0057852bfaa89a56745cba8c7296529d2fc39830' + 'actions/cache@v6.1.0': + ref: 'v6.1.0' + commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' owner_id: 44036562 repo_id: 215566462 - 'actions/checkout@v4.1.1': - ref: 'v4.1.1' - commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11' + 'actions/checkout@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' owner_id: 44036562 repo_id: 197814629 - 'actions/checkout@v4.1.7': - ref: 'v4.1.7' - commit: 'sha1-692973e3d937129bcbf40652eb9f2f61becf3332' - owner_id: 44036562 - repo_id: 197814629 - 'actions/checkout@v4.3.1': - ref: 'v4.3.1' - commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' - owner_id: 44036562 - repo_id: 197814629 - 'actions/checkout@v6.0.2': - ref: 'v6.0.2' - commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' - owner_id: 44036562 - repo_id: 197814629 - 'actions/configure-pages@v5.0.0': - ref: 'v5.0.0' - commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b' + 'actions/configure-pages@v6.0.0': + ref: 'v6.0.0' + commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' owner_id: 44036562 repo_id: 513659658 - 'actions/deploy-pages@v4.0.5': - ref: 'v4.0.5' - commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + 'actions/deploy-pages@v5.0.1': + ref: 'v5.0.1' + commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346' owner_id: 44036562 repo_id: 438112499 - 'actions/upload-artifact@v4.1.0': - ref: 'v4.1.0' - commit: 'sha1-1eb3cb2b3e0f29609092a73eb033bb759a334595' - owner_id: 44036562 - repo_id: 192625955 - 'actions/upload-artifact@v4.6.2': - ref: 'v4.6.2' - commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + 'actions/upload-artifact@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' owner_id: 44036562 repo_id: 192625955 - 'dependabot/fetch-metadata@v2.2.0': - ref: 'v2.2.0' - commit: 'sha1-dbb049abf0d677abbd7f7eee0375145b417fdd34' + 'dependabot/fetch-metadata@v3.1.0': + ref: 'v3.1.0' + commit: 'sha1-25dd0e34f4fe68f24cc83900b1fe3fe149efef98' owner_id: 27347476 repo_id: 371068214 'dtolnay/rust-toolchain@v1': ref: 'v1' - commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772' + commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.34.0': - ref: 'v4.34.0' - commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + 'github/codeql-action@v4.38.0': + ref: 'v4.38.0' + commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1': @@ -124,33 +104,33 @@ dependencies: commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1' owner_id: 1342004 repo_id: 400046858 - 'haskell-actions/setup@v2.7.5': - ref: 'v2.7.5' - commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900' + 'haskell-actions/setup@v2.12.0': + ref: 'v2.12.0' + commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d' owner_id: 75048950 repo_id: 623796603 'hyperpolymath/a2ml-ecosystem@main': ref: 'main' - commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + commit: 'sha1-ed83d6927e8fb21431e403dbf6d7a4af96772746' owner_id: 6759885 repo_id: 1275649586 'hyperpolymath/k9-ecosystem@main': ref: 'main' - commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562' + commit: 'sha1-c1a34884054fabf0e9de81dbf68f4ba7874e85f1' owner_id: 6759885 repo_id: 1275650185 - 'hyperpolymath/smtp-notify-action@v0.2.0': - ref: 'v0.2.0' - commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + 'hyperpolymath/smtp-notify-action@v0.3.0': + ref: 'v0.3.0' + commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' owner_id: 6759885 repo_id: 1352485172 - 'peter-evans/repository-dispatch@v3.0.0': - ref: 'v3.0.0' - commit: 'sha1-ff45666b9427631e3450c54a1bcbee4d9ff4d7c0' + 'peter-evans/repository-dispatch@v4.0.1': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' owner_id: 18365890 repo_id: 220359305 - 'swatinem/rust-cache@v2.7.8': - ref: 'v2.7.8' - commit: 'sha1-9d47c6ad4b02e050fd481d890b2ea34778fd09d6' + 'swatinem/rust-cache@v2.9.2': + ref: 'v2.9.2' + commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6' owner_id: 580492 repo_id: 298565987 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 4008cc3..5fe9594 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger @@ -10,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) run: | # Send a secure trigger to boj-server to build this repository diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index ae5acee..0470e55 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: GitHub Pages @@ -22,22 +23,22 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -125,7 +126,7 @@ jobs: find _site -maxdepth 2 | sort - name: Setup Pages - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + uses: actions/configure-pages@v6.0.0 # NOTE: actions/upload-pages-artifact is a composite that internally # calls actions/upload-artifact@v4 (an UNPINNED upstream tag). The @@ -144,7 +145,7 @@ jobs: --exclude=.git --exclude=.github \ . - name: Upload artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: github-pages path: ${{ runner.temp }}/artifact.tar @@ -160,4 +161,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index 53041c9..75bbf8d 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite batch fuzzing @@ -24,14 +25,14 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 1800 diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 5983c61..fded6cc 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite PR fuzzing @@ -25,14 +26,14 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 300 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 38b260e..56c7dd5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: CI @@ -20,7 +21,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Idris2 0.8.0 env: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index d4ee3cc..e8a80a5 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: CodeQL Security Analysis @@ -37,17 +38,17 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v3 + uses: github/codeql-action/init@v4.38.0 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v3 + uses: github/codeql-action/analyze@v4.38.0 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 8db3fcf..99dc392 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -56,7 +57,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + uses: dependabot/fetch-metadata@v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 16855d6..af0d9b9 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -27,7 +28,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for A2ML files id: detect @@ -40,7 +41,7 @@ jobs: - name: Validate A2ML manifests if: steps.detect.outputs.count > 0 - uses: hyperpolymath/a2ml-ecosystem/validate-action@ed83d6927e8fb21431e403dbf6d7a4af96772746 # main + uses: hyperpolymath/a2ml-ecosystem/validate-action@main with: path: '.' strict: 'false' @@ -71,7 +72,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for K9 files id: detect @@ -88,7 +89,7 @@ jobs: - name: Validate K9 contracts if: steps.detect.outputs.k9_count > 0 - uses: hyperpolymath/k9-ecosystem/validate-action@c1a34884054fabf0e9de81dbf68f4ba7874e85f1 # main + uses: hyperpolymath/k9-ecosystem/validate-action@main with: path: '.' strict: 'false' @@ -120,7 +121,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Scan for invisible characters id: lint @@ -184,7 +185,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for Groove manifest id: groove @@ -242,7 +243,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -307,7 +308,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/finishingbot.yml b/.github/workflows/finishingbot.yml index 3c9ba0f..8712595 100644 --- a/.github/workflows/finishingbot.yml +++ b/.github/workflows/finishingbot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Finishingbot - Release readiness validation @@ -24,10 +25,10 @@ jobs: release-readiness: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 with: toolchain: v1 with: @@ -46,7 +47,7 @@ jobs: git -C "$RUNNER_TEMP/gitbot-fleet" checkout "$GITBOT_FLEET_REF" - name: Cache dependencies - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 with: workspaces: ${{ runner.temp }}/gitbot-fleet/bots/finishingbot @@ -90,7 +91,7 @@ jobs: - name: Upload results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: finishingbot-results path: finishingbot-results.txt diff --git a/.github/workflows/glambot.yml b/.github/workflows/glambot.yml index dafde7d..18e0dee 100644 --- a/.github/workflows/glambot.yml +++ b/.github/workflows/glambot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Glambot - Presentation quality (accessibility, SEO, visual polish) @@ -21,7 +22,7 @@ jobs: presentation-quality: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Glambot status run: | diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 1579f35..ecbf039 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Governance diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 2cd07f5..de8e271 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Hypatia Security Scan diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index b0fa941..d6a2c43 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release @@ -18,7 +19,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Trigger Propagation - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1 + uses: peter-evans/repository-dispatch@v4.0.1 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..814a192 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..83ab941 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Labels diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index d4ac835..e3965f1 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Mirror to Git Forges diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 521f1e5..8a96bf9 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable @@ -40,7 +41,7 @@ jobs: timeout-minutes: 5 steps: - name: Send push notification email - uses: hyperpolymath/smtp-notify-action@22e7bdb322c430c1d0dac6b3bb307f4bb139d0be # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) + uses: hyperpolymath/smtp-notify-action@v0.3.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml index 481ced0..e77abcf 100644 --- a/.github/workflows/rhodibot.yml +++ b/.github/workflows/rhodibot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Rhodibot - RSR compliance checking @@ -25,10 +26,10 @@ jobs: rsr-compliance: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 with: toolchain: v1 with: @@ -47,7 +48,7 @@ jobs: git -C "$RUNNER_TEMP/gitbot-fleet" checkout "$GITBOT_FLEET_REF" - name: Cache dependencies - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 with: workspaces: ${{ runner.temp }}/gitbot-fleet/bots/rhodibot @@ -96,7 +97,7 @@ jobs: - name: Upload results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: rhodibot-results path: rhodibot-results.txt diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 48a8d61..ca6971e 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: OSSF Scorecard diff --git a/.github/workflows/seambot.yml b/.github/workflows/seambot.yml index 288f6aa..646314a 100644 --- a/.github/workflows/seambot.yml +++ b/.github/workflows/seambot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Seambot - Seam hygiene and integration health @@ -24,7 +25,7 @@ jobs: seam-health: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check for seam register id: check-seam @@ -37,7 +38,7 @@ jobs: - name: Setup Rust toolchain if: steps.check-seam.outputs.has_seam == 'true' - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 with: toolchain: v1 with: @@ -58,7 +59,7 @@ jobs: - name: Cache dependencies if: steps.check-seam.outputs.has_seam == 'true' - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 with: workspaces: ${{ runner.temp }}/gitbot-fleet/bots/seambot @@ -107,7 +108,7 @@ jobs: - name: Upload results if: always() && steps.check-seam.outputs.has_seam == 'true' - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: seambot-results path: seambot-results.txt diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index d5cd61c..7c40c71 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Secret Scanner diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index 5aa52c7..b89592c 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Estate SPARK Theatre Gate — thin caller of the reusable workflow in diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index ca00588..14dd5e8 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config @@ -18,7 +19,7 @@ jobs: lint-workflows: runs-on: ubuntu-latest steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: |