From bbaa7d4eb131ba2691ab18beee8fe1fe3309929b Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sun, 20 Sep 2026 02:14:15 +0000 Subject: [PATCH] fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them. --- .github/workflows/actions.lock | 72 +++++++++---------- .github/workflows/aur-publish.yml | 9 +-- .github/workflows/codeql.yml | 7 +- .github/workflows/container.yml | 15 ++-- .github/workflows/dependabot-automerge.yml | 3 +- .../generator-generic-ossf-slsa3-publish.yml | 3 +- .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/instant-sync.yml | 3 +- .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/language-policy.yml | 3 +- .github/workflows/main-estate-audit.yml | 56 ++++++++------- .github/workflows/mirror.yml | 1 + .github/workflows/pages.yml | 9 +-- .github/workflows/push-email-notify.yml | 3 +- .github/workflows/release.yml | 25 +++---- .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + 19 files changed, 115 insertions(+), 100 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 8992e98..ff2e0af 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -12,11 +12,11 @@ workflows: '.github/workflows/container.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - - 'docker/build-push-action@v7.3.0' + - 'docker/build-push-action@v7.4.0' - 'docker/login-action@v4.6.0' - 'docker/metadata-action@v6.2.0' - - 'docker/setup-buildx-action@v4.3.0' - - 'docker/setup-qemu-action@v4.3.0' + - 'docker/setup-buildx-action@v4.4.1' + - 'docker/setup-qemu-action@v4.4.0' '.github/workflows/dependabot-automerge.yml': - 'dependabot/fetch-metadata@v3.1.0' '.github/workflows/generator-generic-ossf-slsa3-publish.yml': @@ -29,6 +29,9 @@ workflows: '.github/workflows/labels.yml': [] '.github/workflows/language-policy.yml': - 'actions/checkout@v7.0.1' + '.github/workflows/main-estate-audit.yml': + - 'actions/checkout@v7.0.1' + - 'hyperpolymath/cicd-suite@main' '.github/workflows/mirror.yml': [] '.github/workflows/pages.yml': - 'actions/checkout@v7.0.1' @@ -52,49 +55,36 @@ dependencies: repo_id: 760702757 uses: - 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d' - 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d': ref: 'v4.2.1' commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d' owner_id: 44036562 repo_id: 760701061 - - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1': - ref: 'v7.0.1' - commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' - owner_id: 44036562 - repo_id: 197814629 - 'actions/checkout@v7.0.1': ref: 'v7.0.1' commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' owner_id: 44036562 repo_id: 197814629 - 'actions/deploy-pages@v5.0.1': ref: 'v5.0.1' commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346' owner_id: 44036562 repo_id: 438112499 - 'actions/download-artifact@v8.0.1': ref: 'v8.0.1' commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c' owner_id: 44036562 repo_id: 192626254 - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': ref: 'v7.0.0' commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' owner_id: 44036562 repo_id: 192625955 - 'actions/upload-artifact@v7.0.1': ref: 'v7.0.1' commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' owner_id: 44036562 repo_id: 192625955 - 'actions/upload-pages-artifact@v5.0.0': ref: 'v5.0.0' commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' @@ -102,73 +92,79 @@ dependencies: repo_id: 496012378 uses: - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' - 'dependabot/fetch-metadata@v3.1.0': ref: 'v3.1.0' commit: 'sha1-25dd0e34f4fe68f24cc83900b1fe3fe149efef98' owner_id: 27347476 repo_id: 371068214 - - 'docker/build-push-action@v7.3.0': - ref: 'v7.3.0' - commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a' + 'docker/build-push-action@v7.4.0': + ref: 'v7.4.0' + commit: 'sha1-c3c9e263c25d99ce0380d002d59b67737d91b0dc' owner_id: 5429470 repo_id: 241092383 - 'docker/login-action@v4.6.0': ref: 'v4.6.0' commit: 'sha1-dbcb813823bdd20940b903addbd779551569679f' owner_id: 5429470 repo_id: 287743349 - 'docker/metadata-action@v6.2.0': ref: 'v6.2.0' commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302' owner_id: 5429470 repo_id: 306769011 - - 'docker/setup-buildx-action@v4.3.0': - ref: 'v4.3.0' - commit: 'sha1-37fe631027851001ddb9b187196cc803df7f5f0e' + 'docker/setup-buildx-action@v4.4.1': + ref: 'v4.4.1' + commit: 'sha1-f87e5991a6d7451dcb8d9637bfbc97413f497069' owner_id: 5429470 repo_id: 288485773 - - 'docker/setup-qemu-action@v4.3.0': - ref: 'v4.3.0' - commit: 'sha1-1f40c72289eff860ee54a304f1438e3cff362e0a' + 'docker/setup-qemu-action@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-99012661954931238ded8c8b007157a8430204e1' owner_id: 5429470 repo_id: 288487894 - 'dtolnay/rust-toolchain@v1': ref: 'v1' - commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772' + commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.38.0': ref: 'v4.38.0' commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' owner_id: 9919 repo_id: 259445878 - + 'hyperpolymath/cicd-suite@main': + ref: 'main' + commit: 'sha1-180b419825d238f8b606584c970a81dfa7cb6f81' + owner_id: 6759885 + repo_id: 1326697643 + uses: + - 'hyperpolymath/deed-ecosystem@f9d999b60cb5f383679ea19912bcdc49c944973a' + - 'hyperpolymath/k9-ecosystem@2155aa26a21758f2ba119f61bc7e0e1981c106fb' + 'hyperpolymath/deed-ecosystem@f9d999b60cb5f383679ea19912bcdc49c944973a': + ref: 'main' + commit: 'sha1-f9d999b60cb5f383679ea19912bcdc49c944973a' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@2155aa26a21758f2ba119f61bc7e0e1981c106fb': + ref: 'main' + commit: 'sha1-2155aa26a21758f2ba119f61bc7e0e1981c106fb' + owner_id: 6759885 + repo_id: 1275650185 'hyperpolymath/smtp-notify-action@v0.3.0': ref: 'v0.3.0' commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' owner_id: 6759885 repo_id: 1352485172 - 'ksxgithub/github-actions-deploy-aur@v4.2.0': ref: 'v4.2.0' commit: 'sha1-084b0d9b15415bf9cdb65d44dad1efe37a354050' owner_id: 11488886 repo_id: 261159912 - 'peter-evans/repository-dispatch@v4.0.1': ref: 'v4.0.1' commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' owner_id: 18365890 repo_id: 220359305 - 'softprops/action-gh-release@v3.0.3': ref: 'v3.0.3' commit: 'sha1-efb35369e0ad2afab669f228072c1b0d510eae64' diff --git a/.github/workflows/aur-publish.yml b/.github/workflows/aur-publish.yml index 9ee97f4..caa55cc 100644 --- a/.github/workflows/aur-publish.yml +++ b/.github/workflows/aur-publish.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -19,7 +20,7 @@ jobs: timeout-minutes: 15 if: vars.AUR_PUBLISH_ENABLED == 'true' steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Get version id: version run: | @@ -68,7 +69,7 @@ jobs: pkgname = vext EOF - name: Publish to AUR - uses: KSXGitHub/github-actions-deploy-aur@084b0d9b15415bf9cdb65d44dad1efe37a354050 # v4.2.0 + uses: KSXGitHub/github-actions-deploy-aur@v4.2.0 if: ${{ secrets.AUR_SSH_PRIVATE_KEY != '' }} with: pkgname: vext @@ -84,7 +85,7 @@ jobs: needs: [publish-aur] if: vars.AUR_PUBLISH_ENABLED == 'true' steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Get version id: version run: | @@ -118,7 +119,7 @@ jobs: sed -i "s/^sha256sums_x86_64=.*/sha256sums_x86_64=('$X86_SUM')/" PKGBUILD-bin sed -i "s/^sha256sums_aarch64=.*/sha256sums_aarch64=('$AARCH64_SUM')/" PKGBUILD-bin - name: Publish vext-bin to AUR - uses: KSXGitHub/github-actions-deploy-aur@084b0d9b15415bf9cdb65d44dad1efe37a354050 # v4.2.0 + uses: KSXGitHub/github-actions-deploy-aur@v4.2.0 if: ${{ secrets.AUR_SSH_PRIVATE_KEY != '' }} with: pkgname: vext-bin diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 58e6922..334329b 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -40,13 +41,13 @@ jobs: # Python/Go are banned in this repo per RSR language policy steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/init@v4.38.0 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0 + uses: github/codeql-action/analyze@v4.38.0 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/container.yml b/.github/workflows/container.yml index f40f0e5..3c82df3 100644 --- a/.github/workflows/container.yml +++ b/.github/workflows/container.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -22,20 +23,20 @@ jobs: attestations: write # write the build-provenance attestation (the "claim") steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up QEMU - uses: docker/setup-qemu-action@99012661954931238ded8c8b007157a8430204e1 # v4.4.0 + uses: docker/setup-qemu-action@v4.4.0 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@f87e5991a6d7451dcb8d9637bfbc97413f497069 # v4.4.1 + uses: docker/setup-buildx-action@v4.4.1 - name: Log in to GitHub Container Registry - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + uses: docker/login-action@v4.6.0 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 + uses: docker/metadata-action@v6.2.0 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | @@ -45,7 +46,7 @@ jobs: type=raw,value=latest,enable={{is_default_branch}} - name: Build and push (multi-arch) id: push - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + uses: docker/build-push-action@v7.4.0 with: context: . file: ./Containerfile @@ -58,7 +59,7 @@ jobs: provenance: true sbom: true - name: Attest container provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index c5a842e..f666905 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -54,7 +55,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + uses: dependabot/fetch-metadata@v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # --- Policy gate ------------------------------------------------------- diff --git a/.github/workflows/generator-generic-ossf-slsa3-publish.yml b/.github/workflows/generator-generic-ossf-slsa3-publish.yml index 61a1667..f9005ca 100644 --- a/.github/workflows/generator-generic-ossf-slsa3-publish.yml +++ b/.github/workflows/generator-generic-ossf-slsa3-publish.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -26,7 +27,7 @@ jobs: outputs: digests: ${{ steps.hash.outputs.digests }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 # ======================================================== # # Step 1: Build your artifacts. diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index a389b15..e7aa4e9 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 23785f3..e378cee 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 28e1ce1..7324fdc 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -17,7 +18,7 @@ jobs: timeout-minutes: 15 steps: - name: Trigger Propagation - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1 + uses: peter-evans/repository-dispatch@v4.0.1 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..814a192 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..83ab941 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Labels diff --git a/.github/workflows/language-policy.yml b/.github/workflows/language-policy.yml index 4debe8e..c1d2f4f 100644 --- a/.github/workflows/language-policy.yml +++ b/.github/workflows/language-policy.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -19,7 +20,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Enforce language policies run: | # Block new Python files (except SaltStack) diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml index 4d7b696..67169d5 100755 --- a/.github/workflows/main-estate-audit.yml +++ b/.github/workflows/main-estate-audit.yml @@ -1,3 +1,5 @@ +# This workflow is managed by gh actions-lock. + name: Central Estate CI/CD Audit permissions: @@ -14,82 +16,82 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Required Files Gate - uses: hyperpolymath/cicd-suite/actions/required-files-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/required-files-check@main - name: Code Hygiene Gate - uses: hyperpolymath/cicd-suite/actions/code-hygiene-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/code-hygiene-check@main - name: Manifest Validation Gate - uses: hyperpolymath/cicd-suite/actions/manifest-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/manifest-check@main - name: Idris2 ABI Purity Gate - uses: hyperpolymath/cicd-suite/actions/idris2-abi-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/idris2-abi-check@main - name: Zig Hexadeca API Gate - uses: hyperpolymath/cicd-suite/actions/zig-hexadeca-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/zig-hexadeca-check@main - name: Contractile Validation Gate - uses: hyperpolymath/cicd-suite/actions/contractile-validation-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/contractile-validation-check@main - name: Recipes Set Validation Gate - uses: hyperpolymath/cicd-suite/actions/recipes-set-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/recipes-set-check@main - name: Affirmation Document Gate - uses: hyperpolymath/cicd-suite/actions/affirmation-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/affirmation-check@main - name: Academic Referencing Gate - uses: hyperpolymath/cicd-suite/actions/referencing-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/referencing-check@main - name: Semantic Audit Gate - uses: hyperpolymath/cicd-suite/actions/semantic-audit-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/semantic-audit-check@main - name: SPDX License Gate - uses: hyperpolymath/cicd-suite/actions/spdx-license-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/spdx-license-check@main - name: Proof Runner Gate - uses: hyperpolymath/cicd-suite/actions/proof-runner-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/proof-runner-check@main - name: PRAT Testing Gate - uses: hyperpolymath/cicd-suite/actions/prat-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/prat-check@main - name: Panic Attack & Pons Gate - uses: hyperpolymath/cicd-suite/actions/custom-tools-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/custom-tools-check@main - name: WWW & Well-Known Compliance Gate - uses: hyperpolymath/cicd-suite/actions/www-compliance-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/www-compliance-check@main - name: BoJ Cartridge Validation Gate - uses: hyperpolymath/cicd-suite/actions/boj-cartridge-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/boj-cartridge-check@main - name: Formatting Validation Gate - uses: hyperpolymath/cicd-suite/actions/formatting-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/formatting-check@main - name: Accreditations & Badges Gate - uses: hyperpolymath/cicd-suite/actions/badges-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/badges-check@main - name: Metrics Extraction Gate - uses: hyperpolymath/cicd-suite/actions/metrics-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/metrics-check@main - name: Linguist & Banned Languages Gate - uses: hyperpolymath/cicd-suite/actions/linguist-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/linguist-check@main - name: Test & Benchmarks Dashboard Gate - uses: hyperpolymath/cicd-suite/actions/tests-benches-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/tests-benches-check@main - name: Hosting & Site Status Gate - uses: hyperpolymath/cicd-suite/actions/hosting-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/hosting-check@main - name: Git-Sea Analytics Gate - uses: hyperpolymath/cicd-suite/actions/gitsea-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/gitsea-check@main - name: Trust & Humans Validation Gate - uses: hyperpolymath/cicd-suite/actions/trust-humans-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/trust-humans-check@main - name: Are We UnAPI Gate (Secret Scanning) - uses: hyperpolymath/cicd-suite/actions/secrets-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/secrets-check@main - name: Reasonably Good Token Validation Gate - uses: hyperpolymath/cicd-suite/actions/vaulted-tokens-check@180b419825d238f8b606584c970a81dfa7cb6f81 # main + uses: hyperpolymath/cicd-suite/actions/vaulted-tokens-check@main diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 1020c2b..7c78083 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index b2b46f4..cd078a1 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -22,9 +23,9 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff steps: - name: Checkout Site - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout Ddraig SSG - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/ddraig-ssg path: .ddraig-ssg @@ -41,7 +42,7 @@ jobs: fi ./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/} - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -54,4 +55,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 8121206..0ae53bc 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable @@ -41,7 +42,7 @@ jobs: timeout-minutes: 5 steps: - name: Send push notification email - uses: hyperpolymath/smtp-notify-action@22e7bdb322c430c1d0dac6b3bb307f4bb139d0be # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7) + uses: hyperpolymath/smtp-notify-action@v0.3.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f9dc6f9..904886e 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. @@ -46,9 +47,9 @@ jobs: os: windows-latest cross: false steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 with: toolchain: v1 with: @@ -79,7 +80,7 @@ jobs: } Get-FileHash vext-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip -Algorithm SHA256 | ForEach-Object { "$($_.Hash.ToLower()) vext-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip" } | Out-File -FilePath vext-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip.sha256 - name: Upload artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: vext-${{ matrix.target }} path: | @@ -91,15 +92,15 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 - name: Install cargo-deb run: cargo install cargo-deb - name: Build .deb run: cargo deb --package vext-core - name: Upload .deb - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: deb-package path: target/debian/*.deb @@ -110,9 +111,9 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 + uses: dtolnay/rust-toolchain@v1 - name: Install cargo-generate-rpm run: cargo install cargo-generate-rpm - name: Build binary @@ -124,7 +125,7 @@ jobs: - name: Build .rpm run: cargo generate-rpm --package vext-core - name: Upload .rpm - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: rpm-package path: target/generate-rpm/*.rpm @@ -136,9 +137,9 @@ jobs: permissions: contents: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Download all artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: path: artifacts - name: Collect release assets @@ -147,7 +148,7 @@ jobs: find artifacts -type f \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.sha256" -o -name "*.deb" -o -name "*.rpm" \) -exec cp {} release/ \; ls -la release/ - name: Create Release - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 + uses: softprops/action-gh-release@v3.0.3 with: tag_name: ${{ github.event.inputs.tag || github.ref_name }} files: release/* diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index dc2bb26..5d212f3 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock. diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 701ae04..a14ad05 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # This workflow is managed by gh actions-lock.