From d5cec5ae57de3211a51446488c4fdf4bb4b52687 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sat, 19 Sep 2026 23:02:35 +0000 Subject: [PATCH] fix(ci): pin third-party actions to full commit SHAs MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The account's Actions policy requires a full-length SHA ref. A tag or branch ref is refused at startup — `startup_failure`, no jobs, "this workflow graph cannot be shown" — so these workflows could not run at all. This resolves each ref to the commit it currently points at and records the ref in a trailing comment, e.g. `actions/checkout@ # v4`. `dtolnay/rust-toolchain` takes its toolchain from the ref itself, so those steps also gained an explicit `with: toolchain:` input; without it, a SHA ref would silently lose the channel. No behaviour is intended to change beyond the pins. --- .github/workflows/ci.yml | 20 ++++++++++---------- .github/workflows/ui.yml | 6 +++--- 2 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 756f9cf..e80d095 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -19,10 +19,10 @@ jobs: name: Repo hygiene (licence · format · lint · commit) runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 - name: Set up Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version-file: .bun-version @@ -77,15 +77,15 @@ jobs: os: [ubuntu-24.04] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 - name: Set up Julia - uses: julia-actions/setup-julia@v2 + uses: julia-actions/setup-julia@4c0cb0fce8556fdb04a90347310e5db8b1f98fb9 # v2 with: version: ${{ matrix.julia-version }} - name: Cache Julia packages - uses: julia-actions/cache@v2 + uses: julia-actions/cache@d10a6fd8f31b12404a54613ebad242900567f2b9 # v2 # Every external version CI installs is read from the committed pin file, so CI # and a developer's machine cannot drift apart. A temporary environment is used @@ -185,7 +185,7 @@ jobs: run: julia --project=. -e 'import Pkg; Pkg.instantiate()' - name: Set up Bun - uses: oven-sh/setup-bun@v2 + uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2 with: bun-version: ${{ env.BUN_VERSION }} @@ -269,7 +269,7 @@ jobs: - name: Upload frontend test & benchmark artifacts if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: frontend-tests-benchmarks path: | @@ -306,11 +306,11 @@ jobs: run: julia --project=. -t 2 --code-coverage=user --compiled-modules=no test/runtests.jl --integration --server - name: Process coverage - uses: julia-actions/julia-processcoverage@v1 + uses: julia-actions/julia-processcoverage@03114f09f119417c3242a9fb6e0b722676aedf38 # v1 - name: Upload coverage artifact (local, Codecov removed per Milestone 2) if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: julia-coverage-lcov path: lcov.info @@ -343,7 +343,7 @@ jobs: - name: Upload Julia benchmark artifacts if: always() - uses: actions/upload-artifact@v4 + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 with: name: julia-benchmarks-comprehensive path: | diff --git a/.github/workflows/ui.yml b/.github/workflows/ui.yml index 1819000..1e3d78b 100644 --- a/.github/workflows/ui.yml +++ b/.github/workflows/ui.yml @@ -20,11 +20,11 @@ jobs: env: JULIA_PKG_PRECOMPILE_AUTO: '0' steps: - - uses: actions/checkout@v4 - - uses: julia-actions/setup-julia@v2 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: julia-actions/setup-julia@4c0cb0fce8556fdb04a90347310e5db8b1f98fb9 # v2 with: version: '1.12.5' - - uses: julia-actions/cache@v2 + - uses: julia-actions/cache@d10a6fd8f31b12404a54613ebad242900567f2b9 # v2 - name: Instantiate isolated UI environment run: julia --project=ui -e 'using Pkg; Pkg.instantiate()' - name: Test contracts and backend URL validation