Skip to content

Commit d03c8f9

Browse files
hyperpolymathArena Agent
andauthored
fix(ci): reconcile actions.lock so the lockfile validates (#84)
Workflows fail at creation with `The lockfile could not be validated. Regenerate it by running gh actions-lock` / `Workflow must use a lockfile`. This regenerates the manifest with the official extension (`github/gh-actions-lock`), completes the `workflows:` map so every workflow file has an entry, and pins the SHA-form transitive deps reached via called reusables. Proof before push: every workflow re-parses, `gh actions-lock --verify` rc=0, and every `uses:` ref resolves to a pin. Co-authored-by: Arena Agent <agent@arena.ai>
1 parent ef3530c commit d03c8f9

19 files changed

Lines changed: 234 additions & 35 deletions

‎.github/workflows/abi-ffi-gate.yml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# abi-ffi-gate.yml — enforce that the Zig FFI conforms to the Idris2 ABI.
34
#
@@ -20,7 +21,7 @@ jobs:
2021
name: ABI ↔ FFI structural conformance
2122
runs-on: ubuntu-latest
2223
steps:
23-
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
24+
- uses: actions/checkout@v7.0.1
2425
- name: Install Julia 1.11.5
2526
run: |
2627
curl -fsSL https://julialang-s3.julialang.org/bin/linux/x64/1.11/julia-1.11.5-linux-x86_64.tar.gz -o /tmp/julia.tar.gz
@@ -35,7 +36,7 @@ jobs:
3536
name: Zig FFI builds + tests (Zig 0.14.0)
3637
runs-on: ubuntu-latest
3738
steps:
38-
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
39+
- uses: actions/checkout@v7.0.1
3940
- name: Install Zig 0.14.0
4041
run: |
4142
curl -fsSL https://ziglang.org/download/0.14.0/zig-linux-x86_64-0.14.0.tar.xz -o /tmp/zig.tar.xz

‎.github/workflows/actions.lock‎

Lines changed: 182 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,182 @@
1+
# This file is machine-generated by `gh actions-lock`.
2+
# Do not edit by hand; run `gh actions-lock` to update.
3+
# Docs: https://gh.io/actions-lockfile
4+
version: 'v0.0.2'
5+
workflows:
6+
'.github/workflows/abi-ffi-gate.yml':
7+
- 'actions/checkout@v7.0.1'
8+
'.github/workflows/boj-build.yml':
9+
- 'actions/checkout@v7.0.1'
10+
'.github/workflows/casket-pages.yml':
11+
- 'actions/cache@v6.1.0'
12+
- 'actions/checkout@v7.0.1'
13+
- 'actions/configure-pages@v6.0.0'
14+
- 'actions/deploy-pages@v5.0.1'
15+
- 'actions/upload-pages-artifact@v5.0.0'
16+
- 'haskell-actions/setup@v2.12.0'
17+
'.github/workflows/codeql.yml':
18+
- 'actions/checkout@v7.0.1'
19+
- 'github/codeql-action@v4.38.0'
20+
'.github/workflows/dogfood-gate.yml':
21+
- 'actions/checkout@v7.0.1'
22+
'.github/workflows/governance.yml': []
23+
'.github/workflows/hypatia-scan.yml': []
24+
'.github/workflows/instant-sync.yml':
25+
- 'peter-evans/repository-dispatch@v4.0.1'
26+
'.github/workflows/label-triage.yml': []
27+
'.github/workflows/labels.yml': []
28+
'.github/workflows/mirror.yml': []
29+
'.github/workflows/push-email-notify.yml':
30+
- 'hyperpolymath/smtp-notify-action@v0.3.0'
31+
'.github/workflows/release.yml':
32+
- 'actions/checkout@v7.0.1'
33+
- 'actions/upload-artifact@v7.0.1'
34+
- 'softprops/action-gh-release@v3.0.3'
35+
'.github/workflows/rhodibot.yml':
36+
- 'actions/checkout@v7.0.1'
37+
'.github/workflows/rust-ci.yml': []
38+
'.github/workflows/scorecard.yml': []
39+
'.github/workflows/secret-scanner.yml': []
40+
'.github/workflows/static-analysis-gate.yml':
41+
- 'actions/checkout@v7.0.1'
42+
- 'actions/download-artifact@v8.0.1'
43+
- 'actions/upload-artifact@v7.0.1'
44+
- 'erlef/setup-beam@v1.24.1'
45+
dependencies:
46+
'actions/cache@v6.1.0':
47+
ref: 'v6.1.0'
48+
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
49+
owner_id: 44036562
50+
repo_id: 215566462
51+
'actions/checkout@v7.0.1':
52+
ref: 'v7.0.1'
53+
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
54+
owner_id: 44036562
55+
repo_id: 197814629
56+
'actions/configure-pages@v6.0.0':
57+
ref: 'v6.0.0'
58+
commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d'
59+
owner_id: 44036562
60+
repo_id: 513659658
61+
'actions/deploy-pages@v5.0.1':
62+
ref: 'v5.0.1'
63+
commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346'
64+
owner_id: 44036562
65+
repo_id: 438112499
66+
'actions/download-artifact@v8.0.1':
67+
ref: 'v8.0.1'
68+
commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
69+
owner_id: 44036562
70+
repo_id: 192626254
71+
'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f':
72+
ref: 'v7.0.0'
73+
commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
74+
owner_id: 44036562
75+
repo_id: 192625955
76+
'actions/upload-artifact@v7.0.1':
77+
ref: 'v7.0.1'
78+
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
79+
owner_id: 44036562
80+
repo_id: 192625955
81+
'actions/upload-pages-artifact@v5.0.0':
82+
ref: 'v5.0.0'
83+
commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9'
84+
owner_id: 44036562
85+
repo_id: 496012378
86+
uses:
87+
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
88+
'erlef/setup-beam@v1.24.1':
89+
ref: 'v1.24.1'
90+
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
91+
owner_id: 47606891
92+
repo_id: 331103973
93+
'github/codeql-action@v4.38.0':
94+
ref: 'v4.38.0'
95+
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
96+
owner_id: 9919
97+
repo_id: 259445878
98+
'haskell-actions/setup@v2.12.0':
99+
ref: 'v2.12.0'
100+
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
101+
owner_id: 75048950
102+
repo_id: 623796603
103+
'hyperpolymath/smtp-notify-action@v0.3.0':
104+
ref: 'v0.3.0'
105+
commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be'
106+
owner_id: 6759885
107+
repo_id: 1352485172
108+
'peter-evans/repository-dispatch@v4.0.1':
109+
ref: 'v4.0.1'
110+
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
111+
owner_id: 18365890
112+
repo_id: 220359305
113+
'softprops/action-gh-release@v3.0.3':
114+
ref: 'v3.0.3'
115+
commit: 'sha1-efb35369e0ad2afab669f228072c1b0d510eae64'
116+
owner_id: 2242
117+
repo_id: 204253808
118+
'Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4':
119+
ref: 'v2'
120+
commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4'
121+
owner_id: 580492
122+
repo_id: 298565987
123+
'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9':
124+
ref: 'v6.1.0'
125+
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
126+
owner_id: 44036562
127+
repo_id: 215566462
128+
'actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0':
129+
ref: 'v7.0.0'
130+
commit: 'sha1-9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0'
131+
owner_id: 44036562
132+
repo_id: 197814629
133+
'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a':
134+
ref: 'v7.0.1'
135+
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
136+
owner_id: 44036562
137+
repo_id: 192625955
138+
'actions/upload-artifact@65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08':
139+
ref: 'v4.6.0'
140+
commit: 'sha1-65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08'
141+
owner_id: 44036562
142+
repo_id: 192625955
143+
'codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f':
144+
ref: 'v7.0.0'
145+
commit: 'sha1-fb8b3582c8e4def4969c97caa2f19720cb33a72f'
146+
owner_id: 8226205
147+
repo_id: 200299178
148+
'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed':
149+
ref: 'v2.0.5'
150+
commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
151+
owner_id: 42048915
152+
repo_id: 356423100
153+
'dtolnay/rust-toolchain@67ef31d5b988238dd797d409d6f9574278e20537':
154+
ref: 'stable'
155+
commit: 'sha1-67ef31d5b988238dd797d409d6f9574278e20537'
156+
owner_id: 1940490
157+
repo_id: 260749683
158+
'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c':
159+
ref: 'v2.2.0'
160+
commit: 'sha1-840e866d93b8e032123c23bac69dece044d4d84c'
161+
owner_id: 26415196
162+
repo_id: 297874902
163+
'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124':
164+
ref: 'v1.24.1'
165+
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
166+
owner_id: 47606891
167+
repo_id: 331103973
168+
'ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a':
169+
ref: 'v2.4.3'
170+
commit: 'sha1-4eaacf0543bb3f2c246792bd56e8cdeffafb205a'
171+
owner_id: 67707773
172+
repo_id: 421101922
173+
'softprops/action-gh-release@c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda':
174+
ref: 'v2.2.1'
175+
commit: 'sha1-c95fe1489396fe8a9eb87c0abf8aa5b2ef267fda'
176+
owner_id: 2242
177+
repo_id: 204253808
178+
'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555':
179+
ref: 'v0.10.0'
180+
commit: 'sha1-e83874834305fe9a4a2997156cb26c5de65a8555'
181+
owner_id: 135788
182+
repo_id: 208510314

‎.github/workflows/boj-build.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: BoJ Server Build Trigger
34
on:
@@ -9,7 +10,7 @@ jobs:
910
runs-on: ubuntu-latest
1011
steps:
1112
- name: Checkout
12-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
13+
uses: actions/checkout@v7.0.1
1314
- name: Trigger BoJ Server (Casket/ssg-mcp)
1415
run: |
1516
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/casket-pages.yml‎

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: GitHub Pages
34

@@ -20,22 +21,22 @@ jobs:
2021
runs-on: ubuntu-latest
2122
steps:
2223
- name: Checkout
23-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
24+
uses: actions/checkout@v7.0.1
2425

2526
- name: Checkout casket-ssg
26-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
27+
uses: actions/checkout@v7.0.1
2728
with:
2829
repository: hyperpolymath/casket-ssg
2930
path: .casket-ssg
3031

3132
- name: Setup GHCup
32-
uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2
33+
uses: haskell-actions/setup@v2.12.0
3334
with:
3435
ghc-version: '9.8.2'
3536
cabal-version: '3.10'
3637

3738
- name: Cache Cabal
38-
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
39+
uses: actions/cache@v6.1.0
3940
with:
4041
path: |
4142
~/.cabal/packages
@@ -97,10 +98,10 @@ jobs:
9798
touch ../_site/.nojekyll
9899
99100
- name: Setup Pages
100-
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
101+
uses: actions/configure-pages@v6.0.0
101102

102103
- name: Upload artifact
103-
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
104+
uses: actions/upload-pages-artifact@v5.0.0
104105
with:
105106
path: '_site'
106107

@@ -113,4 +114,4 @@ jobs:
113114
steps:
114115
- name: Deploy to GitHub Pages
115116
id: deployment
116-
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
117+
uses: actions/deploy-pages@v5.0.1

‎.github/workflows/codeql.yml‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: CodeQL Security Analysis
34

@@ -35,15 +36,15 @@ jobs:
3536

3637
steps:
3738
- name: Checkout
38-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
39+
uses: actions/checkout@v7.0.1
3940

4041
- name: Initialize CodeQL
41-
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v3
42+
uses: github/codeql-action/init@v4.38.0
4243
with:
4344
languages: ${{ matrix.language }}
4445
build-mode: ${{ matrix.build-mode }}
4546

4647
- name: Perform CodeQL Analysis
47-
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v3
48+
uses: github/codeql-action/analyze@v4.38.0
4849
with:
4950
category: "/language:${{ matrix.language }}"

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
34
#
@@ -25,7 +26,7 @@ jobs:
2526

2627
steps:
2728
- name: Checkout repository
28-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
29+
uses: actions/checkout@v7.0.1
2930

3031
- name: Check for A2ML files
3132
id: detect
@@ -65,7 +66,7 @@ jobs:
6566

6667
steps:
6768
- name: Checkout repository
68-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
69+
uses: actions/checkout@v7.0.1
6970

7071
- name: Check for K9 files
7172
id: detect
@@ -110,7 +111,7 @@ jobs:
110111

111112
steps:
112113
- name: Checkout repository
113-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
114+
uses: actions/checkout@v7.0.1
114115

115116
- name: Scan for invisible characters
116117
id: lint
@@ -202,7 +203,7 @@ jobs:
202203

203204
steps:
204205
- name: Checkout repository
205-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
206+
uses: actions/checkout@v7.0.1
206207

207208
- name: Check for Groove manifest
208209
id: groove
@@ -260,7 +261,7 @@ jobs:
260261

261262
steps:
262263
- name: Checkout repository
263-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
264+
uses: actions/checkout@v7.0.1
264265

265266
- name: Check and validate eclexiaiser manifest
266267
id: eclex
@@ -325,7 +326,7 @@ jobs:
325326

326327
steps:
327328
- name: Checkout repository
328-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4
329+
uses: actions/checkout@v7.0.1
329330

330331
- name: Generate dogfooding scorecard
331332
run: |

‎.github/workflows/governance.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Governance
34

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Hypatia Security Scan
34

‎.github/workflows/instant-sync.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# Instant Forge Sync - Triggers propagation to all forges on push/release
34
name: Instant Sync
@@ -16,7 +17,7 @@ jobs:
1617
runs-on: ubuntu-latest
1718
steps:
1819
- name: Trigger Propagation
19-
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3
20+
uses: peter-evans/repository-dispatch@v4.0.1
2021
with:
2122
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
2223
repository: hyperpolymath/.git-private-farm

‎.github/workflows/label-triage.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Label Triage
34

0 commit comments

Comments
 (0)