From 3499939c7f57097a8a3ed33999a60bc17a0a9a1d Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sat, 19 Sep 2026 23:25:11 +0000 Subject: [PATCH] fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them. --- .github/workflows/actions.lock | 28 ++++++++++++------------- .github/workflows/ci.yml | 1 + .github/workflows/codeql.yml | 1 + .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/instant-sync.yml | 1 + .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/mirror.yml | 1 + .github/workflows/publish-container.yml | 1 + .github/workflows/release.yml | 1 + .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + 13 files changed, 26 insertions(+), 14 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index dfb4783..9b62da4 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -7,14 +7,14 @@ workflows: - 'actions/checkout@v7.0.1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.37.9' + - 'github/codeql-action@v4.38.0' '.github/workflows/governance.yml': [] '.github/workflows/hypatia-scan.yml': - 'actions/checkout@v7.0.1' - 'actions/github-script@v9.0.0' - 'actions/upload-artifact@v7.0.1' - 'erlef/setup-beam@v1.24.1' - - 'github/codeql-action@v4.37.9' + - 'github/codeql-action@v4.38.0' '.github/workflows/instant-sync.yml': - 'peter-evans/repository-dispatch@v4.0.1' '.github/workflows/label-triage.yml': [] @@ -25,7 +25,7 @@ workflows: - 'webfactory/ssh-agent@v0.10.0' '.github/workflows/publish-container.yml': - 'actions/checkout@v7.0.1' - - 'docker/build-push-action@v7.3.0' + - 'docker/build-push-action@v7.4.0' - 'docker/login-action@v4.6.0' - 'docker/metadata-action@v6.2.0' '.github/workflows/release.yml': @@ -33,12 +33,12 @@ workflows: - 'softprops/action-gh-release@v3.0.3' '.github/workflows/scorecard.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.37.9' + - 'github/codeql-action@v4.38.0' - 'ossf/scorecard-action@v2.4.4' '.github/workflows/secret-scanner.yml': - 'actions/checkout@v7.0.1' - 'gitleaks/gitleaks-action@v3.0.0' - - 'trufflesecurity/trufflehog@v3.97.1' + - 'trufflesecurity/trufflehog@v3.97.4' dependencies: 'actions/checkout@v7.0.1': ref: 'v7.0.1' @@ -55,9 +55,9 @@ dependencies: commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' owner_id: 44036562 repo_id: 192625955 - 'docker/build-push-action@v7.3.0': - ref: 'v7.3.0' - commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a' + 'docker/build-push-action@v7.4.0': + ref: 'v7.4.0' + commit: 'sha1-c3c9e263c25d99ce0380d002d59b67737d91b0dc' owner_id: 5429470 repo_id: 241092383 'docker/login-action@v4.6.0': @@ -80,9 +80,9 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 - 'github/codeql-action@v4.37.9': - ref: 'v4.37.9' - commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' + 'github/codeql-action@v4.38.0': + ref: 'v4.38.0' + commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' owner_id: 9919 repo_id: 259445878 'gitleaks/gitleaks-action@v3.0.0': @@ -105,9 +105,9 @@ dependencies: commit: 'sha1-efb35369e0ad2afab669f228072c1b0d510eae64' owner_id: 2242 repo_id: 204253808 - 'trufflesecurity/trufflehog@v3.97.1': - ref: 'v3.97.1' - commit: 'sha1-20652fbbdefffcdaa493a5bf57ab2ac6b1db715b' + 'trufflesecurity/trufflehog@v3.97.4': + ref: 'v3.97.4' + commit: 'sha1-363923b901c911a9164f50b6c423f47c15372b1c' owner_id: 79229934 repo_id: 77726177 'webfactory/ssh-agent@v0.10.0': diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 85c41e4..44a079d 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. name: CI diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ec24948..20af160 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: PMPL-1.0-or-later # This workflow is managed by gh actions-lock. name: CodeQL Security Analysis diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 8d2b148..4299527 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: PMPL-1.0-or-later # This workflow is managed by gh actions-lock. # governance.yml — single wrapper calling the shared estate governance bundle diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 90a9e18..c42ba56 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: PMPL-1.0-or-later # This workflow is managed by gh actions-lock. # Hypatia Neurosymbolic CI/CD Security Scan diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 669f986..a4ccbd9 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. # Instant Forge Sync - Add this to your repo's .github/workflows/ diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..814a192 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..83ab941 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Labels diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index c223999..cb2499a 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell diff --git a/.github/workflows/publish-container.yml b/.github/workflows/publish-container.yml index 5ad6c3f..0f5f00b 100644 --- a/.github/workflows/publish-container.yml +++ b/.github/workflows/publish-container.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. name: Publish Container diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index adee68b..3799139 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. name: Release diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 8558480..f5e6d39 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. name: OSSF Scorecard diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index dbe3381..12c6cd9 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0-or-later # This workflow is managed by gh actions-lock. # Prevention workflow - scans for hardcoded secrets before they reach main