fix(ci): add the transitive pins the lockfile validator requires - #145
Merged
Merged
Conversation
🔍 Hypatia Security ScanFindings: 424 issues detected
View findings[
{
"reason": "Invalid .github/workflows/actions.lock: {:line, 112, {:missing_dependency_field, \"actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9\", :owner_id}}. Regenerate and verify it with gh actions-lock.",
"type": "invalid_actions_lock",
"file": "actions.lock",
"action": "regenerate",
"rule_module": "workflow_audit",
"severity": "high"
},
{
"reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "label-triage.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "triage"
},
{
"reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
"type": "missing_timeout_minutes",
"file": "labels.yml",
"action": "flag",
"rule_module": "workflow_audit",
"severity": "medium",
"recipe_id": "recipe-add-workflow-timeout-minutes",
"job": "sync"
},
{
"line": 51,
"reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/build.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 46,
"reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/push-email-notify.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 78,
"reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/hypatia-scan.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 53,
"reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/label-triage.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 39,
"reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/labels.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 43,
"reason": "job in .github/workflows/pages-deploy.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
"type": "RE001",
"file": ".github/workflows/pages-deploy.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "warn"
},
{
"line": 41,
"reason": "workflow .github/workflows/build.yml:41 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork",
"type": "RE008",
"file": ".github/workflows/build.yml",
"action": "report",
"rule_module": "research_extensions",
"severity": "critical"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
hyperpolymath
added a commit
that referenced
this pull request
Sep 21, 2026
…ck (#146) The lockfile-priming PR (#145) wrote its 8 transitive pins through a helper of mine that omitted the `owner_id`/`repo_id` fields the validator requires, so `gh actions-lock --verify` failed at line 112 (`actions/cache@55cc8345…`). This adds the missing pairs from the API for every affected entry; verify now passes locally (rc=0). The helper is fixed so the shape cannot recur.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Runs fail with
The lockfile could not be validated. Regenerate it by running gh actions-lock, and the extension's own--verifypasses locally — because the server resolves the called reusables and requires their refs to be pinned in this repo's manifest. This adds the 8 missing transitive pins (checkout/upload-artifact/setup-beam/cache/scorecard-action/rust-toolchain/ssh-agent/editorconfig-checker) in the same'owner/repo@<sha>'shape healthy repos carry. The manifest is re-parsed before commit.