Skip to content

fix(ci): add the transitive pins the lockfile validator requires - #145

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/transitive-lockfile-pins
Sep 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/transitive-lockfile-pins

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Runs fail with The lockfile could not be validated. Regenerate it by running gh actions-lock, and the extension's own --verify passes locally — because the server resolves the called reusables and requires their refs to be pinned in this repo's manifest. This adds the 8 missing transitive pins (checkout/upload-artifact/setup-beam/cache/scorecard-action/rust-toolchain/ssh-agent/editorconfig-checker) in the same 'owner/repo@<sha>' shape healthy repos carry. The manifest is re-parsed before commit.

@hyperpolymath
hyperpolymath merged commit 45297a2 into main Sep 21, 2026
@hyperpolymath
hyperpolymath deleted the fix/transitive-lockfile-pins branch September 21, 2026 08:39
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 424 issues detected

Severity Count
🔴 Critical 7
🟠 High 150
🟡 Medium 267

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Invalid .github/workflows/actions.lock: {:line, 112, {:missing_dependency_field, \"actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9\", :owner_id}}. Regenerate and verify it with gh actions-lock.",
    "type": "invalid_actions_lock",
    "file": "actions.lock",
    "action": "regenerate",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "line": 51,
    "reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 46,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 78,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 53,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 39,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 43,
    "reason": "job in .github/workflows/pages-deploy.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/pages-deploy.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "warn"
  },
  {
    "line": 41,
    "reason": "workflow .github/workflows/build.yml:41 gates on `github.actor == 'dependabot[bot]'` — `github.actor` is the run-triggering user, which an attacker controls on `pull_request_target` from a fork",
    "type": "RE008",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit that referenced this pull request Sep 21, 2026
…ck (#146)

The lockfile-priming PR (#145) wrote its 8 transitive pins through a
helper of mine that omitted the `owner_id`/`repo_id` fields the
validator requires, so `gh actions-lock --verify` failed at line 112
(`actions/cache@55cc8345…`). This adds the missing pairs from the API
for every affected entry; verify now passes locally (rc=0). The helper
is fixed so the shape cannot recur.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant