From fbefc0f4373f7f8fe507b140352a9c20189b67be Mon Sep 17 00:00:00 2001
From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com>
Date: Sat, 19 Sep 2026 23:25:38 +0000
Subject: [PATCH] fix(ci): reconcile the workflows with actions.lock
(gh-actions-lock v0.1.6)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
`actions.lock` is authoritative: the workflows carry readable refs and the lock records the
commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable — `startup_failure`, "Invalid lockfile".
Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are
reverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.
---
.github/workflows/abi-drift.yml | 9 +++---
.github/workflows/actions.lock | 2 +-
.github/workflows/backend-assurance.yml | 9 +++---
.github/workflows/build.yml | 5 +--
.github/workflows/codeql.yml | 7 +++--
.github/workflows/container-publish.yml | 5 +--
.github/workflows/dogfood-gate.yml | 13 ++++----
.github/workflows/e2e.yml | 41 +++++++++++++------------
.github/workflows/fuzz.yml | 7 +++--
.github/workflows/governance.yml | 1 +
.github/workflows/hcg-surface-drift.yml | 5 +--
.github/workflows/hypatia-scan.yml | 11 ++++---
.github/workflows/instant-sync.yml | 3 +-
.github/workflows/label-triage.yml | 1 +
.github/workflows/labels.yml | 1 +
.github/workflows/lsp-dap-bsp.yml | 13 ++++----
.github/workflows/mirror.yml | 1 +
.github/workflows/pages-deploy.yml | 3 +-
.github/workflows/pages.yml | 9 +++---
.github/workflows/proofs.yml | 9 +++---
.github/workflows/publish.yml | 9 +++---
.github/workflows/push-email-notify.yml | 3 +-
.github/workflows/readme-derive.yml | 1 +
.github/workflows/release.yml | 17 +++++-----
.github/workflows/scorecard.yml | 1 +
.github/workflows/secret-scanner.yml | 1 +
.github/workflows/truthfulness.yml | 7 +++--
.github/workflows/zig-test.yml | 7 +++--
28 files changed, 114 insertions(+), 87 deletions(-)
diff --git a/.github/workflows/abi-drift.yml b/.github/workflows/abi-drift.yml
index 6da5276f..8fd813ca 100644
--- a/.github/workflows/abi-drift.yml
+++ b/.github/workflows/abi-drift.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -46,7 +47,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -71,7 +72,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
# Need at least two commits so `git diff origin/...HEAD`
# can compute the changed-cartridge set on pull_request events.
@@ -79,7 +80,7 @@ jobs:
fetch-depth: 0
- name: Install Rust toolchain (stable)
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1
+ uses: dtolnay/rust-toolchain@v1
with:
toolchain: v1
with:
@@ -93,7 +94,7 @@ jobs:
# GADT-skip fix (iseriser#20, merged 2026-05-20) never reached CI.
# Bumping ISERISER_REV invalidates the cache and forces a rebuild.
- name: Cache cargo bin (iseriser install)
- uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
+ uses: actions/cache@v4.2.2
env:
ISERISER_REV: 741a3b63e7619b6e9cfe7f91b04d7ccfb130b1ca
with:
diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock
index 67bc8bac..f69ea92a 100644
--- a/.github/workflows/actions.lock
+++ b/.github/workflows/actions.lock
@@ -164,7 +164,7 @@ dependencies:
repo_id: 356423100
'dtolnay/rust-toolchain@v1':
ref: 'v1'
- commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
+ commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
owner_id: 1940490
repo_id: 260749683
'erlef/setup-beam@v1.24.0':
diff --git a/.github/workflows/backend-assurance.yml b/.github/workflows/backend-assurance.yml
index ff931033..1b83a8e1 100644
--- a/.github/workflows/backend-assurance.yml
+++ b/.github/workflows/backend-assurance.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -47,7 +48,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -79,16 +80,16 @@ jobs:
run:
working-directory: elixir
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Set up BEAM (Elixir + OTP)
- uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
+ uses: erlef/setup-beam@v1.24.0
with:
elixir-version: '1.18.4'
otp-version: '27.0'
- name: Cache deps + _build
- uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
+ uses: actions/cache@v4.2.2
with:
path: |
elixir/deps
diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml
index 5e2e069c..c9497511 100644
--- a/.github/workflows/build.yml
+++ b/.github/workflows/build.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -22,10 +23,10 @@ jobs:
name: SonarQube
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
+ - uses: actions/checkout@v4.3.1
with:
fetch-depth: 0 # Shallow clones should be disabled for a better relevancy of analysis
- name: SonarQube Scan
- uses: SonarSource/sonarqube-scan-action@7006c4492b2e0ee0f816d36501671557c97f5995 # v8.1.0
+ uses: SonarSource/sonarqube-scan-action@v8.1.0
env:
SONAR_TOKEN: ${{ secrets.SONAR_TOKEN }}
diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml
index 39792b2b..bbf70899 100644
--- a/.github/workflows/codeql.yml
+++ b/.github/workflows/codeql.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -43,15 +44,15 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Initialize CodeQL
- uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
+ uses: github/codeql-action/init@v4.34.0
with:
languages: ${{ matrix.language }}
build-mode: ${{ matrix.build-mode }}
- name: Perform CodeQL Analysis
- uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4.34.0
+ uses: github/codeql-action/analyze@v4.34.0
with:
category: "/language:${{ matrix.language }}"
diff --git a/.github/workflows/container-publish.yml b/.github/workflows/container-publish.yml
index 0a49344d..6a35abe1 100644
--- a/.github/workflows/container-publish.yml
+++ b/.github/workflows/container-publish.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -28,7 +29,7 @@ jobs:
id-token: write # mint the OIDC token the attestation is signed with
attestations: write # write the build-provenance attestation (the "claim")
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Extract version metadata
id: meta
@@ -93,7 +94,7 @@ jobs:
# gh attest verify oci://ghcr.io/${{ github.repository }}: \
# --repo ${{ github.repository }}
- name: Attest container provenance
- uses: actions/attest-build-provenance@e8998f949152b193b063cb0ec769d69d929409be # v2.4.0
+ uses: actions/attest-build-provenance@v2.4.0
with:
subject-name: ghcr.io/${{ github.repository }}
subject-digest: ${{ steps.push.outputs.digest }}
diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml
index 629d3f45..33383516 100644
--- a/.github/workflows/dogfood-gate.yml
+++ b/.github/workflows/dogfood-gate.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -37,7 +38,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Check for A2ML files
id: detect
@@ -78,7 +79,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Check for K9 files
id: detect
@@ -124,7 +125,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Scan for invisible characters
id: lint
@@ -220,7 +221,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Check for Groove manifest
id: groove
@@ -279,7 +280,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Check and validate eclexiaiser manifest
id: eclex
@@ -327,7 +328,7 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Generate dogfooding scorecard
run: |
diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml
index fc8583d7..f10f2f52 100644
--- a/.github/workflows/e2e.yml
+++ b/.github/workflows/e2e.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -34,7 +35,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -66,15 +67,15 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
- name: Install Deno
- uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
+ uses: denoland/setup-deno@v2.0.4
with:
deno-version: v2.x
@@ -82,7 +83,7 @@ jobs:
# tests/e2e_full.sh requires `mix` on PATH to start the Elixir
# backend (elixir/ — `mix run --no-halt`). Pinned to match the
# estate convention (see hypatia-scan.yml across the org).
- uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
+ uses: erlef/setup-beam@v1.24.0
with:
elixir-version: '1.18'
otp-version: '27'
@@ -115,7 +116,7 @@ jobs:
- name: Upload test logs
if: always()
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: e2e-full-logs
path: /tmp/boj-e2e-test.*
@@ -131,10 +132,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
@@ -154,7 +155,7 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Run aspect tests
run: bash tests/aspect_tests.sh
@@ -169,10 +170,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
@@ -184,7 +185,7 @@ jobs:
- name: Upload benchmark results
if: always()
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: benchmark-results
path: ffi/zig/zig-out/bench*
@@ -223,24 +224,24 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Setup Node
# Node is needed on every leg: it is the subject on the node
# leg and the boot-smoke orchestrator on all three.
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
+ uses: actions/setup-node@v4.4.0
with:
node-version: '22'
- name: Install Deno
if: matrix.runtime == 'deno'
- uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
+ uses: denoland/setup-deno@v2.0.4
with:
deno-version: v2.x
- name: Install Bun
if: matrix.runtime == 'bun'
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
+ uses: oven-sh/setup-bun@v2.2.0
with:
bun-version: '1.x'
@@ -269,10 +270,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Setup Node
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
+ uses: actions/setup-node@v4.4.0
with:
node-version: '22'
@@ -281,7 +282,7 @@ jobs:
- name: Upload bridge bench artifact
if: always()
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: bench-bridge-results
path: bench-bridge.txt
@@ -292,7 +293,7 @@ jobs:
# Advisory — a comment failure must never gate the bench job.
# Same reasoning as the hypatia-scan PR-comment step.
continue-on-error: true
- uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
+ uses: actions/github-script@v8.0.0
with:
script: |
const fs = require('fs');
diff --git a/.github/workflows/fuzz.yml b/.github/workflows/fuzz.yml
index abc61fc3..7afaeba6 100644
--- a/.github/workflows/fuzz.yml
+++ b/.github/workflows/fuzz.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -27,10 +28,10 @@ jobs:
permissions:
contents: read
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
@@ -55,7 +56,7 @@ jobs:
permissions:
contents: read
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Fuzz JSON-RPC message parsing
run: |
diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml
index 94ddcbd4..16578c46 100644
--- a/.github/workflows/governance.yml
+++ b/.github/workflows/governance.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
diff --git a/.github/workflows/hcg-surface-drift.yml b/.github/workflows/hcg-surface-drift.yml
index 40eef2d4..b1e447d0 100644
--- a/.github/workflows/hcg-surface-drift.yml
+++ b/.github/workflows/hcg-surface-drift.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -52,7 +53,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -87,7 +88,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Confirm script + inputs are present
run: |
set -euo pipefail
diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml
index 2bbba20a..bb2f17c4 100644
--- a/.github/workflows/hypatia-scan.yml
+++ b/.github/workflows/hypatia-scan.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -50,12 +51,12 @@ jobs:
steps:
- name: Checkout repository
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
with:
fetch-depth: 0 # Full history for better pattern analysis
- name: Setup Elixir for Hypatia scanner
- uses: erlef/setup-beam@fc68ffb90438ef2936bbb3251622353b3dcb2f93 # v1.24.0
+ uses: erlef/setup-beam@v1.24.0
with:
elixir-version: '1.18'
otp-version: '27'
@@ -109,7 +110,7 @@ jobs:
echo "- Medium: $MEDIUM" >> $GITHUB_STEP_SUMMARY
- name: Upload findings artifact
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: hypatia-findings
path: hypatia-findings.json
@@ -245,7 +246,7 @@ jobs:
always() &&
(github.event_name != 'pull_request' ||
github.event.pull_request.head.repo.fork != true)
- uses: github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v4.32.6
+ uses: github/codeql-action/upload-sarif@v4.32.6
with:
sarif_file: hypatia.sarif
# Distinct category so Hypatia results coexist with CodeQL's
@@ -385,7 +386,7 @@ jobs:
# the pull-requests: write permission above: a token/API hiccup or
# a fork PR (read-only token) skips the comment, not the check.
continue-on-error: true
- uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
+ uses: actions/github-script@v8.0.0
with:
script: |
const fs = require('fs');
diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml
index 658c1a7d..f59819cc 100644
--- a/.github/workflows/instant-sync.yml
+++ b/.github/workflows/instant-sync.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -28,7 +29,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Trigger Propagation
- uses: peter-evans/repository-dispatch@ff45666b9427631e3450c54a1bcbee4d9ff4d7c0 # v3.0.0
+ uses: peter-evans/repository-dispatch@v3.0.0
with:
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
repository: hyperpolymath/.git-private-farm
diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml
index 9886e920..814a1924 100644
--- a/.github/workflows/label-triage.yml
+++ b/.github/workflows/label-triage.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Label Triage
diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml
index c80b676c..83ab941a 100644
--- a/.github/workflows/labels.yml
+++ b/.github/workflows/labels.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Labels
diff --git a/.github/workflows/lsp-dap-bsp.yml b/.github/workflows/lsp-dap-bsp.yml
index ae9fba89..c04f8594 100644
--- a/.github/workflows/lsp-dap-bsp.yml
+++ b/.github/workflows/lsp-dap-bsp.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -32,7 +33,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -58,7 +59,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Validate ABI modules exist
run: |
echo "=== Checking LSP/DAP/BSP ABI modules ==="
@@ -94,13 +95,13 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
# Use the pinned action + .tool-versions' canonical Zig, matching
# e2e.yml. (A previous revision curled ziglang.org/builds/... — the
# nightly dir, not release downloads — and got an error page that
# `tar` rejected.)
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
- name: Build LSP/DAP/BSP cartridge FFI
@@ -141,7 +142,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
# jq (pre-installed on ubuntu-latest) — the repo's no-Python policy
# (dogfood-gate) bans the previous json.tool/json.load approach.
# Same checks: valid JSON + required fields + panel count.
@@ -175,7 +176,7 @@ jobs:
needs: [changes, abi-check, ffi-build, panel-validation]
if: needs.changes.outputs.run == 'true'
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Verify triadic structure
run: |
echo "=== LSP/DAP/BSP Triadic Structure Audit ==="
diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml
index 706d21f5..b7da63bc 100644
--- a/.github/workflows/mirror.yml
+++ b/.github/workflows/mirror.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
diff --git a/.github/workflows/pages-deploy.yml b/.github/workflows/pages-deploy.yml
index 403dcacc..332ce492 100644
--- a/.github/workflows/pages-deploy.yml
+++ b/.github/workflows/pages-deploy.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -21,7 +22,7 @@ jobs:
deploy:
runs-on: ubuntu-latest
steps:
- - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
+ - uses: actions/checkout@v4.4.0
- name: Deploy site/ to Cloudflare Workers (static assets)
run: npx wrangler@latest deploy
env:
diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml
index 70bfa21e..d614a31b 100755
--- a/.github/workflows/pages.yml
+++ b/.github/workflows/pages.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -26,9 +27,9 @@ jobs:
image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff
steps:
- name: Checkout Site
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
+ uses: actions/checkout@v4.4.0
- name: Checkout Ddraig SSG
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
+ uses: actions/checkout@v4.4.0
with:
repository: hyperpolymath/ddraig-ssg
path: .ddraig-ssg
@@ -45,7 +46,7 @@ jobs:
fi
./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/}
- name: Upload artifact
- uses: actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa # v3.0.1
+ uses: actions/upload-pages-artifact@v3.0.1
with:
path: '_site'
deploy:
@@ -58,4 +59,4 @@ jobs:
steps:
- name: Deploy to GitHub Pages
id: deployment
- uses: actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e # v4.0.5
+ uses: actions/deploy-pages@v4.0.5
diff --git a/.github/workflows/proofs.yml b/.github/workflows/proofs.yml
index f122e8f4..126df4d6 100644
--- a/.github/workflows/proofs.yml
+++ b/.github/workflows/proofs.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -52,7 +53,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -82,7 +83,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Enforce trusted base
run: bash scripts/check-trusted-base.sh
@@ -94,7 +95,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 45
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Read pinned Idris2 version
id: ver
@@ -104,7 +105,7 @@ jobs:
run: sudo apt-get update && sudo apt-get install -y chezscheme libgmp-dev build-essential
- name: Cache asdf + Idris2 toolchain
- uses: actions/cache@d4323d4df104b026a6aa633fdb11d772146be0bf # v4.2.2
+ uses: actions/cache@v4.2.2
with:
path: ~/.asdf
key: idris2-asdf-${{ runner.os }}-${{ steps.ver.outputs.idris2 }}
diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml
index d4263cc3..c0d0925d 100644
--- a/.github/workflows/publish.yml
+++ b/.github/workflows/publish.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -25,10 +26,10 @@ jobs:
contents: read
id-token: write
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Setup Node.js
- uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4.4.0
+ uses: actions/setup-node@v4.4.0
with:
node-version: '22'
registry-url: 'https://registry.npmjs.org'
@@ -55,10 +56,10 @@ jobs:
contents: read
id-token: write
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Setup Deno
- uses: denoland/setup-deno@667a34cdef165d8d2b2e98dde39547c9daac7282 # v2.0.4
+ uses: denoland/setup-deno@v2.0.4
with:
deno-version: v2.x
diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml
index 8c43f1c0..579479c8 100644
--- a/.github/workflows/push-email-notify.yml
+++ b/.github/workflows/push-email-notify.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Dormant push-email notification. ARMED by setting the repo variable
@@ -40,7 +41,7 @@ jobs:
timeout-minutes: 5
steps:
- name: Send push notification email
- uses: hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7 # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
+ uses: hyperpolymath/smtp-notify-action@v0.2.0
with:
server_address: ${{ secrets.SMTP_HOST }}
server_port: ${{ secrets.SMTP_PORT }}
diff --git a/.github/workflows/readme-derive.yml b/.github/workflows/readme-derive.yml
index 67b154db..4684a108 100644
--- a/.github/workflows/readme-derive.yml
+++ b/.github/workflows/readme-derive.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
index 9d224994..7543d56b 100644
--- a/.github/workflows/release.yml
+++ b/.github/workflows/release.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -27,10 +28,10 @@ jobs:
outputs:
hashes: ${{ steps.hash.outputs.hashes }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
@@ -76,7 +77,7 @@ jobs:
echo "hashes=${HASHES}" >> "$GITHUB_OUTPUT"
- name: Upload build artifacts
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: release-artifacts
path: boj-server-*-linux-x86_64.tar.gz
@@ -92,7 +93,7 @@ jobs:
changelog: ${{ steps.cliff.outputs.content }}
version: ${{ steps.version.outputs.version }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
@@ -122,7 +123,7 @@ jobs:
git cliff --output CHANGELOG.md
- name: Upload updated CHANGELOG.md
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
+ uses: actions/upload-artifact@v4.6.2
with:
name: changelog
path: CHANGELOG.md
@@ -136,16 +137,16 @@ jobs:
permissions:
contents: write
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Download build artifacts
- uses: actions/download-artifact@95815c38cf2ff2164869cbab79da8d1f422bc89e # v4.2.1
+ uses: actions/download-artifact@v4.2.1
with:
name: release-artifacts
path: artifacts/
- name: Create GitHub Release
- uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
+ uses: softprops/action-gh-release@v2.6.2
with:
body: ${{ needs.changelog.outputs.changelog }}
draft: false
diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index fe21f6c8..73f1cac4 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml
index 3b1c5df3..fffde78c 100644
--- a/.github/workflows/secret-scanner.yml
+++ b/.github/workflows/secret-scanner.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
diff --git a/.github/workflows/truthfulness.yml b/.github/workflows/truthfulness.yml
index 1306b1c4..8a526ef8 100644
--- a/.github/workflows/truthfulness.yml
+++ b/.github/workflows/truthfulness.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -36,7 +37,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -67,10 +68,10 @@ jobs:
steps:
- name: Checkout
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0
diff --git a/.github/workflows/zig-test.yml b/.github/workflows/zig-test.yml
index 69ebf4fd..e886291d 100644
--- a/.github/workflows/zig-test.yml
+++ b/.github/workflows/zig-test.yml
@@ -1,3 +1,4 @@
+# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
@@ -33,7 +34,7 @@ jobs:
outputs:
run: ${{ steps.detect.outputs.run }}
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
with:
fetch-depth: 0
- id: detect
@@ -64,10 +65,10 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+ - uses: actions/checkout@v6.0.2
- name: Install Zig
- uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
+ uses: mlugg/setup-zig@v2.2.1
with:
version: 0.16.0