Repository navigation
fix(ci): regenerate actions.lock; Dependabot stops bumping action pins; standards pins → c59f24f7 - #96
Merged
Conversation
…s; standards pins → c59f24f7 Root cause of the CodeQL outage: Dependabot #92 bumped github/codeql-action to v4.37.9 without regenerating .github/workflows/actions.lock, so every CodeQL run since 2026-09-02 11:54Z died in startup_failure ("Invalid lockfile") and the two required CodeQL contexts could never report on any PR. Nobody could have regenerated the lock either: `gh actions-lock` refuses to run while any workflow is unparseable, and workflow-linter.yml had `permissions: read-all` followed by an indented `actions: read` (invalid YAML). Fixed to a mapping. - actions.lock: codeql-action v4.37.9 (cdf488f) pinned; stale dawidd6/action-send-mail entry pruned. - push-email-notify.yml deleted: disabled_manually, last run skipped 2026-07-20, references a tag the lock could not resolve; replaced estate-wide by smtp-notify-action (standards spec §5.5). - dependabot.yml: `github-actions` ecosystem removed — pin bumps come from the standards lock-refresh workflow, which regenerates the lock in the same PR (spec §6.4). `guix` removed: not a Dependabot ecosystem, and an invalid entry disables the whole config. - standards reusables pinned 84355587 → c59f24f7 (PR #718): the lock check is now its own job that fetches its scripts from standards instead of the consumer cwd, which is why "Workflow security linter" exited 127 here on every run. Verified locally: all 17 workflows parse (yq); `update-actions-lock.sh --verify-local` valid; `check-actions-lock-gate.sh` exit 0.
Contributor
|
Warning Review limit reachedNext included review available in 3 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (8)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
hyperpolymath
added a commit
that referenced
this pull request
Sep 2, 2026
## Why Both Dependabot jobs have aborted on every run since at least 2026-08-31 (run 33389729963), and again twice on 09a272c after #96: - cargo: `/Cargo.toml not found` — the crate is under `rust_core/`, not the root. - npm: `/package.json not found` — the repository has no `package.json` at any path. ## Change - `cargo` entry: `directory: "/rust_core"`. - `npm` entry removed, with a comment recording why. - `github-actions` stays absent (pin bumps come from the standards lock-refresh workflow, see #96). ## Pilot note First PR on this repository under the replaced Base ruleset (canonical `standards/config/rulesets/base.json`, 17 machine-derived required contexts). Expected to reach `mergeStateStatus: CLEAN` and merge without `--admin`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Root cause of the CodeQL outage: Dependabot #92 bumped
github/codeql-action to v4.37.9 without regenerating
.github/workflows/actions.lock, so every CodeQL run since
2026-09-02 11:54Z died in startup_failure ("Invalid lockfile") and the
two required CodeQL contexts could never report on any PR.
Nobody could have regenerated the lock either:
gh actions-lockrefuses to run while any workflow is unparseable, and
workflow-linter.yml had
permissions: read-allfollowed by an indentedactions: read(invalid YAML). Fixed to a mapping.dawidd6/action-send-mail entry pruned.
2026-07-20, references a tag the lock could not resolve; replaced
estate-wide by smtp-notify-action (standards spec §5.5).
github-actionsecosystem removed — pin bumps comefrom the standards lock-refresh workflow, which regenerates the lock
in the same PR (spec §6.4).
guixremoved: not a Dependabotecosystem, and an invalid entry disables the whole config.
lock check is now its own job that fetches its scripts from
standards instead of the consumer cwd, which is why
"Workflow security linter" exited 127 here on every run.
Verified locally: all 17 workflows parse (yq);
update-actions-lock.sh --verify-localvalid;check-actions-lock-gate.shexit 0.Unblocks #90 (its two required CodeQL contexts). Ruleset replacement follows as a separate settings change (standards spec §7.3).