Skip to content

fix(ci): regenerate actions.lock; Dependabot stops bumping action pins; standards pins → c59f24f7 - #96

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/actions-lock-and-standards-pins
Sep 2, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/actions-lock-and-standards-pins

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Root cause of the CodeQL outage: Dependabot #92 bumped
github/codeql-action to v4.37.9 without regenerating
.github/workflows/actions.lock, so every CodeQL run since
2026-09-02 11:54Z died in startup_failure ("Invalid lockfile") and the
two required CodeQL contexts could never report on any PR.

Nobody could have regenerated the lock either: gh actions-lock
refuses to run while any workflow is unparseable, and
workflow-linter.yml had permissions: read-all followed by an indented
actions: read (invalid YAML). Fixed to a mapping.

  • actions.lock: codeql-action v4.37.9 (cdf488f) pinned; stale
    dawidd6/action-send-mail entry pruned.
  • push-email-notify.yml deleted: disabled_manually, last run skipped
    2026-07-20, references a tag the lock could not resolve; replaced
    estate-wide by smtp-notify-action (standards spec §5.5).
  • dependabot.yml: github-actions ecosystem removed — pin bumps come
    from the standards lock-refresh workflow, which regenerates the lock
    in the same PR (spec §6.4). guix removed: not a Dependabot
    ecosystem, and an invalid entry disables the whole config.
  • standards reusables pinned 84355587 → c59f24f7 (PR #718): the
    lock check is now its own job that fetches its scripts from
    standards instead of the consumer cwd, which is why
    "Workflow security linter" exited 127 here on every run.

Verified locally: all 17 workflows parse (yq); update-actions-lock.sh --verify-local valid; check-actions-lock-gate.sh exit 0.

Unblocks #90 (its two required CodeQL contexts). Ruleset replacement follows as a separate settings change (standards spec §7.3).

…s; standards pins → c59f24f7

Root cause of the CodeQL outage: Dependabot #92 bumped
github/codeql-action to v4.37.9 without regenerating
.github/workflows/actions.lock, so every CodeQL run since
2026-09-02 11:54Z died in startup_failure ("Invalid lockfile") and the
two required CodeQL contexts could never report on any PR.

Nobody could have regenerated the lock either: `gh actions-lock`
refuses to run while any workflow is unparseable, and
workflow-linter.yml had `permissions: read-all` followed by an indented
`actions: read` (invalid YAML). Fixed to a mapping.

- actions.lock: codeql-action v4.37.9 (cdf488f) pinned; stale
  dawidd6/action-send-mail entry pruned.
- push-email-notify.yml deleted: disabled_manually, last run skipped
  2026-07-20, references a tag the lock could not resolve; replaced
  estate-wide by smtp-notify-action (standards spec §5.5).
- dependabot.yml: `github-actions` ecosystem removed — pin bumps come
  from the standards lock-refresh workflow, which regenerates the lock
  in the same PR (spec §6.4). `guix` removed: not a Dependabot
  ecosystem, and an invalid entry disables the whole config.
- standards reusables pinned 84355587 → c59f24f7 (PR #718): the
  lock check is now its own job that fetches its scripts from
  standards instead of the consumer cwd, which is why
  "Workflow security linter" exited 127 here on every run.

Verified locally: all 17 workflows parse (yq); `update-actions-lock.sh
--verify-local` valid; `check-actions-lock-gate.sh` exit 0.
@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 3 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 03df762d-031e-49c0-a669-0c803dc4b3c5

📥 Commits

Reviewing files that changed from the base of the PR and between 3dbaddd and 68a4982.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (8)
  • .github/dependabot.yml
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/mirror.yml
  • .github/workflows/push-email-notify.yml
  • .github/workflows/scorecard.yml
  • .github/workflows/secret-scanner.yml
  • .github/workflows/workflow-linter.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 09a272c into main Sep 2, 2026
31 of 40 checks passed
@hyperpolymath
hyperpolymath deleted the fix/actions-lock-and-standards-pins branch September 2, 2026 12:20
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

hyperpolymath added a commit that referenced this pull request Sep 2, 2026
## Why

Both Dependabot jobs have aborted on every run since at least 2026-08-31
(run 33389729963), and again twice on 09a272c after #96:

- cargo: `/Cargo.toml not found` — the crate is under `rust_core/`, not
the root.
- npm: `/package.json not found` — the repository has no `package.json`
at any path.

## Change

- `cargo` entry: `directory: "/rust_core"`.
- `npm` entry removed, with a comment recording why.
- `github-actions` stays absent (pin bumps come from the standards
lock-refresh workflow, see #96).

## Pilot note

First PR on this repository under the replaced Base ruleset (canonical
`standards/config/rulesets/base.json`, 17 machine-derived required
contexts). Expected to reach `mergeStateStatus: CLEAN` and merge without
`--admin`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant