From add795b5101d4df59fe846c90141a703c74f2644 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 3 Aug 2026 19:36:44 +0100 Subject: [PATCH] =?UTF-8?q?fix(ci):=20adopt=20GitHub=20Actions=20workflow?= =?UTF-8?q?=20lockfile=20=E2=80=94=20cures=20repo-wide=20startup=5Ffailure?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Every workflow run since 2026-07-27 22:45 died as a 0-second startup_failure with zero jobs. Root cause (readable only as a banner on the run's HTML page): GitHub's new workflow-lockfile enforcement — 'Workflow must use a lockfile.' This change: - adds .github/workflows/actions.lock, generated by gh actions-lock v0.1.7-rc.1, pinning every step-level action (and transitive composite deps) to a verified commit SHA - rewrites step-level 'uses:' refs to the symbolic form the lockfile system expects (SHAs now live in the lockfile, visible in PR diffs) - replaces two phantom dtolnay/rust-toolchain SHAs (commits reachable from no tag or branch — could never resolve) with @stable, which the lockfile pins and which restores the action's ref-as-toolchain semantics - fixes three latent parse defects unmasked once runs could start: duplicate job-level timeout-minutes in codeql.yml, and illegal timeout-minutes on the reusable-caller jobs of hypatia-scan.yml and generator-generic-ossf-slsa3-publish.yml - keeps SPDX headers on line 1 (Workflow Security Linter requirement) with the actions-lock marker on line 2 Verified on probe/actions-lockfile: Lockfile Probe success (1 real job), Chapel Accelerator CI success (3 jobs) — the first successful runs in this repository since 2026-07-27. Pure reusable-caller workflows need no lockfile entry; zero-dep inline workflows need a hand-added empty entry (gh actions-lock skips them). Co-Authored-By: Claude Fable 5 --- .github/workflows/actions.lock | 158 ++++++++++++++++++ .github/workflows/agda-meta-checker.yml | 7 +- .github/workflows/boj-build.yml | 3 +- .github/workflows/bridge-gate.yml | 3 +- .github/workflows/cargo-audit.yml | 5 +- .github/workflows/cflite_batch.yml | 5 +- .github/workflows/cflite_pr.yml | 5 +- .github/workflows/chapel-ci.yml | 29 ++-- .github/workflows/codeql.yml | 8 +- .github/workflows/container-ci.yml | 5 +- .github/workflows/dogfood-gate.yml | 13 +- .github/workflows/dogfood-proofs-ci.yml | 11 +- .github/workflows/formal-verification.yml | 11 +- .../generator-generic-ossf-slsa3-publish.yml | 4 +- .github/workflows/ghcr-publish.yml | 7 +- .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 2 +- .github/workflows/idris2-abi-ci.yml | 3 +- .github/workflows/live-provers.yml | 29 ++-- .github/workflows/mirror.yml | 1 + .github/workflows/mvp-smoke.yml | 9 +- .github/workflows/pages.yml | 9 +- .github/workflows/rust-ci.yml | 1 + .github/workflows/s4-loop.yml | 9 +- .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + .github/workflows/security-scan.yml | 1 + .github/workflows/server-boot-gate.yml | 7 +- .github/workflows/spark-theatre-gate.yml | 1 + .../workflows/verification-proofs-cron.yml | 3 +- .github/workflows/workflow-linter.yml | 3 +- 31 files changed, 270 insertions(+), 85 deletions(-) create mode 100644 .github/workflows/actions.lock diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 00000000..51c1a36c --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,158 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/agda-meta-checker.yml': + - 'actions/cache@v6.1.0' + - 'actions/checkout@v7.0.1' + - 'haskell-actions/setup@v2.11.0' + '.github/workflows/boj-build.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/bridge-gate.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/cargo-audit.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + '.github/workflows/cflite_batch.yml': + - 'google/clusterfuzzlite@v1' + '.github/workflows/cflite_pr.yml': + - 'google/clusterfuzzlite@v1' + '.github/workflows/chapel-ci.yml': + - 'actions/checkout@v7.0.1' + - 'actions/download-artifact@v8.0.1' + - 'actions/upload-artifact@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'mlugg/setup-zig@v2.2.1' + - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/codeql.yml': + - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.37.3' + '.github/workflows/container-ci.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/dogfood-proofs-ci.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/formal-verification.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/generator-generic-ossf-slsa3-publish.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/ghcr-publish.yml': + - 'actions/attest-build-provenance@v4.1.1' + - 'actions/checkout@v7.0.1' + '.github/workflows/idris2-abi-ci.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/live-provers.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/mvp-smoke.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'swatinem/rust-cache@v2.9.1' + - 'taiki-e/install-action@v2.85.3' + '.github/workflows/pages.yml': + - 'actions/checkout@v7.0.1' + - 'actions/deploy-pages@v5.0.0' + - 'actions/upload-pages-artifact@v5.0.0' + '.github/workflows/s4-loop.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'swatinem/rust-cache@v2.9.1' + - 'taiki-e/install-action@v2.85.3' + '.github/workflows/server-boot-gate.yml': + - 'actions/checkout@v7.0.1' + - 'dtolnay/rust-toolchain@stable' + - 'swatinem/rust-cache@v2.9.1' + '.github/workflows/verification-proofs-cron.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/workflow-linter.yml': + - 'actions/checkout@v7.0.1' +dependencies: + 'actions/attest-build-provenance@v4.1.1': + ref: 'v4.1.1' + commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373' + owner_id: 44036562 + repo_id: 760702757 + uses: + - 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763' + 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763': + ref: 'v4.1.1' + commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763' + owner_id: 44036562 + repo_id: 760701061 + 'actions/cache@v6.1.0': + ref: 'v6.1.0' + commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' + owner_id: 44036562 + repo_id: 197814629 + 'actions/deploy-pages@v5.0.0': + ref: 'v5.0.0' + commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + owner_id: 44036562 + repo_id: 438112499 + 'actions/download-artifact@v8.0.1': + ref: 'v8.0.1' + commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c' + owner_id: 44036562 + repo_id: 192626254 + 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': + ref: 'v7.0.0' + commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@v5.0.0': + ref: 'v5.0.0' + commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + 'dtolnay/rust-toolchain@stable': + ref: 'stable' + commit: 'sha1-4cda84d5c5c54efe2404f9d843567869ab1699d4' + owner_id: 1940490 + repo_id: 260749683 + 'github/codeql-action@v4.37.3': + ref: 'v4.37.3' + commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81' + owner_id: 9919 + repo_id: 259445878 + 'google/clusterfuzzlite@v1': + ref: 'v1' + commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1' + owner_id: 1342004 + repo_id: 400046858 + 'haskell-actions/setup@v2.11.0': + ref: 'v2.11.0' + commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' + owner_id: 75048950 + repo_id: 623796603 + 'mlugg/setup-zig@v2.2.1': + ref: 'v2.2.1' + commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29' + owner_id: 7289241 + repo_id: 812112570 + 'swatinem/rust-cache@v2.9.1': + ref: 'v2.9.1' + commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4' + owner_id: 580492 + repo_id: 298565987 + 'taiki-e/install-action@v2.85.3': + ref: 'v2.85.3' + commit: 'sha1-18b1216eba7f8039b0f8d131d5473787f0edce68' + owner_id: 43724913 + repo_id: 442947557 diff --git a/.github/workflows/agda-meta-checker.yml b/.github/workflows/agda-meta-checker.yml index 9c906596..8a46b28f 100644 --- a/.github/workflows/agda-meta-checker.yml +++ b/.github/workflows/agda-meta-checker.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # CI workflow for ECHIDNA Agda meta-checker # Type-checks all formal proofs verifying trust pipeline correctness @@ -33,7 +34,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 # Required-check shim: only the meta-checker/ tree needs the real proof # check. Non-PR events (push, workflow_dispatch) always run it. @@ -61,14 +62,14 @@ jobs: - name: Setup Haskell if: steps.detect.outputs.relevant == 'true' - uses: haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553 # v2 + uses: haskell-actions/setup@v2.11.0 with: ghc-version: '9.6' cabal-version: '3.10' - name: Cache Agda if: steps.detect.outputs.relevant == 'true' - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index a2b04f17..da7de081 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger on: push: @@ -17,7 +18,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) run: | # Send a secure trigger to boj-server to build this repository diff --git a/.github/workflows/bridge-gate.yml b/.github/workflows/bridge-gate.yml index 3f9c747a..cbd400f3 100644 --- a/.github/workflows/bridge-gate.yml +++ b/.github/workflows/bridge-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell # # bridge-gate.yml -- merge-orchestration CVE/bump gate. @@ -29,7 +30,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 25 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 + - uses: actions/checkout@v7.0.1 - name: B3 gate -- nix bumps (no network) env: diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index 8373ccf2..728fe7f8 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # cargo-audit.yml — Dependency vulnerability scanning for Rust projects. @@ -31,7 +32,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Detect Cargo.lock id: detect @@ -45,7 +46,7 @@ jobs: - name: Install Rust toolchain if: steps.detect.outputs.present == 'true' - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Install cargo-audit if: steps.detect.outputs.present == 'true' diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index c18d708d..023a1c3f 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: ClusterFuzzLite batch fuzzing on: schedule: @@ -19,14 +20,14 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 1800 diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 21698740..10a8fdab 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: ClusterFuzzLite PR fuzzing on: pull_request: @@ -24,14 +25,14 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 300 diff --git a/.github/workflows/chapel-ci.yml b/.github/workflows/chapel-ci.yml index 2345c74d..949acbb8 100644 --- a/.github/workflows/chapel-ci.yml +++ b/.github/workflows/chapel-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Chapel Accelerator CI on: @@ -61,7 +62,7 @@ jobs: runs-on: ubuntu-22.04 timeout-minutes: 30 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Chapel ${{ env.CHAPEL_VERSION }} (SHA-pinned .deb) run: | @@ -95,7 +96,7 @@ jobs: ./chapel_smoke - name: Upload Chapel library artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4 + uses: actions/upload-artifact@v7.0.1 with: name: chapel-lib path: src/chapel/lib/libechidna_chapel* @@ -113,10 +114,10 @@ jobs: runs-on: ubuntu-22.04 timeout-minutes: 30 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Zig - uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1 + uses: mlugg/setup-zig@v2.2.1 with: version: 0.14.0 @@ -127,7 +128,7 @@ jobs: run: cd src/zig_ffi && zig build test - name: Upload FFI library artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4 + uses: actions/upload-artifact@v7.0.1 with: name: chapel-ffi-lib path: src/zig_ffi/zig-out/lib/ @@ -144,18 +145,18 @@ jobs: needs: zig-ffi continue-on-error: true steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Rust cache - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Download FFI library - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v4 + uses: actions/download-artifact@v8.0.1 with: name: chapel-ffi-lib path: src/zig_ffi/zig-out/lib/ @@ -183,7 +184,7 @@ jobs: needs: [chapel-build, zig-ffi] continue-on-error: true steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Chapel ${{ env.CHAPEL_VERSION }} (SHA-pinned .deb) run: | @@ -196,20 +197,20 @@ jobs: chpl --version - name: Install Zig - uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1 + uses: mlugg/setup-zig@v2.2.1 with: version: 0.14.0 - name: Install Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Rust cache - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Download real Chapel library - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v4 + uses: actions/download-artifact@v8.0.1 with: name: chapel-lib path: src/chapel/ diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 94058c0f..aa2b465b 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: @@ -27,7 +28,6 @@ jobs: permissions: contents: read security-events: write - timeout-minutes: 15 strategy: fail-fast: false matrix: @@ -39,15 +39,15 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3 + uses: github/codeql-action/init@v4.37.3 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v3 + uses: github/codeql-action/analyze@v4.37.3 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/container-ci.yml b/.github/workflows/container-ci.yml index 3507e578..89613386 100644 --- a/.github/workflows/container-ci.yml +++ b/.github/workflows/container-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # container-ci.yml — Container build verification. # @@ -57,7 +58,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Podman run: | @@ -154,7 +155,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Podman run: | diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 18243ad8..247840af 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate @@ -32,7 +33,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for A2ML files id: detect @@ -73,7 +74,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for K9 files id: detect @@ -119,7 +120,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Scan for invisible characters id: lint @@ -184,7 +185,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for Groove manifest id: groove @@ -243,7 +244,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -315,7 +316,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/dogfood-proofs-ci.yml b/.github/workflows/dogfood-proofs-ci.yml index b5b964e9..52779574 100644 --- a/.github/workflows/dogfood-proofs-ci.yml +++ b/.github/workflows/dogfood-proofs-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Gates the ECHIDNA dogfood proof corpus: every theorem under proofs/{coq,lean,agda} # must type-check. These proofs had no CI coverage before this workflow -- the other # proof workflows are path-filtered to meta-checker/** (agda-meta-checker) and @@ -45,7 +46,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Coq run: | @@ -72,7 +73,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install elan + pinned Lean toolchain run: | @@ -124,7 +125,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install elan + pinned Lean toolchain run: | @@ -174,7 +175,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Idris2 run: | @@ -218,7 +219,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Agda + standard library run: | diff --git a/.github/workflows/formal-verification.yml b/.github/workflows/formal-verification.yml index 03c885fa..e007d657 100644 --- a/.github/workflows/formal-verification.yml +++ b/.github/workflows/formal-verification.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # formal-verification.yml — Creusot formal verification of the trust-pipeline kernel. @@ -47,15 +48,15 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install stable Rust toolchain - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Cache Rust build artefacts - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 with: workspaces: ". -> target" @@ -78,10 +79,10 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install nightly Rust toolchain (Creusot pin) - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable with: # Pin matches crates/echidna-core-spark/rust-toolchain.toml. # Update both files together when bumping. diff --git a/.github/workflows/generator-generic-ossf-slsa3-publish.yml b/.github/workflows/generator-generic-ossf-slsa3-publish.yml index b10ae87d..69bb8947 100644 --- a/.github/workflows/generator-generic-ossf-slsa3-publish.yml +++ b/.github/workflows/generator-generic-ossf-slsa3-publish.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # This workflow uses actions that are not certified by GitHub. # They are provided by a third-party and are governed by # separate terms of service, privacy policy, and support @@ -28,7 +29,7 @@ jobs: digests: ${{ steps.hash.outputs.digests }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 # ======================================================== # @@ -61,7 +62,6 @@ jobs: provenance: needs: [build] - timeout-minutes: 10 permissions: actions: read # To read the workflow path. id-token: write # To sign the provenance. diff --git a/.github/workflows/ghcr-publish.yml b/.github/workflows/ghcr-publish.yml index d201d6d3..b1431b44 100644 --- a/.github/workflows/ghcr-publish.yml +++ b/.github/workflows/ghcr-publish.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Publish to GHCR permissions: @@ -31,7 +32,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 + uses: actions/checkout@v7.0.1 - name: Install nerdctl and containerd run: | @@ -88,14 +89,14 @@ jobs: # gh attest verify oci://ghcr.io/${{ github.repository }}: \ # --repo ${{ github.repository }} - name: Attest container provenance (minimal image) - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@v4.1.1 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.push.outputs.min_digest }} push-to-registry: true - name: Attest container provenance (full image) - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@v4.1.1 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.push.outputs.full_digest }} diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 53f4d575..513ad091 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: PMPL-1.0-or-later +# This workflow is managed by gh actions-lock. name: Governance on: diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 03251e53..108fa11b 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: PMPL-1.0-or-later +# This workflow is managed by gh actions-lock. name: Hypatia Security Scan on: @@ -17,5 +18,4 @@ permissions: jobs: hypatia: uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@6cd3772824e59c8c9affeab66061e25383544242 - timeout-minutes: 10 secrets: inherit diff --git a/.github/workflows/idris2-abi-ci.yml b/.github/workflows/idris2-abi-ci.yml index 0c44bdf1..707d0c13 100644 --- a/.github/workflows/idris2-abi-ci.yml +++ b/.github/workflows/idris2-abi-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Idris2 ABI Type-Check on: @@ -29,7 +30,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 30 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 # Required-check shim: decide whether ABI/proof sources actually changed. # The workflow file itself is intentionally NOT in the pattern, so CI-only diff --git a/.github/workflows/live-provers.yml b/.github/workflows/live-provers.yml index 0d437296..31fa39b3 100644 --- a/.github/workflows/live-provers.yml +++ b/.github/workflows/live-provers.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # ECHIDNA — Live-Prover CI # # Exercises real prover binaries against canonical micro-goals. Complements @@ -74,13 +75,13 @@ jobs: - chuffed steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Cargo - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Provision prover (${{ matrix.backend }}) run: | @@ -133,7 +134,7 @@ jobs: continue-on-error: true steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Guix run: | sudo apt-get update -qq || sudo apt-get update -qq --fix-missing @@ -168,11 +169,11 @@ jobs: - tlaps steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Cargo - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Provision ${{ matrix.backend }} (best-effort via apt / upstream release) continue-on-error: true run: | @@ -316,11 +317,11 @@ jobs: - imandra steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Cargo - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Provision ${{ matrix.backend }} (best-effort) continue-on-error: true run: | @@ -418,7 +419,7 @@ jobs: continue-on-error: true steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Announce Wave-4 TODO run: | echo "Tier-4 backends (Mizar, Nuprl, PVS, Minlog, Dedukti, Arend, KeY, Prism, UPPAAL," @@ -444,11 +445,11 @@ jobs: - faial steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable + uses: dtolnay/rust-toolchain@stable - name: Cache Cargo - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Provision ${{ matrix.backend }} (best-effort, CUDA/OpenCL required) continue-on-error: true run: | diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index f674c159..b57dfa47 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/mvp-smoke.yml b/.github/workflows/mvp-smoke.yml index 1292ee79..19810eb8 100644 --- a/.github/workflows/mvp-smoke.yml +++ b/.github/workflows/mvp-smoke.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: MVP Smoke (Best Effort) on: @@ -28,18 +29,18 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 + uses: actions/checkout@v7.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@6d9817901c499d6b02debbb57edb38d33daa680b # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Cache Cargo - uses: Swatinem/rust-cache@65012b490220f477f20ab979e35ae732e6de4e68 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Install just - uses: taiki-e/install-action@18b1216eba7f8039b0f8d131d5473787f0edce68 # v2.85.3 + uses: taiki-e/install-action@v2.85.3 with: # Governance R1 requires versioned family-tool pins # (just|must|trust|adjust|bust|dust|intend); bare `tool: just` diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index 8f849ca5..62c46b32 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: AGPL-3.0-or-later +# This workflow is managed by gh actions-lock. name: GitHub Pages (Ddraig SSG) on: push: @@ -19,9 +20,9 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff steps: - name: Checkout Site - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout Ddraig SSG - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/ddraig-ssg path: .ddraig-ssg @@ -35,7 +36,7 @@ jobs: mkdir -p _site/playground cp echidna-playground/index.html echidna-playground/styles.css _site/playground/ - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -48,4 +49,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 + uses: actions/deploy-pages@v5.0.0 diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 34690d9f..288393ba 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Rust CI — thin wrapper calling the shared estate reusable in # hyperpolymath/standards. Configure once, propagate everywhere. # See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards. diff --git a/.github/workflows/s4-loop.yml b/.github/workflows/s4-loop.yml index 06e2cfc5..9d4b96f0 100644 --- a/.github/workflows/s4-loop.yml +++ b/.github/workflows/s4-loop.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # S4 loop-closure CI — brings up verisim-api as a service container and # runs the echidna s4_loop_closure integration test. Filed once # ghcr.io/hyperpolymath/verisimdb-api:latest became available (PR #121). @@ -32,15 +33,15 @@ jobs: VERISIM_URL: http://localhost:8080 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 + uses: actions/checkout@v7.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@6d9817901c499d6b02debbb57edb38d33daa680b # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Cache Cargo - uses: Swatinem/rust-cache@65012b490220f477f20ab979e35ae732e6de4e68 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Install just - uses: taiki-e/install-action@18b1216eba7f8039b0f8d131d5473787f0edce68 # v2.85.3 + uses: taiki-e/install-action@v2.85.3 with: tool: just@1.51.0 - name: Install system dependencies diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index c9f09fe7..41e18794 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: PMPL-1.0-or-later +# This workflow is managed by gh actions-lock. name: OSSF Scorecard on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index d4740023..a4d88925 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Secret Scanner on: diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index f3b10313..44c6ec0d 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Security Scan diff --git a/.github/workflows/server-boot-gate.yml b/.github/workflows/server-boot-gate.yml index c5f12277..9c3807ca 100644 --- a/.github/workflows/server-boot-gate.yml +++ b/.github/workflows/server-boot-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Server boot gate — builds the echidna binary, boots the server, and # verifies that /api/health, /api/provers, and a session {id} route all # respond. Exists so "compiles" can never again mean "boots" — the @@ -24,13 +25,13 @@ jobs: contents: read steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 + uses: actions/checkout@v7.0.1 - name: Setup Rust toolchain - uses: dtolnay/rust-toolchain@6d9817901c499d6b02debbb57edb38d33daa680b # stable + uses: dtolnay/rust-toolchain@stable with: toolchain: stable - name: Cache Cargo - uses: Swatinem/rust-cache@65012b490220f477f20ab979e35ae732e6de4e68 # v2 + uses: Swatinem/rust-cache@v2.9.1 - name: Install system dependencies run: sudo apt-get install -y libssl-dev pkg-config - name: Build echidna binary diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index 68cdc970..bd6bc072 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Estate SPARK Theatre Gate — thin caller of the reusable workflow in # hyperpolymath/standards (#135 / #141). Pinned by commit SHA per the # estate action-pinning policy. Regenerate the pin only when the reusable diff --git a/.github/workflows/verification-proofs-cron.yml b/.github/workflows/verification-proofs-cron.yml index 8eb908cd..2e5f9f6f 100644 --- a/.github/workflows/verification-proofs-cron.yml +++ b/.github/workflows/verification-proofs-cron.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Weekly verification of the heavier self-proof corpora that are too slow and too # network-heavy to gate on every PR: currently Isabelle/HOL (proofs/isabelle). The # Isabelle toolchain is a large, non-apt download (~500MB tarball), so this runs on @@ -38,7 +39,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 60 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Isabelle run: | diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 92c7eece..ed0ae72a 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter @@ -17,7 +18,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v4 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: |