Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
158 changes: 158 additions & 0 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
@@ -0,0 +1,158 @@
# This file is machine-generated by `gh actions-lock`.
# Do not edit by hand; run `gh actions-lock` to update.
# Docs: https://gh.io/actions-lockfile
version: 'v0.0.2'
workflows:
'.github/workflows/agda-meta-checker.yml':
- 'actions/cache@v6.1.0'
- 'actions/checkout@v7.0.1'
- 'haskell-actions/setup@v2.11.0'
'.github/workflows/boj-build.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/bridge-gate.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/cargo-audit.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
'.github/workflows/cflite_batch.yml':
- 'google/clusterfuzzlite@v1'
'.github/workflows/cflite_pr.yml':
- 'google/clusterfuzzlite@v1'
'.github/workflows/chapel-ci.yml':
- 'actions/checkout@v7.0.1'
- 'actions/download-artifact@v8.0.1'
- 'actions/upload-artifact@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'mlugg/setup-zig@v2.2.1'
- 'swatinem/rust-cache@v2.9.1'
'.github/workflows/codeql.yml':
- 'actions/checkout@v7.0.1'
- 'github/codeql-action@v4.37.3'
'.github/workflows/container-ci.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/dogfood-gate.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/dogfood-proofs-ci.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/formal-verification.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
'.github/workflows/generator-generic-ossf-slsa3-publish.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/ghcr-publish.yml':
- 'actions/attest-build-provenance@v4.1.1'
- 'actions/checkout@v7.0.1'
'.github/workflows/idris2-abi-ci.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/live-provers.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
'.github/workflows/mvp-smoke.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'taiki-e/install-action@v2.85.3'
'.github/workflows/pages.yml':
- 'actions/checkout@v7.0.1'
- 'actions/deploy-pages@v5.0.0'
- 'actions/upload-pages-artifact@v5.0.0'
'.github/workflows/s4-loop.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
- 'taiki-e/install-action@v2.85.3'
'.github/workflows/server-boot-gate.yml':
- 'actions/checkout@v7.0.1'
- 'dtolnay/rust-toolchain@stable'
- 'swatinem/rust-cache@v2.9.1'
'.github/workflows/verification-proofs-cron.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/workflow-linter.yml':
- 'actions/checkout@v7.0.1'
dependencies:
'actions/attest-build-provenance@v4.1.1':
ref: 'v4.1.1'
commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373'
owner_id: 44036562
repo_id: 760702757
uses:
- 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763'
'actions/attest@a1948c3f048ba23858d222213b7c278aabede763':
ref: 'v4.1.1'
commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763'
owner_id: 44036562
repo_id: 760701061
'actions/cache@v6.1.0':
ref: 'v6.1.0'
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
owner_id: 44036562
repo_id: 215566462
'actions/checkout@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
owner_id: 44036562
repo_id: 197814629
'actions/deploy-pages@v5.0.0':
ref: 'v5.0.0'
commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128'
owner_id: 44036562
repo_id: 438112499
'actions/download-artifact@v8.0.1':
ref: 'v8.0.1'
commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
owner_id: 44036562
repo_id: 192626254
'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f':
ref: 'v7.0.0'
commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
owner_id: 44036562
repo_id: 192625955
'actions/upload-artifact@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
owner_id: 44036562
repo_id: 192625955
'actions/upload-pages-artifact@v5.0.0':
ref: 'v5.0.0'
commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9'
owner_id: 44036562
repo_id: 496012378
uses:
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
'dtolnay/rust-toolchain@stable':
ref: 'stable'
commit: 'sha1-4cda84d5c5c54efe2404f9d843567869ab1699d4'
owner_id: 1940490
repo_id: 260749683
'github/codeql-action@v4.37.3':
ref: 'v4.37.3'
commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81'
owner_id: 9919
repo_id: 259445878
'google/clusterfuzzlite@v1':
ref: 'v1'
commit: 'sha1-884713a6c30a92e5e8544c39945cd7cb630abcd1'
owner_id: 1342004
repo_id: 400046858
'haskell-actions/setup@v2.11.0':
ref: 'v2.11.0'
commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553'
owner_id: 75048950
repo_id: 623796603
'mlugg/setup-zig@v2.2.1':
ref: 'v2.2.1'
commit: 'sha1-d1434d08867e3ee9daa34448df10607b98908d29'
owner_id: 7289241
repo_id: 812112570
'swatinem/rust-cache@v2.9.1':
ref: 'v2.9.1'
commit: 'sha1-c19371144df3bb44fab255c43d04cbc2ab54d1c4'
owner_id: 580492
repo_id: 298565987
'taiki-e/install-action@v2.85.3':
ref: 'v2.85.3'
commit: 'sha1-18b1216eba7f8039b0f8d131d5473787f0edce68'
owner_id: 43724913
repo_id: 442947557
7 changes: 4 additions & 3 deletions .github/workflows/agda-meta-checker.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# CI workflow for ECHIDNA Agda meta-checker
# Type-checks all formal proofs verifying trust pipeline correctness

Expand Down Expand Up @@ -33,7 +34,7 @@ jobs:
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
uses: actions/checkout@v7.0.1

# Required-check shim: only the meta-checker/ tree needs the real proof
# check. Non-PR events (push, workflow_dispatch) always run it.
Expand Down Expand Up @@ -61,14 +62,14 @@ jobs:

- name: Setup Haskell
if: steps.detect.outputs.relevant == 'true'
uses: haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553 # v2
uses: haskell-actions/setup@v2.11.0
with:
ghc-version: '9.6'
cabal-version: '3.10'

- name: Cache Agda
if: steps.detect.outputs.relevant == 'true'
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
uses: actions/cache@v6.1.0
with:
path: |
~/.cabal
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: BoJ Server Build Trigger
on:
push:
Expand All @@ -17,7 +18,7 @@ jobs:
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
uses: actions/checkout@v7.0.1
- name: Trigger BoJ Server (Casket/ssg-mcp)
run: |
# Send a secure trigger to boj-server to build this repository
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/bridge-gate.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
#
# bridge-gate.yml -- merge-orchestration CVE/bump gate.
Expand Down Expand Up @@ -29,7 +30,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
- uses: actions/checkout@v7.0.1

- name: B3 gate -- nix bumps (no network)
env:
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/cargo-audit.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
# cargo-audit.yml — Dependency vulnerability scanning for Rust projects.
Expand Down Expand Up @@ -31,7 +32,7 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
uses: actions/checkout@v7.0.1

- name: Detect Cargo.lock
id: detect
Expand All @@ -45,7 +46,7 @@ jobs:

- name: Install Rust toolchain
if: steps.detect.outputs.present == 'true'
uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable
uses: dtolnay/rust-toolchain@stable

- name: Install cargo-audit
if: steps.detect.outputs.present == 'true'
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/cflite_batch.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite batch fuzzing
on:
schedule:
Expand All @@ -19,14 +20,14 @@ jobs:
steps:
- name: Build Fuzzers (${{ matrix.sanitizer }})
id: build
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
with:
language: rust
sanitizer: ${{ matrix.sanitizer }}

- name: Run Fuzzers (${{ matrix.sanitizer }})
id: run
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 1800
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/cflite_pr.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: ClusterFuzzLite PR fuzzing
on:
pull_request:
Expand All @@ -24,14 +25,14 @@ jobs:
steps:
- name: Build Fuzzers (${{ matrix.sanitizer }})
id: build
uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/build_fuzzers@v1
with:
language: rust
sanitizer: ${{ matrix.sanitizer }}

- name: Run Fuzzers (${{ matrix.sanitizer }})
id: run
uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1
uses: google/clusterfuzzlite/actions/run_fuzzers@v1
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
fuzz-seconds: 300
Expand Down
29 changes: 15 additions & 14 deletions .github/workflows/chapel-ci.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,5 @@
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Chapel Accelerator CI

on:
Expand Down Expand Up @@ -61,7 +62,7 @@ jobs:
runs-on: ubuntu-22.04
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1

- name: Install Chapel ${{ env.CHAPEL_VERSION }} (SHA-pinned .deb)
run: |
Expand Down Expand Up @@ -95,7 +96,7 @@ jobs:
./chapel_smoke

- name: Upload Chapel library artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4
uses: actions/upload-artifact@v7.0.1
with:
name: chapel-lib
path: src/chapel/lib/libechidna_chapel*
Expand All @@ -113,10 +114,10 @@ jobs:
runs-on: ubuntu-22.04
timeout-minutes: 30
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1

- name: Install Zig
uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
uses: mlugg/setup-zig@v2.2.1
with:
version: 0.14.0

Expand All @@ -127,7 +128,7 @@ jobs:
run: cd src/zig_ffi && zig build test

- name: Upload FFI library artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4
uses: actions/upload-artifact@v7.0.1
with:
name: chapel-ffi-lib
path: src/zig_ffi/zig-out/lib/
Expand All @@ -144,18 +145,18 @@ jobs:
needs: zig-ffi
continue-on-error: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable
uses: dtolnay/rust-toolchain@stable
with:
toolchain: stable

- name: Rust cache
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2
uses: Swatinem/rust-cache@v2.9.1

- name: Download FFI library
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v4
uses: actions/download-artifact@v8.0.1
with:
name: chapel-ffi-lib
path: src/zig_ffi/zig-out/lib/
Expand Down Expand Up @@ -183,7 +184,7 @@ jobs:
needs: [chapel-build, zig-ffi]
continue-on-error: true
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1

- name: Install Chapel ${{ env.CHAPEL_VERSION }} (SHA-pinned .deb)
run: |
Expand All @@ -196,20 +197,20 @@ jobs:
chpl --version

- name: Install Zig
uses: mlugg/setup-zig@d1434d08867e3ee9daa34448df10607b98908d29 # v2.2.1
uses: mlugg/setup-zig@v2.2.1
with:
version: 0.14.0

- name: Install Rust
uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable
uses: dtolnay/rust-toolchain@stable
with:
toolchain: stable

- name: Rust cache
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2
uses: Swatinem/rust-cache@v2.9.1

- name: Download real Chapel library
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v4
uses: actions/download-artifact@v8.0.1
with:
name: chapel-lib
path: src/chapel/
Expand Down
Loading
Loading