diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 36c488a..3570b51 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -7,7 +7,7 @@ workflows: - 'actions/checkout@v7.0.1' '.github/workflows/cargo-audit.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' '.github/workflows/casket-pages.yml': - 'actions/cache@v6.1.0' - 'actions/checkout@v7.0.1' @@ -22,13 +22,13 @@ workflows: '.github/workflows/container.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - - 'docker/build-push-action@v7.3.0' + - 'docker/build-push-action@v7.4.0' - 'docker/login-action@v4.6.0' - 'docker/metadata-action@v6.2.0' - - 'docker/setup-buildx-action@v4.3.0' + - 'docker/setup-buildx-action@v4.4.0' '.github/workflows/db-checks.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'swatinem/rust-cache@v2.9.2' '.github/workflows/dependabot-automerge.yml': - 'dependabot/fetch-metadata@v3.1.0' @@ -57,7 +57,7 @@ workflows: '.github/workflows/publish.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'softprops/action-gh-release@v3.0.3' - 'swatinem/rust-cache@v2.9.2' '.github/workflows/release.yml': @@ -65,7 +65,7 @@ workflows: - 'actions/checkout@v7.0.1' - 'actions/download-artifact@v8.0.1' - 'actions/upload-artifact@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'softprops/action-gh-release@v3.0.3' '.github/workflows/rhodibot.yml': - 'actions/checkout@v7.0.1' @@ -76,7 +76,7 @@ workflows: - 'erlef/setup-beam@v1.24.1' '.github/workflows/stress-test.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' '.github/workflows/workflow-linter.yml': - 'actions/checkout@v7.0.1' dependencies: @@ -139,9 +139,9 @@ dependencies: commit: 'sha1-25dd0e34f4fe68f24cc83900b1fe3fe149efef98' owner_id: 27347476 repo_id: 371068214 - 'docker/build-push-action@v7.3.0': - ref: 'v7.3.0' - commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a' + 'docker/build-push-action@v7.4.0': + ref: 'v7.4.0' + commit: 'sha1-c3c9e263c25d99ce0380d002d59b67737d91b0dc' owner_id: 5429470 repo_id: 241092383 'docker/login-action@v4.6.0': @@ -154,14 +154,14 @@ dependencies: commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302' owner_id: 5429470 repo_id: 306769011 - 'docker/setup-buildx-action@v4.3.0': - ref: 'v4.3.0' - commit: 'sha1-37fe631027851001ddb9b187196cc803df7f5f0e' + 'docker/setup-buildx-action@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-594f3bf4285d9ea8dc53c9a0c9c4092420091003' owner_id: 5429470 repo_id: 288485773 - 'dtolnay/rust-toolchain@master': - ref: 'master' - commit: 'sha1-b3b07ba8b418998c39fb20f53e8b695cdcc8de1b' + 'dtolnay/rust-toolchain@v1': + ref: 'v1' + commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 'erlef/setup-beam@v1.24.1': diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 44411f4..3ad4d57 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -24,7 +25,7 @@ jobs: if: ${{ vars.BOJ_SERVER_URL != '' }} steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) env: BOJ_URL: ${{ secrets.BOJ_SERVER_URL || vars.BOJ_SERVER_URL }} diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index a394f17..7b488ac 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -22,12 +23,12 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. This SHA currently tolerates its absence; # stating it explicitly keeps the step working across future re-pins. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 43a937a..9d732b2 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: GitHub Pages @@ -18,21 +19,21 @@ jobs: timeout-minutes: 30 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b path: .casket-ssg persist-credentials: false - name: Setup GHCup - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -75,9 +76,9 @@ jobs: fi cd .casket-ssg && cabal run --index-state=2026-09-06T00:00:00Z casket-ssg -- build ../site ../_site - name: Setup Pages - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + uses: actions/configure-pages@v6.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -90,4 +91,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index a445a24..0de84c4 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite batch fuzzing @@ -17,13 +18,13 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 1800 diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index b8ce644..da98a50 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite PR fuzzing @@ -24,13 +25,13 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 300 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 489854f..1fdfc72 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards codeql-reusable.yml. diff --git a/.github/workflows/container.yml b/.github/workflows/container.yml index 85d6efb..fc5b4c0 100644 --- a/.github/workflows/container.yml +++ b/.github/workflows/container.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Container Build @@ -21,18 +22,18 @@ jobs: attestations: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0 + uses: docker/setup-buildx-action@v4.4.0 - name: Log in to GitHub Container Registry - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + uses: docker/login-action@v4.6.0 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 + uses: docker/metadata-action@v6.2.0 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | @@ -41,7 +42,7 @@ jobs: type=sha - name: Build and push id: push - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + uses: docker/build-push-action@v7.4.0 with: context: . file: ./Containerfile @@ -51,7 +52,7 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - name: Attest container provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/db-checks.yml b/.github/workflows/db-checks.yml index 990148c..5ffd95a 100644 --- a/.github/workflows/db-checks.yml +++ b/.github/workflows/db-checks.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -37,20 +38,20 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. This SHA currently tolerates its absence; # stating it explicitly keeps the step working across future re-pins. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: toolchain: stable - name: Cache cargo - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 - name: Install sqlite3 CLI run: sudo apt-get update && sudo apt-get install -y sqlite3 diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 8b8a7b5..66543da 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -52,7 +53,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + uses: dependabot/fetch-metadata@v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # --- Policy gate ------------------------------------------------------- diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 767e317..02dfa09 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Documentation (casket-ssg) @@ -26,21 +27,21 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b path: casket-ssg persist-credentials: false - name: Set up GHC - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -75,7 +76,7 @@ jobs: test -s ../docs/_site/index.html touch ../docs/_site/.nojekyll - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: docs/_site deploy: @@ -89,4 +90,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 7f45d87..5012352 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -27,7 +28,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for A2ML files id: detect @@ -68,7 +69,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for K9 files id: detect @@ -114,7 +115,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Scan for invisible characters id: lint @@ -179,7 +180,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for Groove manifest id: groove @@ -238,7 +239,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -304,7 +305,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 803a37a..47d03db 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # E2E + Point-to-Point + Unit tests for echidnabot. @@ -51,7 +52,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false @@ -63,7 +64,7 @@ jobs: cargo metadata --format-version 1 >/dev/null echo "✅ dependency graph resolves from a standalone checkout" - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2.9.2 - name: Unit + Point-to-Point + End-to-End run: | diff --git a/.github/workflows/echidna-fuzz.yml b/.github/workflows/echidna-fuzz.yml index 435a771..6b55d5d 100644 --- a/.github/workflows/echidna-fuzz.yml +++ b/.github/workflows/echidna-fuzz.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Echidna Smart Contract Fuzzing @@ -111,7 +112,7 @@ jobs: contracts: ${{ steps.detect.outputs.contracts }} contract_count: ${{ steps.detect.outputs.contract_count }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Detect contract files id: detect run: | @@ -152,9 +153,9 @@ jobs: matrix: contract: ${{ fromJson(needs.detect-contracts.outputs.contracts) }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Restore Echidna corpus cache - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: echidna-corpus key: echidna-corpus-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} @@ -286,13 +287,13 @@ jobs: fi - name: Save corpus cache if: always() - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache/save@v6.1.0 with: path: echidna-corpus key: echidna-corpus-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} - name: Upload Echidna results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidna-property-results-${{ matrix.contract }} path: echidna-results/ @@ -312,9 +313,9 @@ jobs: matrix: contract: ${{ fromJson(needs.detect-contracts.outputs.contracts) }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Restore Echidna corpus cache - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: echidna-corpus-assertion key: echidna-corpus-assertion-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} @@ -380,7 +381,7 @@ jobs: fi - name: Upload Echidna results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidna-assertion-results-${{ matrix.contract }} path: echidna-results/ diff --git a/.github/workflows/echidnabot.yml b/.github/workflows/echidnabot.yml index 4facfbd..d4c24c0 100644 --- a/.github/workflows/echidnabot.yml +++ b/.github/workflows/echidnabot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: echidnabot Proof Verification @@ -61,7 +62,7 @@ jobs: has_metamath: ${{ steps.detect.outputs.has_metamath }} any_proofs: ${{ steps.detect.outputs.any_proofs }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Detect proof file types @@ -92,7 +93,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Coq @@ -114,7 +115,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install elan (Lean version manager) @@ -141,7 +142,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Z3 @@ -163,7 +164,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Agda diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index c3f5302..08a6a9c 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Governance diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index da2e480..b967733 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Hypatia Security Scan diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index fc79947..da34fac 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index af34c6b..be2ff5c 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Labels diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 628ac11..55ff19a 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Mirror to Git Forges diff --git a/.github/workflows/openssf-compliance.yml b/.github/workflows/openssf-compliance.yml index f7d8f75..1d901fc 100644 --- a/.github/workflows/openssf-compliance.yml +++ b/.github/workflows/openssf-compliance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # OpenSSF Best Practices compliance gate — blocks PRs and pushes that lack @@ -18,7 +19,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Check SECURITY.md exists and has substance diff --git a/.github/workflows/proof-safety.yml b/.github/workflows/proof-safety.yml index 3ee83a5..544bd93 100644 --- a/.github/workflows/proof-safety.yml +++ b/.github/workflows/proof-safety.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Proof Safety @@ -16,10 +17,10 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 25 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2.9.2 - name: Test REST and GraphQL wire contracts run: | cargo test --locked --test protocol_contract diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 1fa5722..8ea3348 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 hyperpolymath @@ -32,15 +33,15 @@ jobs: attestations: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: toolchain: stable - name: Cache cargo - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 - name: Install dependencies run: | sudo apt-get update @@ -77,7 +78,7 @@ jobs: - name: Package crate run: cargo package - name: Attest crate provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-path: 'target/package/*.crate' - name: Publish to crates.io (dry run) @@ -90,7 +91,7 @@ jobs: run: cargo publish - name: Create GitHub Release if: startsWith(github.ref, 'refs/tags/') - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 + uses: softprops/action-gh-release@v3.0.3 with: generate_release_notes: true draft: false diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index dec3400..53487fa 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 hyperpolymath @@ -45,12 +46,12 @@ jobs: os: windows-latest binary: echidnabot.exe steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. Supplying `targets:` alone does not # satisfy it. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: @@ -89,7 +90,7 @@ jobs: Compress-Archive -Path ${{ matrix.binary }} -DestinationPath echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip Get-FileHash echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip -Algorithm SHA256 | ForEach-Object { "$($_.Hash.ToLower()) echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip" } | Out-File -FilePath echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip.sha256 - name: Upload artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidnabot-${{ matrix.target }} path: | @@ -102,13 +103,13 @@ jobs: contents: read needs: build-binaries steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install cargo-deb run: cargo install cargo-deb - name: Build .deb run: cargo deb - name: Upload .deb - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: deb-package path: target/debian/*.deb @@ -120,7 +121,7 @@ jobs: contents: read needs: build-binaries steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install cargo-generate-rpm run: cargo install cargo-generate-rpm - name: Build binary @@ -130,7 +131,7 @@ jobs: - name: Build .rpm run: cargo generate-rpm - name: Upload .rpm - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: rpm-package path: target/generate-rpm/*.rpm @@ -144,9 +145,9 @@ jobs: id-token: write attestations: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Download all artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: path: artifacts - name: Collect release assets @@ -155,13 +156,13 @@ jobs: find artifacts -type f \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.sha256" -o -name "*.deb" -o -name "*.rpm" \) -exec cp {} release/ \; ls -la release/ - name: Create Release - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 + uses: softprops/action-gh-release@v3.0.3 with: tag_name: ${{ env.RELEASE_TAG }} files: release/* generate_release_notes: true draft: false - name: Attest build provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-path: 'release/*' diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml index 255ddea..29dc13e 100644 --- a/.github/workflows/rhodibot.yml +++ b/.github/workflows/rhodibot.yml @@ -34,7 +34,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 1 - name: Rhodibot — detect drift (no mutations) diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 817b9ee..5fb7aca 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Rust CI — thin wrapper calling the shared estate reusable in diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1871ab9..f751176 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: OSSF Scorecard diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index aeec938..3f27a16 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards secret-scanner-reusable.yml. diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml index 44b708d..b6ffc3c 100644 --- a/.github/workflows/static-analysis-gate.yml +++ b/.github/workflows/static-analysis-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Static Analysis Gate — Required by branch protection rules. @@ -20,7 +21,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -117,7 +118,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload panic-attack findings - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: panic-attack-findings path: panic-attack-findings.json @@ -136,13 +137,13 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Setup Elixir for Hypatia scanner id: beam continue-on-error: true - uses: erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124 # v1.24.1 + uses: erlef/setup-beam@v1.24.1 with: elixir-version: '1.19.4' otp-version: '28.3' @@ -243,7 +244,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload hypatia findings - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: hypatia-findings path: hypatia-findings.json @@ -262,7 +263,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -324,7 +325,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload bridge report - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: bridge-report path: bridge-report.json @@ -346,17 +347,17 @@ jobs: if: always() steps: - name: Download panic-attack findings - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: panic-attack-findings path: findings/ - name: Download hypatia findings - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: hypatia-findings path: findings/ - name: Download bridge report - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: bridge-report path: findings/ @@ -416,7 +417,7 @@ jobs: echo "medium=$MEDIUM" >> "$GITHUB_OUTPUT" echo "low=$LOW" >> "$GITHUB_OUTPUT" - name: Upload unified findings (fleet scanner picks these up) - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: unified-findings path: findings/unified-findings.json diff --git a/.github/workflows/stress-test.yml b/.github/workflows/stress-test.yml index e5da6cf..58361ff 100644 --- a/.github/workflows/stress-test.yml +++ b/.github/workflows/stress-test.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Stress Testing @@ -11,13 +12,13 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 60 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA: it # normally infers the toolchain from the ref that called it (@stable -> # "stable"), and a SHA carries no such name. Without it the action fails # with `error: invalid toolchain name ''`. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 296eba4..80dab63 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config @@ -15,7 +16,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: | errors=0