From 0422047c5e0f9553dc20168f2ed20f773dba6cb1 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sun, 20 Sep 2026 02:02:00 +0000 Subject: [PATCH] fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them. --- .github/workflows/actions.lock | 32 +++++++++++----------- .github/workflows/boj-build.yml | 3 +- .github/workflows/cargo-audit.yml | 5 ++-- .github/workflows/casket-pages.yml | 15 +++++----- .github/workflows/cflite_batch.yml | 5 ++-- .github/workflows/cflite_pr.yml | 5 ++-- .github/workflows/codeql.yml | 1 + .github/workflows/container.yml | 13 +++++---- .github/workflows/db-checks.yml | 7 +++-- .github/workflows/dependabot-automerge.yml | 3 +- .github/workflows/docs.yml | 13 +++++---- .github/workflows/dogfood-gate.yml | 13 +++++---- .github/workflows/e2e.yml | 5 ++-- .github/workflows/echidna-fuzz.yml | 17 ++++++------ .github/workflows/echidnabot.yml | 11 ++++---- .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/mirror.yml | 1 + .github/workflows/openssf-compliance.yml | 3 +- .github/workflows/proof-safety.yml | 5 ++-- .github/workflows/publish.yml | 11 ++++---- .github/workflows/release.yml | 23 ++++++++-------- .github/workflows/rhodibot.yml | 2 +- .github/workflows/rust-ci.yml | 1 + .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + .github/workflows/static-analysis-gate.yml | 23 ++++++++-------- .github/workflows/stress-test.yml | 5 ++-- .github/workflows/workflow-linter.yml | 3 +- 31 files changed, 130 insertions(+), 101 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 36c488a..3570b51 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -7,7 +7,7 @@ workflows: - 'actions/checkout@v7.0.1' '.github/workflows/cargo-audit.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' '.github/workflows/casket-pages.yml': - 'actions/cache@v6.1.0' - 'actions/checkout@v7.0.1' @@ -22,13 +22,13 @@ workflows: '.github/workflows/container.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - - 'docker/build-push-action@v7.3.0' + - 'docker/build-push-action@v7.4.0' - 'docker/login-action@v4.6.0' - 'docker/metadata-action@v6.2.0' - - 'docker/setup-buildx-action@v4.3.0' + - 'docker/setup-buildx-action@v4.4.0' '.github/workflows/db-checks.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'swatinem/rust-cache@v2.9.2' '.github/workflows/dependabot-automerge.yml': - 'dependabot/fetch-metadata@v3.1.0' @@ -57,7 +57,7 @@ workflows: '.github/workflows/publish.yml': - 'actions/attest-build-provenance@v4.2.2' - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'softprops/action-gh-release@v3.0.3' - 'swatinem/rust-cache@v2.9.2' '.github/workflows/release.yml': @@ -65,7 +65,7 @@ workflows: - 'actions/checkout@v7.0.1' - 'actions/download-artifact@v8.0.1' - 'actions/upload-artifact@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' - 'softprops/action-gh-release@v3.0.3' '.github/workflows/rhodibot.yml': - 'actions/checkout@v7.0.1' @@ -76,7 +76,7 @@ workflows: - 'erlef/setup-beam@v1.24.1' '.github/workflows/stress-test.yml': - 'actions/checkout@v7.0.1' - - 'dtolnay/rust-toolchain@master' + - 'dtolnay/rust-toolchain@v1' '.github/workflows/workflow-linter.yml': - 'actions/checkout@v7.0.1' dependencies: @@ -139,9 +139,9 @@ dependencies: commit: 'sha1-25dd0e34f4fe68f24cc83900b1fe3fe149efef98' owner_id: 27347476 repo_id: 371068214 - 'docker/build-push-action@v7.3.0': - ref: 'v7.3.0' - commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a' + 'docker/build-push-action@v7.4.0': + ref: 'v7.4.0' + commit: 'sha1-c3c9e263c25d99ce0380d002d59b67737d91b0dc' owner_id: 5429470 repo_id: 241092383 'docker/login-action@v4.6.0': @@ -154,14 +154,14 @@ dependencies: commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302' owner_id: 5429470 repo_id: 306769011 - 'docker/setup-buildx-action@v4.3.0': - ref: 'v4.3.0' - commit: 'sha1-37fe631027851001ddb9b187196cc803df7f5f0e' + 'docker/setup-buildx-action@v4.4.0': + ref: 'v4.4.0' + commit: 'sha1-594f3bf4285d9ea8dc53c9a0c9c4092420091003' owner_id: 5429470 repo_id: 288485773 - 'dtolnay/rust-toolchain@master': - ref: 'master' - commit: 'sha1-b3b07ba8b418998c39fb20f53e8b695cdcc8de1b' + 'dtolnay/rust-toolchain@v1': + ref: 'v1' + commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 'erlef/setup-beam@v1.24.1': diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 44411f4..3ad4d57 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -24,7 +25,7 @@ jobs: if: ${{ vars.BOJ_SERVER_URL != '' }} steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Trigger BoJ Server (Casket/ssg-mcp) env: BOJ_URL: ${{ secrets.BOJ_SERVER_URL || vars.BOJ_SERVER_URL }} diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index a394f17..7b488ac 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -22,12 +23,12 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. This SHA currently tolerates its absence; # stating it explicitly keeps the step working across future re-pins. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 43a937a..9d732b2 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: GitHub Pages @@ -18,21 +19,21 @@ jobs: timeout-minutes: 30 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b path: .casket-ssg persist-credentials: false - name: Setup GHCup - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -75,9 +76,9 @@ jobs: fi cd .casket-ssg && cabal run --index-state=2026-09-06T00:00:00Z casket-ssg -- build ../site ../_site - name: Setup Pages - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + uses: actions/configure-pages@v6.0.0 - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -90,4 +91,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index a445a24..0de84c4 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite batch fuzzing @@ -17,13 +18,13 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 1800 diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index b8ce644..da98a50 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: ClusterFuzzLite PR fuzzing @@ -24,13 +25,13 @@ jobs: steps: - name: Build Fuzzers (${{ matrix.sanitizer }}) id: build - uses: google/clusterfuzzlite/actions/build_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/build_fuzzers@v1 with: language: rust sanitizer: ${{ matrix.sanitizer }} - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run - uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 + uses: google/clusterfuzzlite/actions/run_fuzzers@v1 with: github-token: ${{ secrets.GITHUB_TOKEN }} fuzz-seconds: 300 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 489854f..1fdfc72 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards codeql-reusable.yml. diff --git a/.github/workflows/container.yml b/.github/workflows/container.yml index 85d6efb..fc5b4c0 100644 --- a/.github/workflows/container.yml +++ b/.github/workflows/container.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Container Build @@ -21,18 +22,18 @@ jobs: attestations: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@594f3bf4285d9ea8dc53c9a0c9c4092420091003 # v4.4.0 + uses: docker/setup-buildx-action@v4.4.0 - name: Log in to GitHub Container Registry - uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + uses: docker/login-action@v4.6.0 with: registry: ${{ env.REGISTRY }} username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - name: Extract metadata id: meta - uses: docker/metadata-action@dc802804100637a589fabce1cb79ff13a1411302 # v6.2.0 + uses: docker/metadata-action@v6.2.0 with: images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} tags: | @@ -41,7 +42,7 @@ jobs: type=sha - name: Build and push id: push - uses: docker/build-push-action@c3c9e263c25d99ce0380d002d59b67737d91b0dc # v7.4.0 + uses: docker/build-push-action@v7.4.0 with: context: . file: ./Containerfile @@ -51,7 +52,7 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - name: Attest container provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-name: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }} subject-digest: ${{ steps.push.outputs.digest }} diff --git a/.github/workflows/db-checks.yml b/.github/workflows/db-checks.yml index 990148c..5ffd95a 100644 --- a/.github/workflows/db-checks.yml +++ b/.github/workflows/db-checks.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -37,20 +38,20 @@ jobs: steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. This SHA currently tolerates its absence; # stating it explicitly keeps the step working across future re-pins. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: toolchain: stable - name: Cache cargo - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 - name: Install sqlite3 CLI run: sudo apt-get update && sudo apt-get install -y sqlite3 diff --git a/.github/workflows/dependabot-automerge.yml b/.github/workflows/dependabot-automerge.yml index 8b8a7b5..66543da 100644 --- a/.github/workflows/dependabot-automerge.yml +++ b/.github/workflows/dependabot-automerge.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # @@ -52,7 +53,7 @@ jobs: steps: - name: Fetch Dependabot metadata id: meta - uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3.1.0 + uses: dependabot/fetch-metadata@v3.1.0 with: github-token: ${{ secrets.GITHUB_TOKEN }} # --- Policy gate ------------------------------------------------------- diff --git a/.github/workflows/docs.yml b/.github/workflows/docs.yml index 767e317..02dfa09 100644 --- a/.github/workflows/docs.yml +++ b/.github/workflows/docs.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Documentation (casket-ssg) @@ -26,21 +27,21 @@ jobs: timeout-minutes: 30 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg ref: cec3c20d80ea1dc93660b69a4e7b38aa49f2a56b path: casket-ssg persist-credentials: false - name: Set up GHC - uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0 + uses: haskell-actions/setup@v2.12.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -75,7 +76,7 @@ jobs: test -s ../docs/_site/index.html touch ../docs/_site/.nojekyll - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: docs/_site deploy: @@ -89,4 +90,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1 + uses: actions/deploy-pages@v5.0.1 diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 7f45d87..5012352 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) @@ -27,7 +28,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for A2ML files id: detect @@ -68,7 +69,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for K9 files id: detect @@ -114,7 +115,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Scan for invisible characters id: lint @@ -179,7 +180,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check for Groove manifest id: groove @@ -238,7 +239,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Check and validate eclexiaiser manifest id: eclex @@ -304,7 +305,7 @@ jobs: steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Generate dogfooding scorecard run: | diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 803a37a..47d03db 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # E2E + Point-to-Point + Unit tests for echidnabot. @@ -51,7 +52,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false @@ -63,7 +64,7 @@ jobs: cargo metadata --format-version 1 >/dev/null echo "✅ dependency graph resolves from a standalone checkout" - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2.9.2 - name: Unit + Point-to-Point + End-to-End run: | diff --git a/.github/workflows/echidna-fuzz.yml b/.github/workflows/echidna-fuzz.yml index 435a771..6b55d5d 100644 --- a/.github/workflows/echidna-fuzz.yml +++ b/.github/workflows/echidna-fuzz.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Echidna Smart Contract Fuzzing @@ -111,7 +112,7 @@ jobs: contracts: ${{ steps.detect.outputs.contracts }} contract_count: ${{ steps.detect.outputs.contract_count }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Detect contract files id: detect run: | @@ -152,9 +153,9 @@ jobs: matrix: contract: ${{ fromJson(needs.detect-contracts.outputs.contracts) }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Restore Echidna corpus cache - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: echidna-corpus key: echidna-corpus-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} @@ -286,13 +287,13 @@ jobs: fi - name: Save corpus cache if: always() - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache/save@v6.1.0 with: path: echidna-corpus key: echidna-corpus-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} - name: Upload Echidna results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidna-property-results-${{ matrix.contract }} path: echidna-results/ @@ -312,9 +313,9 @@ jobs: matrix: contract: ${{ fromJson(needs.detect-contracts.outputs.contracts) }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Restore Echidna corpus cache - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 + uses: actions/cache@v6.1.0 with: path: echidna-corpus-assertion key: echidna-corpus-assertion-${{ matrix.contract }}-${{ hashFiles(format('contracts/{0}.sol', matrix.contract)) }} @@ -380,7 +381,7 @@ jobs: fi - name: Upload Echidna results if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidna-assertion-results-${{ matrix.contract }} path: echidna-results/ diff --git a/.github/workflows/echidnabot.yml b/.github/workflows/echidnabot.yml index 4facfbd..d4c24c0 100644 --- a/.github/workflows/echidnabot.yml +++ b/.github/workflows/echidnabot.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: echidnabot Proof Verification @@ -61,7 +62,7 @@ jobs: has_metamath: ${{ steps.detect.outputs.has_metamath }} any_proofs: ${{ steps.detect.outputs.any_proofs }} steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Detect proof file types @@ -92,7 +93,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Coq @@ -114,7 +115,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install elan (Lean version manager) @@ -141,7 +142,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Z3 @@ -163,7 +164,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Agda diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index c3f5302..08a6a9c 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Governance diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index da2e480..b967733 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Hypatia Security Scan diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index fc79947..da34fac 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Label Triage diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index af34c6b..be2ff5c 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Labels diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 628ac11..55ff19a 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Mirror to Git Forges diff --git a/.github/workflows/openssf-compliance.yml b/.github/workflows/openssf-compliance.yml index f7d8f75..1d901fc 100644 --- a/.github/workflows/openssf-compliance.yml +++ b/.github/workflows/openssf-compliance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # OpenSSF Best Practices compliance gate — blocks PRs and pushes that lack @@ -18,7 +19,7 @@ jobs: permissions: contents: read steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Check SECURITY.md exists and has substance diff --git a/.github/workflows/proof-safety.yml b/.github/workflows/proof-safety.yml index 3ee83a5..544bd93 100644 --- a/.github/workflows/proof-safety.yml +++ b/.github/workflows/proof-safety.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Proof Safety @@ -16,10 +17,10 @@ jobs: runs-on: ubuntu-24.04 timeout-minutes: 25 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 with: persist-credentials: false - - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + - uses: Swatinem/rust-cache@v2.9.2 - name: Test REST and GraphQL wire contracts run: | cargo test --locked --test protocol_contract diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 1fa5722..8ea3348 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 hyperpolymath @@ -32,15 +33,15 @@ jobs: attestations: write steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: toolchain: stable - name: Cache cargo - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 + uses: Swatinem/rust-cache@v2.9.2 - name: Install dependencies run: | sudo apt-get update @@ -77,7 +78,7 @@ jobs: - name: Package crate run: cargo package - name: Attest crate provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-path: 'target/package/*.crate' - name: Publish to crates.io (dry run) @@ -90,7 +91,7 @@ jobs: run: cargo publish - name: Create GitHub Release if: startsWith(github.ref, 'refs/tags/') - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 + uses: softprops/action-gh-release@v3.0.3 with: generate_release_notes: true draft: false diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index dec3400..53487fa 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 hyperpolymath @@ -45,12 +46,12 @@ jobs: os: windows-latest binary: echidnabot.exe steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA — see # the note in stress-test.yml. Supplying `targets:` alone does not # satisfy it. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: @@ -89,7 +90,7 @@ jobs: Compress-Archive -Path ${{ matrix.binary }} -DestinationPath echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip Get-FileHash echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip -Algorithm SHA256 | ForEach-Object { "$($_.Hash.ToLower()) echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip" } | Out-File -FilePath echidnabot-${{ env.RELEASE_TAG }}-${{ matrix.target }}.zip.sha256 - name: Upload artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: echidnabot-${{ matrix.target }} path: | @@ -102,13 +103,13 @@ jobs: contents: read needs: build-binaries steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install cargo-deb run: cargo install cargo-deb - name: Build .deb run: cargo deb - name: Upload .deb - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: deb-package path: target/debian/*.deb @@ -120,7 +121,7 @@ jobs: contents: read needs: build-binaries steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install cargo-generate-rpm run: cargo install cargo-generate-rpm - name: Build binary @@ -130,7 +131,7 @@ jobs: - name: Build .rpm run: cargo generate-rpm - name: Upload .rpm - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: rpm-package path: target/generate-rpm/*.rpm @@ -144,9 +145,9 @@ jobs: id-token: write attestations: write steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Download all artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: path: artifacts - name: Collect release assets @@ -155,13 +156,13 @@ jobs: find artifacts -type f \( -name "*.tar.gz" -o -name "*.zip" -o -name "*.sha256" -o -name "*.deb" -o -name "*.rpm" \) -exec cp {} release/ \; ls -la release/ - name: Create Release - uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3 + uses: softprops/action-gh-release@v3.0.3 with: tag_name: ${{ env.RELEASE_TAG }} files: release/* generate_release_notes: true draft: false - name: Attest build provenance - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 + uses: actions/attest-build-provenance@v4.2.2 with: subject-path: 'release/*' diff --git a/.github/workflows/rhodibot.yml b/.github/workflows/rhodibot.yml index 255ddea..29dc13e 100644 --- a/.github/workflows/rhodibot.yml +++ b/.github/workflows/rhodibot.yml @@ -34,7 +34,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 1 - name: Rhodibot — detect drift (no mutations) diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 817b9ee..5fb7aca 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Rust CI — thin wrapper calling the shared estate reusable in diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1871ab9..f751176 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: OSSF Scorecard diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index aeec938..3f27a16 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards secret-scanner-reusable.yml. diff --git a/.github/workflows/static-analysis-gate.yml b/.github/workflows/static-analysis-gate.yml index 44b708d..b6ffc3c 100644 --- a/.github/workflows/static-analysis-gate.yml +++ b/.github/workflows/static-analysis-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Static Analysis Gate — Required by branch protection rules. @@ -20,7 +21,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -117,7 +118,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload panic-attack findings - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: panic-attack-findings path: panic-attack-findings.json @@ -136,13 +137,13 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Setup Elixir for Hypatia scanner id: beam continue-on-error: true - uses: erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124 # v1.24.1 + uses: erlef/setup-beam@v1.24.1 with: elixir-version: '1.19.4' otp-version: '28.3' @@ -243,7 +244,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload hypatia findings - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: hypatia-findings path: hypatia-findings.json @@ -262,7 +263,7 @@ jobs: timeout-minutes: 15 steps: - name: Checkout repository - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Install panic-attack (if available) @@ -324,7 +325,7 @@ jobs: echo "" >> "$GITHUB_STEP_SUMMARY" echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY" - name: Upload bridge report - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: bridge-report path: bridge-report.json @@ -346,17 +347,17 @@ jobs: if: always() steps: - name: Download panic-attack findings - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: panic-attack-findings path: findings/ - name: Download hypatia findings - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: hypatia-findings path: findings/ - name: Download bridge report - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + uses: actions/download-artifact@v8.0.1 with: name: bridge-report path: findings/ @@ -416,7 +417,7 @@ jobs: echo "medium=$MEDIUM" >> "$GITHUB_OUTPUT" echo "low=$LOW" >> "$GITHUB_OUTPUT" - name: Upload unified findings (fleet scanner picks these up) - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: unified-findings path: findings/unified-findings.json diff --git a/.github/workflows/stress-test.yml b/.github/workflows/stress-test.yml index e5da6cf..58361ff 100644 --- a/.github/workflows/stress-test.yml +++ b/.github/workflows/stress-test.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. name: Stress Testing @@ -11,13 +12,13 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 60 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Install Rust toolchain # `toolchain:` is mandatory when this action is pinned to a SHA: it # normally infers the toolchain from the ref that called it (@stable -> # "stable"), and a SHA carries no such name. Without it the action fails # with `error: invalid toolchain name ''`. - uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master + uses: dtolnay/rust-toolchain@v1 with: toolchain: master with: diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 296eba4..80dab63 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config @@ -15,7 +16,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 15 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: | errors=0