Skip to content

Commit 3814e14

Browse files
committed
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6)
`actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them.
1 parent 3e810d3 commit 3814e14

19 files changed

Lines changed: 60 additions & 43 deletions

‎.github/workflows/abi-ffi-gate.yml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# abi-ffi-gate.yml — enforce that the Zig FFI conforms to the Idris2 ABI.
@@ -21,7 +22,7 @@ jobs:
2122
name: ABI ↔ FFI structural conformance
2223
runs-on: ubuntu-latest
2324
steps:
24-
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
- uses: actions/checkout@v7.0.1
2526
- name: Install Julia 1.11.5
2627
run: |
2728
curl --proto "=https" --proto-redir "=https" --tlsv1.2 -fsSL https://julialang-s3.julialang.org/bin/linux/x64/1.11/julia-1.11.5-linux-x86_64.tar.gz -o /tmp/julia.tar.gz
@@ -39,7 +40,7 @@ jobs:
3940
name: Zig FFI builds + tests (Zig 0.14.0)
4041
runs-on: ubuntu-latest
4142
steps:
42-
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
43+
- uses: actions/checkout@v7.0.1
4344
- name: Install Zig 0.14.0
4445
run: |
4546
curl --proto "=https" --proto-redir "=https" --tlsv1.2 -fsSL https://ziglang.org/download/0.14.0/zig-linux-x86_64-0.14.0.tar.xz -o /tmp/zig.tar.xz

‎.github/workflows/actions.lock‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ workflows:
1616
- 'haskell-actions/setup@v2.12.0'
1717
'.github/workflows/codeql.yml':
1818
- 'actions/checkout@v7.0.1'
19-
- 'github/codeql-action@v4.37.9'
19+
- 'github/codeql-action@v4.38.0'
2020
'.github/workflows/dogfood-gate.yml':
2121
- 'actions/checkout@v7.0.1'
2222
'.github/workflows/governance.yml': []
@@ -27,7 +27,7 @@ workflows:
2727
'.github/workflows/labels.yml': []
2828
'.github/workflows/mirror.yml': []
2929
'.github/workflows/push-email-notify.yml':
30-
- 'hyperpolymath/smtp-notify-action@v0.2.0'
30+
- 'hyperpolymath/smtp-notify-action@v0.3.0'
3131
'.github/workflows/release.yml':
3232
- 'actions/checkout@v7.0.1'
3333
- 'actions/upload-artifact@v7.0.1'
@@ -90,19 +90,19 @@ dependencies:
9090
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
9191
owner_id: 47606891
9292
repo_id: 331103973
93-
'github/codeql-action@v4.37.9':
94-
ref: 'v4.37.9'
95-
commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938'
93+
'github/codeql-action@v4.38.0':
94+
ref: 'v4.38.0'
95+
commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63'
9696
owner_id: 9919
9797
repo_id: 259445878
9898
'haskell-actions/setup@v2.12.0':
9999
ref: 'v2.12.0'
100100
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
101101
owner_id: 75048950
102102
repo_id: 623796603
103-
'hyperpolymath/smtp-notify-action@v0.2.0':
104-
ref: 'v0.2.0'
105-
commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7'
103+
'hyperpolymath/smtp-notify-action@v0.3.0':
104+
ref: 'v0.3.0'
105+
commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be'
106106
owner_id: 6759885
107107
repo_id: 1352485172
108108
'peter-evans/repository-dispatch@v4.0.1':

‎.github/workflows/boj-build.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -11,7 +12,7 @@ jobs:
1112
runs-on: ubuntu-latest
1213
steps:
1314
- name: Checkout
14-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
15+
uses: actions/checkout@v7.0.1
1516
- name: Trigger BoJ Server (Casket/ssg-mcp)
1617
run: |
1718
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/casket-pages.yml‎

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -22,22 +23,22 @@ jobs:
2223
runs-on: ubuntu-latest
2324
steps:
2425
- name: Checkout
25-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
26+
uses: actions/checkout@v7.0.1
2627

2728
- name: Checkout casket-ssg
28-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
29+
uses: actions/checkout@v7.0.1
2930
with:
3031
repository: hyperpolymath/casket-ssg
3132
path: .casket-ssg
3233

3334
- name: Setup GHCup
34-
uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0
35+
uses: haskell-actions/setup@v2.12.0
3536
with:
3637
ghc-version: '9.8.2'
3738
cabal-version: '3.10'
3839

3940
- name: Cache Cabal
40-
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
41+
uses: actions/cache@v6.1.0
4142
with:
4243
path: |
4344
~/.cabal/packages
@@ -99,10 +100,10 @@ jobs:
99100
touch ../_site/.nojekyll
100101
101102
- name: Setup Pages
102-
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
103+
uses: actions/configure-pages@v6.0.0
103104

104105
- name: Upload artifact
105-
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
106+
uses: actions/upload-pages-artifact@v5.0.0
106107
with:
107108
path: '_site'
108109

@@ -115,4 +116,4 @@ jobs:
115116
steps:
116117
- name: Deploy to GitHub Pages
117118
id: deployment
118-
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
119+
uses: actions/deploy-pages@v5.0.1

‎.github/workflows/codeql.yml‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -37,15 +38,15 @@ jobs:
3738

3839
steps:
3940
- name: Checkout
40-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
41+
uses: actions/checkout@v7.0.1
4142

4243
- name: Initialize CodeQL
43-
uses: github/codeql-action/init@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
44+
uses: github/codeql-action/init@v4.38.0
4445
with:
4546
languages: ${{ matrix.language }}
4647
build-mode: ${{ matrix.build-mode }}
4748

4849
- name: Perform CodeQL Analysis
49-
uses: github/codeql-action/analyze@b96794f015dfd88f77b49b1c93e0fa7110f94c63 # v4.38.0
50+
uses: github/codeql-action/analyze@v4.38.0
5051
with:
5152
category: "/language:${{ matrix.language }}"

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# This workflow is managed by gh actions-lock.
@@ -27,7 +28,7 @@ jobs:
2728

2829
steps:
2930
- name: Checkout repository
30-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
31+
uses: actions/checkout@v7.0.1
3132

3233
- name: Check for A2ML files
3334
id: detect
@@ -67,7 +68,7 @@ jobs:
6768

6869
steps:
6970
- name: Checkout repository
70-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
71+
uses: actions/checkout@v7.0.1
7172

7273
- name: Check for K9 files
7374
id: detect
@@ -112,7 +113,7 @@ jobs:
112113

113114
steps:
114115
- name: Checkout repository
115-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
116+
uses: actions/checkout@v7.0.1
116117

117118
- name: Scan for invisible characters
118119
id: lint
@@ -176,7 +177,7 @@ jobs:
176177

177178
steps:
178179
- name: Checkout repository
179-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
180+
uses: actions/checkout@v7.0.1
180181

181182
- name: Check for Groove manifest
182183
id: groove
@@ -234,7 +235,7 @@ jobs:
234235

235236
steps:
236237
- name: Checkout repository
237-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
238+
uses: actions/checkout@v7.0.1
238239

239240
- name: Check and validate eclexiaiser manifest
240241
id: eclex
@@ -299,7 +300,7 @@ jobs:
299300

300301
steps:
301302
- name: Checkout repository
302-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
303+
uses: actions/checkout@v7.0.1
303304

304305
- name: Generate dogfooding scorecard
305306
run: |

‎.github/workflows/governance.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: Governance

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: Hypatia Security Scan

‎.github/workflows/instant-sync.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# Instant Forge Sync - Triggers propagation to all forges on push/release
@@ -22,7 +23,7 @@ jobs:
2223
- name: Trigger Propagation
2324
id: propagate
2425
if: env.FARM_DISPATCH_TOKEN != ''
25-
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1
26+
uses: peter-evans/repository-dispatch@v4.0.1
2627
with:
2728
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
2829
repository: hyperpolymath/.git-private-farm

‎.github/workflows/label-triage.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Label Triage
34

0 commit comments

Comments
 (0)