Skip to content

Commit 89be7e8

Browse files
hyperpolymathclaude
andcommitted
fix(ci): unbreak workflow YAML and add a complete actions.lock
Remediates GitHub Workflow Dependency Locking (public preview), which rejects runs at startup_failure with zero jobs and no logs. See hyperpolymath/standards#657. Five steps, in order, because each blocks the next: 1. Unbroke any workflow whose `permissions:` carried a scalar with an indented mapping under it - blind-permissions-insertion damage. This matters beyond the one file: gh actions-lock refuses to run when ANY workflow in the repo fails to parse, so the repo could never acquire a lockfile and could never self-heal. 2. Repinned hyperpolymath/standards reusables off commits that have no actions.lock. The rejection requires the CALLEE to be covered at the pinned SHA, which is unsatisfiable at a pre-lockfile commit. 3. Generated the lockfile with gh actions-lock. 4. Hand-added the reusable-workflow caller entries the tool omits, as '<path>': []. Measured across 218 repos: P(startup_failure | has lockfile) = 91.7% vs 15.8% without, because every workflow a lockfile OMITS is rejected. A PARTIAL lock is worse than none - running gh actions-lock and stopping there is how this outage spread. 5. Restored SPDX-License-Identifier to line 1, which the tool displaces with its own banner and which the workflow-security linter greps with head -1. Verified before push: 0 unparseable workflows, lockfile covers every workflow with no omissions, SPDX on line 1 in every file. Proven on hyperpolymath/anamnesis: 6 of 6 workflows dead -> 0 startup_failure, 13 running. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 7256a3a commit 89be7e8

17 files changed

Lines changed: 64 additions & 34 deletions

‎.github/workflows/abi-ffi-gate.yml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
# abi-ffi-gate.yml — enforce that the Zig FFI conforms to the Idris2 ABI.
34
#
45
# The Idris2 ABI (src/interface/abi) is the source of truth. This gate fails if
@@ -20,15 +21,15 @@ jobs:
2021
name: ABI ↔ FFI structural conformance
2122
runs-on: ubuntu-latest
2223
steps:
23-
- uses: actions/checkout@v7
24+
- uses: actions/checkout@v7.0.1
2425
- name: Run ABI-FFI gate
2526
run: python3 scripts/abi-ffi-gate.py
2627

2728
zig-build:
2829
name: Zig FFI builds + tests (Zig 0.14.0)
2930
runs-on: ubuntu-latest
3031
steps:
31-
- uses: actions/checkout@v7
32+
- uses: actions/checkout@v7.0.1
3233
- name: Install Zig 0.14.0
3334
run: |
3435
curl -fsSL https://ziglang.org/download/0.14.0/zig-linux-x86_64-0.14.0.tar.xz -o /tmp/zig.tar.xz

‎.github/workflows/actions.lock‎

Lines changed: 17 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,14 @@
33
# Docs: https://gh.io/actions-lockfile
44
version: 'v0.0.2'
55
workflows:
6+
'.github/workflows/governance.yml': []
7+
'.github/workflows/hypatia-scan.yml': []
8+
'.github/workflows/mirror.yml': []
9+
'.github/workflows/rust-ci.yml': []
10+
'.github/workflows/scorecard.yml': []
11+
'.github/workflows/secret-scanner.yml': []
12+
'.github/workflows/abi-ffi-gate.yml':
13+
- 'actions/checkout@v7.0.1'
614
'.github/workflows/boj-build.yml':
715
- 'actions/checkout@v7.0.1'
816
'.github/workflows/casket-pages.yml':
@@ -11,10 +19,10 @@ workflows:
1119
- 'actions/configure-pages@v6.0.0'
1220
- 'actions/deploy-pages@v5.0.0'
1321
- 'actions/upload-pages-artifact@v5.0.0'
14-
- 'haskell-actions/setup@v2.11.0'
22+
- 'haskell-actions/setup@v2.12.0'
1523
'.github/workflows/codeql.yml':
1624
- 'actions/checkout@v7.0.1'
17-
- 'github/codeql-action@v4.37.3'
25+
- 'github/codeql-action@v4.37.7'
1826
'.github/workflows/dogfood-gate.yml':
1927
- 'actions/checkout@v7.0.1'
2028
'.github/workflows/instant-sync.yml':
@@ -77,22 +85,22 @@ dependencies:
7785
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
7886
'dawidd6/action-send-mail@v3.12.0':
7987
ref: 'v3.12.0'
80-
commit: 'sha1-12335b969ae3fb71bee5f2c6b829744261aec34c'
88+
commit: 'sha1-0bbdab096651ee93f37ec02383e088183d41ff0b'
8189
owner_id: 9713907
8290
repo_id: 222439721
8391
'erlef/setup-beam@v1.24.1':
8492
ref: 'v1.24.1'
8593
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
8694
owner_id: 47606891
8795
repo_id: 331103973
88-
'github/codeql-action@v4.37.3':
89-
ref: 'v4.37.3'
90-
commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81'
96+
'github/codeql-action@v4.37.7':
97+
ref: 'v4.37.7'
98+
commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
9199
owner_id: 9919
92100
repo_id: 259445878
93-
'haskell-actions/setup@v2.11.0':
94-
ref: 'v2.11.0'
95-
commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553'
101+
'haskell-actions/setup@v2.12.0':
102+
ref: 'v2.12.0'
103+
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
96104
owner_id: 75048950
97105
repo_id: 623796603
98106
'peter-evans/repository-dispatch@v4.0.1':

‎.github/workflows/boj-build.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: BoJ Server Build Trigger
45
on:
56
push:
@@ -10,7 +11,7 @@ jobs:
1011
runs-on: ubuntu-latest
1112
steps:
1213
- name: Checkout
13-
uses: actions/checkout@v7
14+
uses: actions/checkout@v7.0.1
1415
- name: Trigger BoJ Server (Casket/ssg-mcp)
1516
run: |
1617
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/casket-pages.yml‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: GitHub Pages
45

56
on:
@@ -21,10 +22,10 @@ jobs:
2122
runs-on: ubuntu-latest
2223
steps:
2324
- name: Checkout
24-
uses: actions/checkout@v7
25+
uses: actions/checkout@v7.0.1
2526

2627
- name: Checkout casket-ssg
27-
uses: actions/checkout@v7
28+
uses: actions/checkout@v7.0.1
2829
with:
2930
repository: hyperpolymath/casket-ssg
3031
path: .casket-ssg

‎.github/workflows/codeql.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: CodeQL Security Analysis
45

56
on:
@@ -36,7 +37,7 @@ jobs:
3637

3738
steps:
3839
- name: Checkout
39-
uses: actions/checkout@v7
40+
uses: actions/checkout@v7.0.1
4041

4142
- name: Initialize CodeQL
4243
uses: github/codeql-action/init@v4.37.7

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
45
#
56
# dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate
@@ -26,7 +27,7 @@ jobs:
2627

2728
steps:
2829
- name: Checkout repository
29-
uses: actions/checkout@v7
30+
uses: actions/checkout@v7.0.1
3031

3132
- name: Check for A2ML files
3233
id: detect
@@ -66,7 +67,7 @@ jobs:
6667

6768
steps:
6869
- name: Checkout repository
69-
uses: actions/checkout@v7
70+
uses: actions/checkout@v7.0.1
7071

7172
- name: Check for K9 files
7273
id: detect
@@ -111,7 +112,7 @@ jobs:
111112

112113
steps:
113114
- name: Checkout repository
114-
uses: actions/checkout@v7
115+
uses: actions/checkout@v7.0.1
115116

116117
- name: Scan for invisible characters
117118
id: lint
@@ -175,7 +176,7 @@ jobs:
175176

176177
steps:
177178
- name: Checkout repository
178-
uses: actions/checkout@v7
179+
uses: actions/checkout@v7.0.1
179180

180181
- name: Check for Groove manifest
181182
id: groove
@@ -233,7 +234,7 @@ jobs:
233234

234235
steps:
235236
- name: Checkout repository
236-
uses: actions/checkout@v7
237+
uses: actions/checkout@v7.0.1
237238

238239
- name: Check and validate eclexiaiser manifest
239240
id: eclex
@@ -298,7 +299,7 @@ jobs:
298299

299300
steps:
300301
- name: Checkout repository
301-
uses: actions/checkout@v7
302+
uses: actions/checkout@v7.0.1
302303

303304
- name: Generate dogfooding scorecard
304305
run: |

‎.github/workflows/governance.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: Governance
45

56
on:
@@ -10,8 +11,9 @@ on:
1011
workflow_dispatch:
1112

1213
permissions:
14+
actions: read
1315
contents: read
1416

1517
jobs:
1618
governance:
17-
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@d7c22711e830e1f383846472f6e9b99debdb201e
19+
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: Hypatia Security Scan
45

56
on:
@@ -12,9 +13,10 @@ on:
1213
workflow_dispatch:
1314

1415
permissions:
16+
actions: read
1517
contents: read
1618
security-events: write
1719

1820
jobs:
1921
scan:
20-
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@d7c22711e830e1f383846472f6e9b99debdb201e
22+
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a

‎.github/workflows/instant-sync.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
# Instant Forge Sync - Triggers propagation to all forges on push/release
45
name: Instant Sync
56

‎.github/workflows/mirror.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: Mirror to Git Forges
45

56
on:
@@ -8,9 +9,10 @@ on:
89
workflow_dispatch:
910

1011
permissions:
12+
actions: read
1113
contents: read
1214

1315
jobs:
1416
mirror:
15-
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236
17+
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
1618
secrets: inherit

0 commit comments

Comments
 (0)