Skip to content

build-gossamer-gui.yml has a duplicate 'with:' key, reddening the workflow security linter on every PR #822

Description

@hyperpolymath

Symptom

governance / Workflow security linter fails on every PR with:

##[error]duplicate key(s): 'with' (line 143)

Cause

.github/workflows/build-gossamer-gui.yml has a single step carrying two with: blocks:

      - name: Setup Rust (stable) with wasm32 target
        uses: dtolnay/rust-toolchain@v1
        with:
          toolchain: master
        with:
          toolchain: stable
          targets: wasm32-unknown-unknown

Introduced by #810 (chore(deps): bump the actions group with 7 updates, 2026-09-22). Dependabot rewrote the action ref from a branch to @v1 and added a with: block instead of editing the existing one, leaving the original toolchain: master in place.

Why it matters beyond the red check

This is a duplicate YAML mapping key, so the outcome is parser-dependent: most YAML loaders take the last occurrence (giving toolchain: stable + targets: wasm32-unknown-unknown, which is what was intended), but the value is not well-defined by the spec and a stricter loader may reject the document outright. A workflow whose inputs depend on which parser reads it is not a workflow anyone can reason about — and if a parser ever takes the first key, the job silently builds with toolchain: master and no wasm32 target.

Acceptance criteria

  • .github/workflows/build-gossamer-gui.yml has exactly one with: per step; the surviving block is toolchain: stable + targets: wasm32-unknown-unknown.
  • Confirm the intended action ref: dtolnay/rust-toolchain is conventionally used at @master (it has no version tags in the usual sense). Whatever is chosen, pin it to a commit SHA with the version in a trailing comment, per estate policy.
  • governance / Workflow security linter reports success on a PR carrying the fix.
  • Mutant: re-add a second with: block to any step and confirm the linter goes red again — a gate that passes after a fix proves nothing until it is shown it can still fail.
  • Sweep the other six workflows Dependabot touched in chore(deps): bump the actions group with 7 updates #810 for the same double-with: shape, since the cause is mechanical and would repeat.

Scope note

Found while verifying PR #821 (#815, the src/abi duplicate deletion). It is not caused by that PR — build-gossamer-gui.yml is byte-identical between #821 and main, and #821's only workflow change is a single comment line inside a run: block in tests.yml, which cannot create a duplicate YAML key. Filed separately rather than folded in, per the standing rule that a new finding is an issue, not a merge blocker.

🤖 Generated with Claude Code

https://claude.ai/code/session_0113HQM9LVGkNCzU1WwkJZSV

Activity

  1. added
    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates
    enhancementNew capability or improvement to existing behaviour
    on Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesenhancementNew capability or improvement to existing behaviour

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions