Skip to content

fix(ci): repair broken actions/upload-artifact SHA pin - #18

Closed
hyperpolymath wants to merge 1 commit into
mainfrom
claude/fix-broken-upload-artifact-sha
Closed

hyperpolymath wants to merge 1 commit into
mainfrom
claude/fix-broken-upload-artifact-sha

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The pin actions/upload-artifact@65c79d7f... references a commit that does not exist on upstream actions/upload-artifact (verified via gh api — "No commit found for SHA"). Every workflow run using this pin fails immediately with:

Unable to resolve action `actions/upload-artifact@65c79d7f...`

Replacing with the current v4 head SHA ea165f8d65b6e75b540449e92b4886f43607fa02, retrieved from gh api repos/actions/upload-artifact/git/refs/tags/v4.

One repo's slice of a 10-repo estate-wide outage; companion PRs are landing in parallel.

Affects 1 workflow file in .github/workflows/.

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

The pin `actions/upload-artifact@65c79d7f...` references a commit
that does not exist on upstream `actions/upload-artifact` (verified
via gh api — "No commit found for SHA"). Every workflow run using
this pin fails immediately with:

    Unable to resolve action `actions/upload-artifact@65c79d7f...`

Replacing with the current v4 head SHA `ea165f8d65b6e75b540449e92b4886f43607fa02`, retrieved from
`gh api repos/actions/upload-artifact/git/refs/tags/v4`.

One repo's slice of a 10-repo estate-wide outage; companion PRs are
landing in parallel.

Affects 1 workflow file in .github/workflows/.
@hyperpolymath

Copy link
Copy Markdown
Owner Author

Closing (notification/PR-backlog triage): Superseded — main migrated hypatia-scan to the standards reusable workflow (42d7324), which already pins a correct/newer upload-artifact SHA. This inline fix is now redundant. Branch retained.

@hyperpolymath
hyperpolymath deleted the claude/fix-broken-upload-artifact-sha branch August 18, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant