diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 0000000..6cb9a05 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,119 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/boj-build.yml': + - 'actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332' + '.github/workflows/casket-pages.yml': + - 'actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830' + - 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' + - 'actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b' + - 'actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + - 'actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa' + - 'haskell-actions/setup@ec49483bfc012387b227434aba94f59a6ecd0900' + '.github/workflows/codeql.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' + - 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + - 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697' + '.github/workflows/push-email-notify.yml': + - 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + '.github/workflows/secret-scanner.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7' + - 'trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d' + '.github/workflows/workflow-linter.yml': + - 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' +dependencies: + 'actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830': + ref: 'v4.3.0' + commit: 'sha1-0057852bfaa89a56745cba8c7296529d2fc39830' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5': + ref: 'v4.3.1' + commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332': + ref: 'v4.1.7' + commit: 'sha1-692973e3d937129bcbf40652eb9f2f61becf3332' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11': + ref: 'v4.1.1' + commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@983d7736d9b0ae728b81ab479565c72886d7745b': + ref: 'v5.0.0' + commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b' + owner_id: 44036562 + repo_id: 513659658 + 'actions/deploy-pages@d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e': + ref: 'v4.0.5' + commit: 'sha1-d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e' + owner_id: 44036562 + repo_id: 438112499 + 'actions/upload-artifact@v4': + ref: 'v4' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@56afc609e74202658d3ffba0e8f6dda462b719fa': + ref: 'v3.0.1' + commit: 'sha1-56afc609e74202658d3ffba0e8f6dda462b719fa' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@v4' + 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745': + ref: 'v4.34.0' + commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + owner_id: 9919 + repo_id: 259445878 + 'gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7': + ref: 'v2.3.9' + commit: 'sha1-ff98106e4c7b2bc287b24eaf42907196329070c7' + owner_id: 90395851 + repo_id: 242854909 + 'haskell-actions/setup@ec49483bfc012387b227434aba94f59a6ecd0900': + ref: 'v2.7.5' + commit: 'sha1-ec49483bfc012387b227434aba94f59a6ecd0900' + owner_id: 75048950 + repo_id: 623796603 + 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79': + ref: 'main' + commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562': + ref: 'main' + commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562' + owner_id: 6759885 + repo_id: 1275650185 + 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7': + ref: 'v0.2.0' + commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + owner_id: 6759885 + repo_id: 1352485172 + 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' + owner_id: 18365890 + repo_id: 220359305 + 'trufflesecurity/trufflehog@6c05c4a00b91aa542267d8e32a8254774799d68d': + ref: 'v3.93.8' + commit: 'sha1-6c05c4a00b91aa542267d8e32a8254774799d68d' + owner_id: 79229934 + repo_id: 77726177 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 786b8fb..f394886 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger on: push: diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index b625074..e2463d1 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages on: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 7282f84..e7ed0a9 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 07b3242..d27a558 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index d6ee198..80e2fc4 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # governance.yml — single wrapper calling the shared estate governance bundle # in hyperpolymath/standards instead of carrying per-repo copies. # diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index d8e00ae..97e8676 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. # See standards#191 for the reusable's purpose and design. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index e612d96..c4fd4c3 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..fc79947 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Label Triage # Classify newly-filed issues against the estate label taxonomy. diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..af34c6b 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Labels # Applies the canonical estate label set from .github/labels.json. diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 5b4b2c7..45c91fa 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 0689291..80c6942 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 1426c5c..2e266df 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Scorecards supply-chain security on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 599c64a..e6832ee 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Prevention workflow - scans for hardcoded secrets before they reach main name: Secret Scanner diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 3bed9c5..758a716 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter