From 153d3d25a56b211b9ac9188608b0003c7e0d0063 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 18:02:11 +0100 Subject: [PATCH 1/2] fix(ci): SHA-pin scan-and-report steps so sha_pinning callers can start it Callers with `sha_pinning_required: true` (e.g. hyperpolymath/echidna) refuse this reusable at startup because its steps used tag refs: The actions actions/checkout@v4.3.1, dtolnay/rust-toolchain@v1, and swatinem/rust-cache@v2.8.2 are not allowed in hyperpolymath/echidna ... A caller's own actions.lock does not cover a cross-repo callee's steps, so the callee must carry commit SHAs itself (same shape as the standards reusables, which start fine under the same policy). #201 had pinned them; #203's `gh actions-lock` rewrite turned them back into tags. - checkout 3d3c42e5 (v7.0.1), rust-toolchain 02cb101e (v1), rust-cache 6323deb1 (v2.9.2); lock entry updated to match by hand (`gh actions-lock` write mode de-pins them again) - `toolchain: v1` -> `stable` (v1 is the action's tag, not a Rust toolchain) - one "managed by gh actions-lock" line after SPDX instead of three Verify (--no-fix) on this file: 0 errors, 3 sha-as-ref warnings; repo total 67 -> 66 findings, none new. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8 --- .github/workflows/actions.lock | 11 ++++++++--- .github/workflows/scan-and-report.yml | 10 ++++------ 2 files changed, 12 insertions(+), 9 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index ab632ff..3e5ec1e 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -61,9 +61,9 @@ workflows: - 'swatinem/rust-cache@v2.8.2' '.github/workflows/rust-ci.yml': [] '.github/workflows/scan-and-report.yml': - - 'actions/checkout@v4.3.1' - - 'dtolnay/rust-toolchain@v1' - - 'swatinem/rust-cache@v2.8.2' + - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' + - 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de' + - 'Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6' '.github/workflows/scorecard.yml': [] '.github/workflows/secret-scanner.yml': [] dependencies: @@ -199,6 +199,11 @@ dependencies: commit: 'sha1-65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08' owner_id: 44036562 repo_id: 192625955 + 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de': + ref: 'v1' + commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' + owner_id: 1940490 + repo_id: 260749683 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772': ref: 'stable' commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772' diff --git a/.github/workflows/scan-and-report.yml b/.github/workflows/scan-and-report.yml index 32fe861..5e0d74a 100644 --- a/.github/workflows/scan-and-report.yml +++ b/.github/workflows/scan-and-report.yml @@ -1,7 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # This workflow is managed by gh actions-lock. -# This workflow is managed by gh actions-lock. name: Scan and Report to VeriSimDB @@ -38,15 +36,15 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 20 steps: - - uses: actions/checkout@v7.0.1 + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Install Rust - uses: dtolnay/rust-toolchain@v1 + uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1 with: - toolchain: v1 + toolchain: stable - name: Cache Rust dependencies - uses: Swatinem/rust-cache@v2.9.2 + uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 - name: Install panic-attack run: | From 39081ecd6f71024330fcb941aa9e641053b7e41d Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 23:37:34 +0100 Subject: [PATCH 2/2] fix(ci): re-key codeql.yml lock entry to its bumped refs codeql.yml was bumped to actions/checkout@v7.0.1 and github/codeql-action@v4.38.2 but actions.lock still pinned v6.0.2 and v4.34.0, so every CodeQL run since 5e75753 (2026-09-28) died at startup with "Invalid lockfile". CodeQL is the ruleset's only required status check, so no PR on main could merge. Hand-edited (write mode de-pins SHAs and prunes shared records): v4.38.2 -> 2892aa5e (annotated tag dereferenced), v7.0.1 -> 3d3c42e5. gh actions-lock --no-fix: codeql.yml findings 10 -> 0. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8 --- .github/workflows/actions.lock | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 3e5ec1e..807b706 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -24,8 +24,8 @@ workflows: - 'actions/upload-artifact@v4.6.2' - 'dtolnay/rust-toolchain@v1' '.github/workflows/codeql.yml': - - 'actions/checkout@v6.0.2' - - 'github/codeql-action@v4.34.0' + - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.38.2' '.github/workflows/coverage.yml': - 'actions/checkout@v5.0.1' - 'dtolnay/rust-toolchain@v1' @@ -102,6 +102,11 @@ dependencies: commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' owner_id: 44036562 repo_id: 197814629 + 'actions/checkout@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' + owner_id: 44036562 + repo_id: 197814629 'actions/configure-pages@v5.0.0': ref: 'v5.0.0' commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b' @@ -144,9 +149,9 @@ dependencies: commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.34.0': - ref: 'v4.34.0' - commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + 'github/codeql-action@v4.38.2': + ref: 'v4.38.2' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' owner_id: 9919 repo_id: 259445878 'haskell-actions/setup@v2.7.5':