Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
80 changes: 78 additions & 2 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ workflows:
- 'ocaml/setup-ocaml@e89b2ded52a6e13f50162220cf5fe47290162032'
'.github/workflows/allowlist-preflight-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/apply-workflow-pins.yml':
- 'actions/checkout@v7.0.1'
- 'actions/create-github-app-token@v3.2.0'
- 'actions/upload-artifact@v7.0.1'
'.github/workflows/boj-build.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/canon-spine-lockstep.yml':
Expand All @@ -33,6 +37,8 @@ workflows:
'.github/workflows/codeql.yml': []
'.github/workflows/debt-measure.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/deed-conformance.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/doc-format.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/dyadt-verify.yml':
Expand Down Expand Up @@ -68,11 +74,11 @@ workflows:
'.github/workflows/labels.yml': []
'.github/workflows/launcher-standard-lockstep.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/lock-selfcheck.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/lockfile-drift-detect.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
'.github/workflows/lock-selfcheck.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/makefile-blocker.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/mirror-reusable.yml':
Expand All @@ -82,10 +88,19 @@ workflows:
'.github/workflows/mirror.yml': []
'.github/workflows/no-js-scan.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/pages-archive.yml':
- 'actions/cache@v6.1.0'
- 'actions/checkout@v7.0.1'
- 'actions/configure-pages@v6.0.0'
- 'actions/deploy-pages@v5.0.1'
- 'actions/upload-pages-artifact@v5.0.0'
- 'haskell-actions/setup@v2.12.0'
'.github/workflows/pages.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346'
- 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9'
'.github/workflows/propagate-hooks.yml':
- 'actions/checkout@v7.0.1'
'.github/workflows/readme-derive-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/readme-derive.yml': []
Expand All @@ -108,40 +123,76 @@ workflows:
- 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc'
'.github/workflows/secret-scanner-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/security-gate-pr-target.yml':
- 'actions/checkout@v7.0.1'
- 'actions/github-script@v9.0.0'
- 'hyperpolymath/a2ml-ecosystem@main'
'.github/workflows/self-test.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/settings-drift-detect.yml':
- 'actions/checkout@v7.0.1'
- 'actions/upload-artifact@v7.0.1'
'.github/workflows/signed-push-smoke.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1'
- 'asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897'
'.github/workflows/spark-theatre-gate.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/tag-ruleset-canon.yml':
- 'actions/checkout@v7.0.1'
- 'actions/create-github-app-token@v3.2.0'
- 'actions/upload-artifact@v7.0.1'
dependencies:
'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9':
ref: '55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
owner_id: 44036562
repo_id: 215566462
'actions/cache@v6.1.0':
ref: 'v6.1.0'
commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
owner_id: 44036562
repo_id: 215566462
'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1':
ref: 'v7.0.1'
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
owner_id: 44036562
repo_id: 197814629
'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d':
ref: '45bfe0192ca1faeb007ade9deae92b16b8254a0d'
commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d'
owner_id: 44036562
repo_id: 513659658
'actions/configure-pages@v6.0.0':
ref: 'v6.0.0'
commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d'
owner_id: 44036562
repo_id: 513659658
'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1':
ref: 'v3.2.0'
commit: 'sha1-bcd2ba49218906704ab6c1aa796996da409d3eb1'
owner_id: 44036562
repo_id: 642580244
'actions/create-github-app-token@v3.2.0':
ref: 'v3.2.0'
commit: 'sha1-bcd2ba49218906704ab6c1aa796996da409d3eb1'
owner_id: 44036562
repo_id: 642580244
'actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346':
ref: '368f82528645a54fb793d4d04e342629a3f51346'
commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346'
owner_id: 44036562
repo_id: 438112499
'actions/deploy-pages@v5.0.1':
ref: 'v5.0.1'
commit: 'sha1-368f82528645a54fb793d4d04e342629a3f51346'
owner_id: 44036562
repo_id: 438112499
'actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c':
ref: 'v8.0.1'
commit: 'sha1-3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c'
Expand All @@ -152,6 +203,11 @@ dependencies:
commit: 'sha1-3a2844b7e9c422d3c10d287c895573f7108da1b3'
owner_id: 44036562
repo_id: 205262760
'actions/github-script@v9.0.0':
ref: 'v9.0.0'
commit: 'sha1-3a2844b7e9c422d3c10d287c895573f7108da1b3'
owner_id: 44036562
repo_id: 205262760
'actions/setup-python@v2':
ref: 'v2'
commit: 'sha1-e9aba2c848f5ebd159c070c61ea2c4e2b122355e'
Expand All @@ -167,13 +223,23 @@ dependencies:
commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
owner_id: 44036562
repo_id: 192625955
'actions/upload-artifact@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
owner_id: 44036562
repo_id: 192625955
'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9':
ref: 'fc324d3547104276b827a68afc52ff2a11cc49c9'
commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9'
owner_id: 44036562
repo_id: 496012378
uses:
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
'actions/upload-pages-artifact@v5.0.0':
ref: 'v5.0.0'
commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9'
owner_id: 44036562
repo_id: 496012378
'asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897':
ref: 'v1.3'
commit: 'sha1-d615ca88d8e1a946734c24970d1e7a6c56f34897'
Expand Down Expand Up @@ -211,6 +277,16 @@ dependencies:
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
owner_id: 75048950
repo_id: 623796603
'haskell-actions/setup@v2.12.0':
ref: 'v2.12.0'
commit: 'sha1-6037f33647c3f17758a2356c80fc4a53d7e0685d'
owner_id: 75048950
repo_id: 623796603
'hyperpolymath/a2ml-ecosystem@main':
ref: 'main'
commit: 'sha1-f7a40a4d5cc82b2e73f861119baa6818d77a448d'
owner_id: 6759885
repo_id: 1275649586
'ocaml/setup-ocaml@e89b2ded52a6e13f50162220cf5fe47290162032':
ref: 'v3.8.0'
commit: 'sha1-e89b2ded52a6e13f50162220cf5fe47290162032'
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/affinescript-verify.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: AffineScript Verify
Expand Down
9 changes: 5 additions & 4 deletions .github/workflows/apply-workflow-pins.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
#
Expand Down Expand Up @@ -54,7 +55,7 @@ jobs:
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1

# WHICH App's credentials belong in vars.APP_ID / secrets.APP_PRIVATE_KEY:
# a DEDICATED App for this applier, explicitly NOT OikosBot. Owner ruling
Expand All @@ -70,7 +71,7 @@ jobs:
- name: Mint an App installation token for hyperpolymath
id: tok-user
if: vars.APP_ID != ''
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
uses: actions/create-github-app-token@v3.2.0
continue-on-error: true
with:
app-id: ${{ vars.APP_ID }}
Expand All @@ -80,7 +81,7 @@ jobs:
- name: Mint an App installation token for metadatastician
id: tok-org
if: vars.APP_ID != ''
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
uses: actions/create-github-app-token@v3.2.0
continue-on-error: true
with:
app-id: ${{ vars.APP_ID }}
Expand Down Expand Up @@ -145,7 +146,7 @@ jobs:

- name: Upload the census
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
uses: actions/upload-artifact@v7.0.1
with:
name: workflow-pin-census
path: census.tsv
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/boj-build.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
#
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/canon-spine-lockstep.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# canon-spine-lockstep — GATE A.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/casket-pages.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: GitHub Pages
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/changelog-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath)
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Changelog
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/check-suite-monitor.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# 🟡 CHECK: Check Suite Monitor
# This workflow is managed by gh actions-lock.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/codeql-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# codeql-reusable.yml — Reusable CodeQL security-analysis workflow.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: CodeQL Security Analysis
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/debt-measure.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: "📅 Debt measure"

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/deed-conformance.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: deed-conformance

Expand All @@ -22,7 +23,7 @@ jobs:
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/checkout@v7.0.1
with:
persist-credentials: false
- name: validator self-test
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/doc-format.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Documentation Format Enforcement
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/dyadt-verify.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# dyadt-verify — DYADT dogfood. Verify this repo's CLAIMS.a2ml against primary
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/echidna-verify.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# ECHIDNA proof verification — formal verification of Agda and Idris2 proofs.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/elixir-ci-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# elixir-ci-reusable.yml — Reusable Elixir CI bundle (RSR).
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/elixir-ci.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Elixir CI
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/governance-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Governance checks for hyperpolymath repositories — Reusable Workflow
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Governance
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/hypatia-scan-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Hypatia Neurosymbolic CI/CD Security Scan — Reusable Workflow
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Hypatia Security Scan
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/instant-sync.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# Instant Forge Sync - Triggers propagation to all forges on push/release
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/k9-contractile.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
#
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/label-triage.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Label Triage

Expand Down
1 change: 1 addition & 0 deletions .github/workflows/labels.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
name: Labels

Expand Down
1 change: 1 addition & 0 deletions .github/workflows/launcher-standard-lockstep.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: launcher-standard lock-step
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/lockfile-drift-detect.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# Copyright (c) 2026 Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
#
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/makefile-blocker.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Makefile Blocker
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/mirror-reusable.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
Comment thread
github-advanced-security[bot] marked this conversation as resolved.
Fixed
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# mirror-reusable.yml — Reusable git-forge mirror bundle.
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/mirror.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Mirror to Git Forges
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/no-js-scan.yml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: No-JS Scan (warn-first)
Expand Down
Loading
Loading