Skip to content

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) - #32

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/sha-pin-actions
Sep 20, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/sha-pin-actions

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6)

actions.lock is authoritative: the workflows carry readable refs and the lock records the
commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable — startup_failure, "Invalid lockfile".

Regenerated with the official extension (github/gh-actions-lock). The hand-pinned SHA refs are
reverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.

…0.1.6)

`actions.lock` is authoritative: the workflows carry readable refs and the lock records the
commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest
make the whole repository unstartable — `startup_failure`, "Invalid lockfile".

Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are
reverted to their readable form here precisely because the lockfile, not the workflow, is what
pins them.
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 2b032d7c-ea01-4ca2-9399-0f3cddf43900

📥 Commits

Reviewing files that changed from the base of the PR and between 1a3bd7f and b792d00.

📒 Files selected for processing (6)
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/label-triage.yml
  • .github/workflows/labels.yml
  • .github/workflows/push-email-notify.yml
  • .github/workflows/secret-scanner.yml

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (4)
  • GitHub Check: secret-scan / shell-secrets
  • GitHub Check: secret-scan / rust-secrets
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: secret-scan / gitleaks
🔇 Additional comments (7)
.github/workflows/governance.yml (1)

1-1: LGTM!

.github/workflows/hypatia-scan.yml (1)

1-1: LGTM!

.github/workflows/label-triage.yml (1)

1-1: LGTM!

.github/workflows/labels.yml (1)

1-1: LGTM!

.github/workflows/push-email-notify.yml (2)

1-1: LGTM!


44-44: 🔒 Security & Privacy | 🛡️ Analyzed with Security Review

The lockfile is enforced for this action.

The workflow is onboarded in .github/workflows/actions.lock, which records the resolved commit. gh-actions-lock guarantees that onboarded workflows execute the locked commit, so a moved v0.2.0 tag cannot select different code through this workflow. No change is required.

Likely an incorrect or invalid review comment.

.github/workflows/secret-scanner.yml (1)

1-1: LGTM!


📝 Summary

Summary by CodeRabbit

  • Documentation

    • Added management annotations to several automated workflows to clarify their maintenance status.
    • Updated workflow metadata related to push notification processing.
  • Chores

    • No user-facing functionality or workflow behaviour has changed.
    • Automated governance, scanning, labelling, notification, and security checks continue to operate as before.

Walkthrough

Six GitHub Actions workflows now include gh actions-lock management comments. The push notification workflow also changes the smtp-notify-action reference from a pinned commit SHA to the mutable tag v0.2.0.

Changes

Workflow management updates

Layer / File(s) Summary
Workflow annotations and action reference
.github/workflows/*.yml
Management comments were added to six workflows. The smtp-notify-action reference changed from a pinned SHA to @v0.2.0.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes reconciling CI workflows with the actions.lock configuration. It matches the main change.
Description check ✅ Passed The description explains the actions.lock reconciliation, the workflow reference changes, and the startup_failure issue. It relates directly to the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit marks each workflow line
With tidy notes in a neat design
One action tag now points anew
The locks stand clear for all to view
Soft paws approve the change_queue tune

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 751747b into main Sep 20, 2026
6 checks passed
@hyperpolymath
hyperpolymath deleted the fix/sha-pin-actions branch September 20, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant