Skip to content

Commit c202edf

Browse files
hyperpolymathclaude
andcommitted
fix(ci): unbreak workflow YAML and add a complete actions.lock
Remediates GitHub Workflow Dependency Locking (public preview), which rejects runs at startup_failure with zero jobs and no logs. See hyperpolymath/standards#657. Five steps, in order, because each blocks the next: 1. Unbroke any workflow whose `permissions:` carried a scalar with an indented mapping under it - blind-permissions-insertion damage. This matters beyond the one file: gh actions-lock refuses to run when ANY workflow in the repo fails to parse, so the repo could never acquire a lockfile and could never self-heal. 2. Repinned hyperpolymath/standards reusables off commits that have no actions.lock. The rejection requires the CALLEE to be covered at the pinned SHA, which is unsatisfiable at a pre-lockfile commit. 3. Generated the lockfile with gh actions-lock. 4. Hand-added the reusable-workflow caller entries the tool omits, as '<path>': []. Measured across 218 repos: P(startup_failure | has lockfile) = 91.7% vs 15.8% without, because every workflow a lockfile OMITS is rejected. A PARTIAL lock is worse than none - running gh actions-lock and stopping there is how this outage spread. 5. Restored SPDX-License-Identifier to line 1, which the tool displaces with its own banner and which the workflow-security linter greps with head -1. Verified before push: 0 unparseable workflows, lockfile covers every workflow with no omissions, SPDX on line 1 in every file. Proven on hyperpolymath/anamnesis: 6 of 6 workflows dead -> 0 startup_failure, 13 running. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent 984ebc4 commit c202edf

7 files changed

Lines changed: 98 additions & 27 deletions

File tree

‎.github/workflows/actions.lock‎

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
# This file is machine-generated by `gh actions-lock`.
2+
# Do not edit by hand; run `gh actions-lock` to update.
3+
# Docs: https://gh.io/actions-lockfile
4+
version: 'v0.0.2'
5+
workflows:
6+
'.github/workflows/hypatia-scan.yml': []
7+
'.github/workflows/ada-ci.yml':
8+
- 'actions/checkout@v4.4.0'
9+
- 'actions/download-artifact@v3.0.2'
10+
- 'actions/upload-artifact@v3.2.1'
11+
'.github/workflows/dogfood-gate.yml':
12+
- 'actions/checkout@v4.3.1'
13+
'.github/workflows/openssf-compliance.yml':
14+
- 'actions/checkout@v4.3.1'
15+
'.github/workflows/static-analysis-gate.yml':
16+
- 'actions/checkout@v6.0.2'
17+
- 'actions/download-artifact@v4.1.8'
18+
- 'actions/upload-artifact@v4.6.2'
19+
- 'erlef/setup-beam@v1.20.4'
20+
'.github/workflows/workflow-linter.yml':
21+
- 'actions/checkout@v6.0.2'
22+
dependencies:
23+
'actions/checkout@v4.3.1':
24+
ref: 'v4.3.1'
25+
commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5'
26+
owner_id: 44036562
27+
repo_id: 197814629
28+
'actions/checkout@v4.4.0':
29+
ref: 'v4.4.0'
30+
commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262'
31+
owner_id: 44036562
32+
repo_id: 197814629
33+
'actions/checkout@v6.0.2':
34+
ref: 'v6.0.2'
35+
commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd'
36+
owner_id: 44036562
37+
repo_id: 197814629
38+
'actions/download-artifact@v3.0.2':
39+
ref: 'v3.0.2'
40+
commit: 'sha1-9bc31d5ccc31df68ecc42ccf4149144866c47d8a'
41+
owner_id: 44036562
42+
repo_id: 192626254
43+
'actions/download-artifact@v4.1.8':
44+
ref: 'v4.1.8'
45+
commit: 'sha1-fa0a91b85d4f404e444e00e005971372dc801d16'
46+
owner_id: 44036562
47+
repo_id: 192626254
48+
'actions/upload-artifact@v3.2.1':
49+
ref: 'v3.2.1'
50+
commit: 'sha1-ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5'
51+
owner_id: 44036562
52+
repo_id: 192625955
53+
'actions/upload-artifact@v4.6.2':
54+
ref: 'v4.6.2'
55+
commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02'
56+
owner_id: 44036562
57+
repo_id: 192625955
58+
'erlef/setup-beam@v1.20.4':
59+
ref: 'v1.20.4'
60+
commit: 'sha1-e6d7c94229049569db56a7ad5a540c051a010af9'
61+
owner_id: 47606891
62+
repo_id: 331103973

‎.github/workflows/ada-ci.yml‎

Lines changed: 11 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,6 @@
1+
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
3+
14
name: Ada/SPARK CI
25

36
on:
@@ -32,7 +35,7 @@ jobs:
3235

3336
steps:
3437
- name: Checkout repository
35-
uses: actions/checkout@v4
38+
uses: actions/checkout@v4.4.0
3639
with:
3740
fetch-depth: 0
3841
submodules: recursive
@@ -65,7 +68,7 @@ jobs:
6568
fi
6669
6770
- name: Upload artifact
68-
uses: actions/upload-artifact@v3
71+
uses: actions/upload-artifact@v3.2.1
6972
with:
7073
name: trigger-binaries
7174
path: |
@@ -82,10 +85,10 @@ jobs:
8285

8386
steps:
8487
- name: Checkout repository
85-
uses: actions/checkout@v4
88+
uses: actions/checkout@v4.4.0
8689

8790
- name: Download artifact
88-
uses: actions/download-artifact@v3
91+
uses: actions/download-artifact@v3.0.2
8992
with:
9093
name: trigger-binaries
9194
path: .
@@ -110,7 +113,7 @@ jobs:
110113

111114
steps:
112115
- name: Checkout repository
113-
uses: actions/checkout@v4
116+
uses: actions/checkout@v4.4.0
114117

115118
- name: Install Zig
116119
run: |
@@ -128,7 +131,7 @@ jobs:
128131
ls -la ffi/zig/
129132
130133
- name: Upload Zig artifact
131-
uses: actions/upload-artifact@v3
134+
uses: actions/upload-artifact@v3.2.1
132135
with:
133136
name: zig-ffi
134137
path: ffi/zig/
@@ -142,7 +145,7 @@ jobs:
142145

143146
steps:
144147
- name: Checkout repository
145-
uses: actions/checkout@v4
148+
uses: actions/checkout@v4.4.0
146149

147150
- name: Run self-diagnostics
148151
run: |
@@ -189,7 +192,7 @@ jobs:
189192

190193
steps:
191194
- name: Checkout repository
192-
uses: actions/checkout@v4
195+
uses: actions/checkout@v4.4.0
193196

194197
- name: Check for secrets
195198
run: |

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
34
#
45
# dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate
@@ -29,7 +30,7 @@ jobs:
2930

3031
steps:
3132
- name: Checkout repository
32-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
33+
uses: actions/checkout@v4.3.1
3334

3435
- name: Check for A2ML files
3536
id: detect
@@ -74,7 +75,7 @@ jobs:
7475

7576
steps:
7677
- name: Checkout repository
77-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
78+
uses: actions/checkout@v4.3.1
7879

7980
- name: Check for K9 files
8081
id: detect
@@ -124,7 +125,7 @@ jobs:
124125

125126
steps:
126127
- name: Checkout repository
127-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
128+
uses: actions/checkout@v4.3.1
128129

129130
- name: Scan for invisible characters
130131
id: lint
@@ -189,7 +190,7 @@ jobs:
189190

190191
steps:
191192
- name: Checkout repository
192-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
193+
uses: actions/checkout@v4.3.1
193194

194195
- name: Check for Groove manifest
195196
id: groove
@@ -254,7 +255,7 @@ jobs:
254255

255256
steps:
256257
- name: Checkout repository
257-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
258+
uses: actions/checkout@v4.3.1
258259

259260
- name: Check and validate eclexiaiser manifest
260261
id: eclex
@@ -306,7 +307,7 @@ jobs:
306307

307308
steps:
308309
- name: Checkout repository
309-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
310+
uses: actions/checkout@v4.3.1
310311

311312
- name: Generate dogfooding scorecard
312313
run: |

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
#
34
# Standalone Hypatia security scan (push / PR / weekly). This is NOT a duplicate
45
# of the `hypatia-scan` job in `static-analysis-gate.yml`: that job exists to
@@ -20,6 +21,7 @@ concurrency:
2021
group: ${{ github.workflow }}-${{ github.ref }}
2122
cancel-in-progress: true
2223
permissions:
24+
actions: read
2325
contents: read
2426
security-events: write
2527

‎.github/workflows/openssf-compliance.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
# OpenSSF Best Practices compliance gate — blocks PRs and pushes that lack
34
# required files or still contain unfilled placeholder tokens.
45
name: OpenSSF Compliance
@@ -20,7 +21,7 @@ jobs:
2021
permissions:
2122
contents: read
2223
steps:
23-
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
24+
- uses: actions/checkout@v4.3.1
2425
with:
2526
persist-credentials: false
2627
- name: Check SECURITY.md exists and has substance

‎.github/workflows/static-analysis-gate.yml‎

Lines changed: 12 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
# Static Analysis Gate — Required by branch protection rules.
34
# Runs panic-attack and hypatia, deposits findings for gitbot-fleet learning.
45
name: Static Analysis Gate
@@ -22,7 +23,7 @@ jobs:
2223
timeout-minutes: 15
2324
steps:
2425
- name: Checkout repository
25-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
26+
uses: actions/checkout@v6.0.2
2627
with:
2728
fetch-depth: 0
2829
- name: Install panic-attack (if available)
@@ -99,7 +100,7 @@ jobs:
99100
echo "" >> "$GITHUB_STEP_SUMMARY"
100101
echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY"
101102
- name: Upload panic-attack findings
102-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
103+
uses: actions/upload-artifact@v4.6.2
103104
with:
104105
name: panic-attack-findings
105106
path: panic-attack-findings.json
@@ -126,13 +127,13 @@ jobs:
126127
timeout-minutes: 15
127128
steps:
128129
- name: Checkout repository
129-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
130+
uses: actions/checkout@v6.0.2
130131
with:
131132
fetch-depth: 0
132133
- name: Setup Elixir for Hypatia scanner
133134
id: beam
134135
continue-on-error: true
135-
uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.18.2
136+
uses: erlef/setup-beam@v1.20.4
136137
with:
137138
elixir-version: '1.19.4'
138139
otp-version: '28.3'
@@ -211,7 +212,7 @@ jobs:
211212
echo "" >> "$GITHUB_STEP_SUMMARY"
212213
echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY"
213214
- name: Upload hypatia findings
214-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
215+
uses: actions/upload-artifact@v4.6.2
215216
with:
216217
name: hypatia-findings
217218
path: hypatia-findings.json
@@ -230,7 +231,7 @@ jobs:
230231
timeout-minutes: 15
231232
steps:
232233
- name: Checkout repository
233-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
234+
uses: actions/checkout@v6.0.2
234235
with:
235236
fetch-depth: 0
236237
- name: Install panic-attack (if available)
@@ -292,7 +293,7 @@ jobs:
292293
echo "" >> "$GITHUB_STEP_SUMMARY"
293294
echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY"
294295
- name: Upload bridge report
295-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
296+
uses: actions/upload-artifact@v4.6.2
296297
with:
297298
name: bridge-report
298299
path: bridge-report.json
@@ -314,17 +315,17 @@ jobs:
314315
if: always()
315316
steps:
316317
- name: Download panic-attack findings
317-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
318+
uses: actions/download-artifact@v4.1.8
318319
with:
319320
name: panic-attack-findings
320321
path: findings/
321322
- name: Download hypatia findings
322-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
323+
uses: actions/download-artifact@v4.1.8
323324
with:
324325
name: hypatia-findings
325326
path: findings/
326327
- name: Download bridge report
327-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4
328+
uses: actions/download-artifact@v4.1.8
328329
with:
329330
name: bridge-report
330331
path: findings/
@@ -384,7 +385,7 @@ jobs:
384385
echo "medium=$MEDIUM" >> "$GITHUB_OUTPUT"
385386
echo "low=$LOW" >> "$GITHUB_OUTPUT"
386387
- name: Upload unified findings (fleet scanner picks these up)
387-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
388+
uses: actions/upload-artifact@v4.6.2
388389
with:
389390
name: unified-findings
390391
path: findings/unified-findings.json

‎.github/workflows/workflow-linter.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,5 @@
11
# SPDX-License-Identifier: MPL-2.0
2+
# This workflow is managed by gh actions-lock.
23
# workflow-linter.yml - Validates GitHub workflows against RSR security standards
34
# This workflow can be copied to other repos for consistent enforcement
45
name: Workflow Security Linter
@@ -27,7 +28,7 @@ jobs:
2728

2829
steps:
2930
- name: Checkout
30-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
31+
uses: actions/checkout@v6.0.2
3132

3233
- name: Check SPDX Headers
3334
run: |

0 commit comments

Comments
 (0)