Skip to content

Commit ea57ab2

Browse files
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (#10)
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them.
1 parent ea72950 commit ea57ab2

8 files changed

Lines changed: 35 additions & 27 deletions

File tree

‎.github/workflows/ada-ci.yml‎

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34

@@ -35,7 +36,7 @@ jobs:
3536

3637
steps:
3738
- name: Checkout repository
38-
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
39+
uses: actions/checkout@v4.4.0
3940
with:
4041
fetch-depth: 0
4142
submodules: recursive
@@ -68,7 +69,7 @@ jobs:
6869
fi
6970
7071
- name: Upload artifact
71-
uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3.2.1
72+
uses: actions/upload-artifact@v3.2.1
7273
with:
7374
name: trigger-binaries
7475
path: |
@@ -85,10 +86,10 @@ jobs:
8586

8687
steps:
8788
- name: Checkout repository
88-
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
89+
uses: actions/checkout@v4.4.0
8990

9091
- name: Download artifact
91-
uses: actions/download-artifact@9bc31d5ccc31df68ecc42ccf4149144866c47d8a # v3.0.2
92+
uses: actions/download-artifact@v3.0.2
9293
with:
9394
name: trigger-binaries
9495
path: .
@@ -113,7 +114,7 @@ jobs:
113114

114115
steps:
115116
- name: Checkout repository
116-
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
117+
uses: actions/checkout@v4.4.0
117118

118119
- name: Install Zig
119120
run: |
@@ -131,7 +132,7 @@ jobs:
131132
ls -la ffi/zig/
132133
133134
- name: Upload Zig artifact
134-
uses: actions/upload-artifact@ff15f0306b3f739f7b6fd43fb5d26cd321bd4de5 # v3.2.1
135+
uses: actions/upload-artifact@v3.2.1
135136
with:
136137
name: zig-ffi
137138
path: ffi/zig/
@@ -145,7 +146,7 @@ jobs:
145146

146147
steps:
147148
- name: Checkout repository
148-
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
149+
uses: actions/checkout@v4.4.0
149150

150151
- name: Run self-diagnostics
151152
run: |
@@ -192,7 +193,7 @@ jobs:
192193

193194
steps:
194195
- name: Checkout repository
195-
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
196+
uses: actions/checkout@v4.4.0
196197

197198
- name: Check for secrets
198199
run: |

‎.github/workflows/dogfood-gate.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>
@@ -30,7 +31,7 @@ jobs:
3031

3132
steps:
3233
- name: Checkout repository
33-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
34+
uses: actions/checkout@v4.3.1
3435

3536
- name: Check for A2ML files
3637
id: detect
@@ -75,7 +76,7 @@ jobs:
7576

7677
steps:
7778
- name: Checkout repository
78-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
79+
uses: actions/checkout@v4.3.1
7980

8081
- name: Check for K9 files
8182
id: detect
@@ -125,7 +126,7 @@ jobs:
125126

126127
steps:
127128
- name: Checkout repository
128-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
129+
uses: actions/checkout@v4.3.1
129130

130131
- name: Scan for invisible characters
131132
id: lint
@@ -190,7 +191,7 @@ jobs:
190191

191192
steps:
192193
- name: Checkout repository
193-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
194+
uses: actions/checkout@v4.3.1
194195

195196
- name: Check for Groove manifest
196197
id: groove
@@ -255,7 +256,7 @@ jobs:
255256

256257
steps:
257258
- name: Checkout repository
258-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
259+
uses: actions/checkout@v4.3.1
259260

260261
- name: Check and validate eclexiaiser manifest
261262
id: eclex
@@ -307,7 +308,7 @@ jobs:
307308

308309
steps:
309310
- name: Checkout repository
310-
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
311+
uses: actions/checkout@v4.3.1
311312

312313
- name: Generate dogfooding scorecard
313314
run: |

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
#

‎.github/workflows/label-triage.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Label Triage
34

‎.github/workflows/labels.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Labels
34

‎.github/workflows/openssf-compliance.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# OpenSSF Best Practices compliance gate — blocks PRs and pushes that lack
@@ -21,7 +22,7 @@ jobs:
2122
permissions:
2223
contents: read
2324
steps:
24-
- uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
25+
- uses: actions/checkout@v4.3.1
2526
with:
2627
persist-credentials: false
2728
- name: Check SECURITY.md exists and has substance

‎.github/workflows/static-analysis-gate.yml‎

Lines changed: 12 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# Static Analysis Gate — Required by branch protection rules.
@@ -23,7 +24,7 @@ jobs:
2324
timeout-minutes: 15
2425
steps:
2526
- name: Checkout repository
26-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
27+
uses: actions/checkout@v6.0.2
2728
with:
2829
fetch-depth: 0
2930
- name: Install panic-attack (if available)
@@ -120,7 +121,7 @@ jobs:
120121
echo "" >> "$GITHUB_STEP_SUMMARY"
121122
echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY"
122123
- name: Upload panic-attack findings
123-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
124+
uses: actions/upload-artifact@v4.6.2
124125
with:
125126
name: panic-attack-findings
126127
path: panic-attack-findings.json
@@ -147,13 +148,13 @@ jobs:
147148
timeout-minutes: 15
148149
steps:
149150
- name: Checkout repository
150-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
151+
uses: actions/checkout@v6.0.2
151152
with:
152153
fetch-depth: 0
153154
- name: Setup Elixir for Hypatia scanner
154155
id: beam
155156
continue-on-error: true
156-
uses: erlef/setup-beam@e6d7c94229049569db56a7ad5a540c051a010af9 # v1.20.4
157+
uses: erlef/setup-beam@v1.20.4
157158
with:
158159
elixir-version: '1.19.4'
159160
otp-version: '28.3'
@@ -254,7 +255,7 @@ jobs:
254255
echo "" >> "$GITHUB_STEP_SUMMARY"
255256
echo "Skipped: Hypatia scanner not available in this environment." >> "$GITHUB_STEP_SUMMARY"
256257
- name: Upload hypatia findings
257-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
258+
uses: actions/upload-artifact@v4.6.2
258259
with:
259260
name: hypatia-findings
260261
path: hypatia-findings.json
@@ -273,7 +274,7 @@ jobs:
273274
timeout-minutes: 15
274275
steps:
275276
- name: Checkout repository
276-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
277+
uses: actions/checkout@v6.0.2
277278
with:
278279
fetch-depth: 0
279280
- name: Install panic-attack (if available)
@@ -335,7 +336,7 @@ jobs:
335336
echo "" >> "$GITHUB_STEP_SUMMARY"
336337
echo "Skipped: panic-attack not available in this environment." >> "$GITHUB_STEP_SUMMARY"
337338
- name: Upload bridge report
338-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
339+
uses: actions/upload-artifact@v4.6.2
339340
with:
340341
name: bridge-report
341342
path: bridge-report.json
@@ -357,17 +358,17 @@ jobs:
357358
if: always()
358359
steps:
359360
- name: Download panic-attack findings
360-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
361+
uses: actions/download-artifact@v4.1.8
361362
with:
362363
name: panic-attack-findings
363364
path: findings/
364365
- name: Download hypatia findings
365-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
366+
uses: actions/download-artifact@v4.1.8
366367
with:
367368
name: hypatia-findings
368369
path: findings/
369370
- name: Download bridge report
370-
uses: actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
371+
uses: actions/download-artifact@v4.1.8
371372
with:
372373
name: bridge-report
373374
path: findings/
@@ -427,7 +428,7 @@ jobs:
427428
echo "medium=$MEDIUM" >> "$GITHUB_OUTPUT"
428429
echo "low=$LOW" >> "$GITHUB_OUTPUT"
429430
- name: Upload unified findings (fleet scanner picks these up)
430-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
431+
uses: actions/upload-artifact@v4.6.2
431432
with:
432433
name: unified-findings
433434
path: findings/unified-findings.json

‎.github/workflows/workflow-linter.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# workflow-linter.yml - Validates GitHub workflows against RSR security standards
@@ -28,7 +29,7 @@ jobs:
2829

2930
steps:
3031
- name: Checkout
31-
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
32+
uses: actions/checkout@v6.0.2
3233

3334
- name: Check SPDX Headers
3435
run: |

0 commit comments

Comments
 (0)