Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) #10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uh oh!
There was an error while loading. Please reload this page.
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) #10
Changes from all commits
ba4cb5dFile filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
There are no files selected for viewing
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🩺 Stability & Availability | 🟠 Major | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: hyperpolymath/trigger
Length of output: 29064
🌐 Web query:
official GitHub documentation actions/upload-artifact v3 deprecation January 30 2025 GitHub.com v4 GHES support💡 Result:
<search_synthesis>
The deprecation of actions/upload-artifact v3 and actions/download-artifact v3 on GitHub.com occurred on January 30, 2025 [1][2][3]. After this date, attempts to use v3 of these actions on GitHub.com result in workflow failures [1]. Regarding GitHub Enterprise Server (GHES) support: - The deprecation of v3 on GitHub.com does not impact existing versions of GitHub Enterprise Server [1][4][5]. - As of the deprecation date, actions/upload-artifact v4+ was not supported on GHES [5][6]. Users on GHES were advised to continue using v3 (specifically versions such as v3.2.2) [5][6]. - While GitHub has expressed the intent to bring Artifacts v4 to GHES, it has not been universally available across all GHES versions [7]. Users should consult their specific GHES version documentation for the most accurate information regarding v4 compatibility [5][6].
</search_synthesis>
<source_evidence>
Citations:
Replace all v3 artifact action references.
Because this workflow runs on GitHub.com,
actions/upload-artifact@v3.2.1andactions/download-artifact@v3.0.2fail after 30 January 2025. The build/test artifact hand-off therefore cannot complete. The workflow also usesactions/upload-artifact@v3.2.1for the Zig artifact.Update all three references to compatible v4+ versions, such as the existing
actions/upload-artifact@v4.6.2andactions/download-artifact@v4.1.8lock entries, then regenerate.github/workflows/actions.lock.🧰 Tools
🪛 zizmor (1.30.0)
[warning] 5-255: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[warning] 31-77: overly broad permissions (excessive-permissions): default permissions used due to no permissions: block
(excessive-permissions)
[error] 72-72: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Source: MCP tools
Check failure on line 157 in .github/workflows/static-analysis-gate.yml
Use full commit SHA hash for this dependency.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Keep the SPDX header first.
The
Check SPDX Headersstep readshead -1 "$file"and requires# SPDX-License-Identifier:. This new management marker becomes the first line, soworkflow-linter.ymlfails its own check. Apply the same correction to every workflow with this marker, or update the check to allow the optional management line.🤖 Prompt for AI Agents
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Update the action-pinning check for the lockfile format.
Check SHA-Pinned Actionsrejects everyuses:value without a 40-character hexadecimal SHA. This newactions/checkout@v6.0.2line, plus the tag references in.github/workflows/ada-ci.yml,.github/workflows/dogfood-gate.yml, and.github/workflows/openssf-compliance.yml, will be reported as unpinned. The workflow then exits at line 83.Validate managed references against
.github/workflows/actions.lock, or otherwise update this check to support the readable references required by this PR.🧰 Tools
🪛 zizmor (1.30.0)
[warning] 31-32: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false
(artipacked)
[error] 32-32: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)
(unpinned-uses)
🤖 Prompt for AI Agents
Uh oh!
There was an error while loading. Please reload this page.