Skip to content

Commit 1628d9e

Browse files
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock) (#75)
fix(ci): reconcile the workflows with actions.lock (gh-actions-lock v0.1.6) `actions.lock` is authoritative: the workflows carry readable refs and the lock records the commit each ref resolves to, which is what actually runs. Refs that stop matching the manifest make the whole repository unstartable — `startup_failure`, "Invalid lockfile". Regenerated with the official extension (`github/gh-actions-lock`). The hand-pinned SHA refs are reverted to their readable form here precisely because the lockfile, not the workflow, is what pins them.
1 parent 8711f76 commit 1628d9e

12 files changed

Lines changed: 26 additions & 14 deletions

‎.github/workflows/boj-build.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: BoJ Server Build Trigger
@@ -11,7 +12,7 @@ jobs:
1112
timeout-minutes: 15
1213
steps:
1314
- name: Checkout
14-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
15+
uses: actions/checkout@v7.0.1
1516
- name: Trigger BoJ Server (Casket/ssg-mcp)
1617
run: |
1718
# Send a secure trigger to boj-server to build this repository

‎.github/workflows/casket-pages.yml‎

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: GitHub Pages
@@ -18,19 +19,19 @@ jobs:
1819
timeout-minutes: 15
1920
steps:
2021
- name: Checkout
21-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
22+
uses: actions/checkout@v7.0.1
2223
- name: Checkout casket-ssg
23-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
24+
uses: actions/checkout@v7.0.1
2425
with:
2526
repository: hyperpolymath/casket-ssg
2627
path: .casket-ssg
2728
- name: Setup GHCup
28-
uses: haskell-actions/setup@6037f33647c3f17758a2356c80fc4a53d7e0685d # v2.12.0
29+
uses: haskell-actions/setup@v2.12.0
2930
with:
3031
ghc-version: '9.8.2'
3132
cabal-version: '3.10'
3233
- name: Cache Cabal
33-
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
34+
uses: actions/cache@v6.1.0
3435
with:
3536
path: |
3637
~/.cabal/packages
@@ -88,9 +89,9 @@ jobs:
8889
cd .casket-ssg && cabal run casket-ssg -- build ../.site-src ../_site
8990
touch ../_site/.nojekyll
9091
- name: Setup Pages
91-
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
92+
uses: actions/configure-pages@v6.0.0
9293
- name: Upload artifact
93-
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
94+
uses: actions/upload-pages-artifact@v5.0.0
9495
with:
9596
path: '_site'
9697
deploy:
@@ -103,4 +104,4 @@ jobs:
103104
steps:
104105
- name: Deploy to GitHub Pages
105106
id: deployment
106-
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
107+
uses: actions/deploy-pages@v5.0.1

‎.github/workflows/governance.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: Governance

‎.github/workflows/hypatia-scan.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: Hypatia Security Scan

‎.github/workflows/instant-sync.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# Instant Forge Sync - Triggers propagation to all forges on push/release
@@ -15,7 +16,7 @@ jobs:
1516
timeout-minutes: 15
1617
steps:
1718
- name: Trigger Propagation
18-
uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v4.0.1
19+
uses: peter-evans/repository-dispatch@v4.0.1
1920
with:
2021
token: ${{ secrets.FARM_DISPATCH_TOKEN }}
2122
repository: hyperpolymath/.git-private-farm

‎.github/workflows/label-triage.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Label Triage
34

‎.github/workflows/labels.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
name: Labels
34

‎.github/workflows/mirror.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: Mirror to Git Forges

‎.github/workflows/pages.yml‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
name: GitHub Pages (Ddraig SSG)
@@ -20,9 +21,9 @@ jobs:
2021
image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff
2122
steps:
2223
- name: Checkout Site
23-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
24+
uses: actions/checkout@v7.0.1
2425
- name: Checkout Ddraig SSG
25-
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
26+
uses: actions/checkout@v7.0.1
2627
with:
2728
repository: hyperpolymath/ddraig-ssg
2829
path: .ddraig-ssg
@@ -39,7 +40,7 @@ jobs:
3940
fi
4041
./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/}
4142
- name: Upload artifact
42-
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
43+
uses: actions/upload-pages-artifact@v5.0.0
4344
with:
4445
path: '_site'
4546
deploy:
@@ -52,4 +53,4 @@ jobs:
5253
steps:
5354
- name: Deploy to GitHub Pages
5455
id: deployment
55-
uses: actions/deploy-pages@368f82528645a54fb793d4d04e342629a3f51346 # v5.0.1
56+
uses: actions/deploy-pages@v5.0.1

‎.github/workflows/push-email-notify.yml‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,4 @@
1+
# This workflow is managed by gh actions-lock.
12
# SPDX-License-Identifier: MPL-2.0
23
# This workflow is managed by gh actions-lock.
34
# Dormant push-email notification. ARMED by setting the repo variable
@@ -40,7 +41,7 @@ jobs:
4041
timeout-minutes: 5
4142
steps:
4243
- name: Send push notification email
43-
uses: hyperpolymath/smtp-notify-action@22e7bdb322c430c1d0dac6b3bb307f4bb139d0be # NOSONAR — pin authority is actions.lock (sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7)
44+
uses: hyperpolymath/smtp-notify-action@v0.3.0
4445
with:
4546
server_address: ${{ secrets.SMTP_HOST }}
4647
server_port: ${{ secrets.SMTP_PORT }}

0 commit comments

Comments
 (0)