You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Audit follow-up. governance / Workflow security linter fails on every run (e.g. run 36184467817, job 108234397269) at step Check SHA-pinned actions with exit code 127.
Root cause (reproduced from the pinned reusable source):
.github/workflows/governance.yml pins governance-reusable.yml@84355587 (2026-08-27). At that pin, the step runs:
scripts/update-actions-lock.sh is a hyperpolymath/standards helper that does not exist in consumer checkouts — bash exits 127 "No such file or directory". This is exactly the consumer-side bug fixed in standards by #684 / 0a70a726 "fix(governance): provide lock verifier to consumers" (its commit message names this precise symptom: "Consumer repositories with an actions.lock do not carry that standards implementation script, so their otherwise-correct governance job failed with exit 127").
A second defect at the same pin would fail the step even with the script present: its unpinned grep requires inline 40-hex SHA pins, but this repo intentionally uses symbolic version refs under GitHub's native actions.lock resolution. Fixed in standards by #686 / f192f08d "fix(governance): honor native actions lock resolution", which replaced that grep with gh actions-lock --verify-local ("Check locked or SHA-pinned actions").
Fix in this repo:
Re-pin governance-reusable.yml to 28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a (2026-08-29+, first pin containing #684 + #686 + the live-policy advisory split + the pinned-source fixes).
No change needed in hyperpolymath/standards for this item — both defects are already fixed there; this repo's pin just predates the fixes. (A full refresh to current standards HEAD remains available as routine maintenance.)
Audit follow-up.
governance / Workflow security linterfails on every run (e.g. run 36184467817, job 108234397269) at step Check SHA-pinned actions with exit code 127.Root cause (reproduced from the pinned reusable source):
.github/workflows/governance.ymlpinsgovernance-reusable.yml@84355587(2026-08-27). At that pin, the step runs:scripts/update-actions-lock.shis a hyperpolymath/standards helper that does not exist in consumer checkouts —bashexits 127 "No such file or directory". This is exactly the consumer-side bug fixed in standards by #684 / 0a70a726 "fix(governance): provide lock verifier to consumers" (its commit message names this precise symptom: "Consumer repositories with an actions.lock do not carry that standards implementation script, so their otherwise-correct governance job failed with exit 127").A second defect at the same pin would fail the step even with the script present: its
unpinnedgrep requires inline 40-hex SHA pins, but this repo intentionally uses symbolic version refs under GitHub's native actions.lock resolution. Fixed in standards by #686 / f192f08d "fix(governance): honor native actions lock resolution", which replaced that grep withgh actions-lock --verify-local("Check locked or SHA-pinned actions").Fix in this repo:
governance-reusable.ymlto 28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a (2026-08-29+, first pin containing #684 + #686 + the live-policy advisory split + the pinned-source fixes)..github/workflows/actions.lock(it currently listshaskell-actions/setup@v2.12.0whilecasket-pages.ymluses@v2.12.1— dependabot PR chore(deps): Bump haskell-actions/setup from 2.12.0 to 2.12.1 in the actions group #79 bumped the workflow without regenerating the lock, which--verify-localwill flag as stale).No change needed in hyperpolymath/standards for this item — both defects are already fixed there; this repo's pin just predates the fixes. (A full refresh to current standards HEAD remains available as routine maintenance.)