diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 22626fa..cfb7ec2 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -12,8 +12,10 @@ workflows: - 'actions/deploy-pages@v5.0.1' - 'actions/upload-pages-artifact@v5.0.0' - 'haskell-actions/setup@v2.12.1' - '.github/workflows/governance.yml': [] - '.github/workflows/hypatia-scan.yml': [] + '.github/workflows/governance.yml': + - 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540' + '.github/workflows/hypatia-scan.yml': + - 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540' '.github/workflows/instant-sync.yml': - 'peter-evans/repository-dispatch@v4.0.1' '.github/workflows/journal-theme-php-standards.yml': @@ -27,7 +29,8 @@ workflows: - 'dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87' '.github/workflows/label-triage.yml': [] '.github/workflows/labels.yml': [] - '.github/workflows/mirror.yml': [] + '.github/workflows/mirror.yml': + - 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540' '.github/workflows/pages.yml': - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.1' @@ -41,8 +44,10 @@ workflows: - 'dtolnay/rust-toolchain@d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3' '.github/workflows/push-email-notify.yml': - 'hyperpolymath/smtp-notify-action@v0.3.0' - '.github/workflows/scorecard.yml': [] - '.github/workflows/secret-scanner.yml': [] + '.github/workflows/scorecard.yml': + - 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540' + '.github/workflows/secret-scanner.yml': + - 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540' dependencies: 'actions/cache@v6.1.0': ref: 'v6.1.0' @@ -86,6 +91,21 @@ dependencies: commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' owner_id: 6759885 repo_id: 1352485172 + 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540': + ref: 'da2c748aad55c1a1dcba00b60fe4a35017bc6540' + commit: 'sha1-da2c748aad55c1a1dcba00b60fe4a35017bc6540' + owner_id: 6759885 + repo_id: 1116521501 + uses: + - 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9' + - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' + - 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' + - 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772' + - 'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393' + - 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124' + - 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938' + - 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc' + - 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555' 'peter-evans/repository-dispatch@v4.0.1': ref: 'v4.0.1' commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' @@ -106,19 +126,14 @@ dependencies: commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' owner_id: 44036562 repo_id: 192625955 - 'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed': - ref: 'v2.0.5' - commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed' - owner_id: 42048915 - repo_id: 356423100 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772': ref: 'stable' commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772' owner_id: 1940490 repo_id: 260749683 - 'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c': - ref: 'v2.2.0' - commit: 'sha1-840e866d93b8e032123c23bac69dece044d4d84c' + 'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393': + ref: '51f63319f592f97930c73d9c46184d20bd206393' + commit: 'sha1-51f63319f592f97930c73d9c46184d20bd206393' owner_id: 26415196 repo_id: 297874902 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124': @@ -126,6 +141,11 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 + 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938': + ref: 'cdf488f595d80d6e07e03d4674febd5ab45fa938' + commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' + owner_id: 9919 + repo_id: 259445878 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc': ref: 'v2.4.4' commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc' diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index e63a8ee..306a707 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,6 +1,5 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. name: Governance on: @@ -10,14 +9,20 @@ on: branches: [main, master] workflow_dispatch: +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true permissions: - actions: read + actions: read # required by the reusable workflow (staleness check reads workflow runs) contents: read jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 + # Optional credentialed live-policy audit. governance-reusable@da2c748 + # declares HYPATIA_SCAN_PAT (fine-grained PAT, Administration: read) as an + # optional secret: without it the "Live Actions policy (credentialed + # advisory)" job reports a notice instead of running; with it, the live + # check actually executes. Passing an absent secret is a no-op. secrets: - # Optional credentialed live-policy audit ("Live Actions policy" - # advisory job). Absent secret => advisory notice, not a red run. HYPATIA_SCAN_PAT: ${{ secrets.HYPATIA_SCAN_PAT }} diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index b8b7d7a..e2c5ee9 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,6 +1,5 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. name: Hypatia Security Scan on: @@ -12,11 +11,19 @@ on: - cron: '0 0 * * 0' workflow_dispatch: +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true permissions: - actions: read + actions: read # required by the reusable workflow (staleness check reads workflow runs) contents: read + # MUST be `write`, not `read`. hypatia-scan-reusable.yml declares + # `security-events: write` so it can upload SARIF. A called workflow may + # never request more than its caller grants: if it does, GitHub rejects the + # run at startup, before any job is created — `startup_failure`, zero jobs, + # and `gh run view --log-failed` returns "log not found" (standards#451). security-events: write jobs: hypatia: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 816acff..23c34cf 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,15 +1,29 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: push: branches: [main] workflow_dispatch: +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false permissions: - actions: read + actions: read # required by the reusable workflow (staleness check reads workflow runs) contents: read jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d5fe075a50ab3ce4f41614d66ed77f152fda134f - secrets: inherit + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 + # Explicit secrets map — no `secrets: inherit` (Hypatia WH008, alert #131). + # All seven are the callee's complete optional contract (standards + # mirror-reusable.yml@da2c748); behaviour is unchanged, future secrets + # are no longer shared implicitly. Forge selection is per-repo via the + # _MIRROR_ENABLED Actions variables. + secrets: + GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }} + BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }} + CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }} + SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }} + DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }} + GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }} + RADICLE_KEY: ${{ secrets.RADICLE_KEY }} diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index c910772..d5279fe 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,11 +1,10 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. name: Scorecard on: schedule: - - cron: "0 0 * * 0" + - cron: '0 0 * * 0' push: branches: [main, master] workflow_dispatch: @@ -15,11 +14,18 @@ concurrency: cancel-in-progress: true permissions: - actions: read + actions: read # required by the reusable workflow (staleness check reads workflow runs) contents: read - security-events: write - id-token: write jobs: scorecard: - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 + # Reusable called-workflow permissions are CAPPED by the caller's grants; + # without security-events: write here the scorecard SARIF upload fails with + # startup_failure (hypatia WF018). id-token: write enables OIDC publish. + # The reusable's job self-gates on non-pull_request events, so only + # default-branch publication receives OIDC. + permissions: + contents: read + security-events: write + id-token: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index f3dd0e3..8a86c96 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,6 +1,5 @@ # This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 -# This workflow is managed by gh actions-lock. name: Secret Scanner on: pull_request: @@ -14,12 +13,16 @@ permissions: contents: read jobs: scan: - # The pinned reusable (post-standards-#500) needs only `contents: read`: - # its gitleaks job runs a pinned checksum-verified binary and posts no PR - # comments, so the old `pull-requests: write` + `actions: read` caller - # guidance is obsolete (see the PERMISSIONS note in the reusable itself). - # A job-level block REPLACES the workflow-level one for this job. + # The reusable (post-standards-#500) needs only `contents: read` for its + # own scans: its gitleaks job runs a pinned checksum-verified binary and + # posts no PR comments, so the old `pull-requests: write` caller guidance + # is obsolete. This job-level block REPLACES the workflow-level one for + # this job — it is the cap GitHub applies to the called workflow. permissions: contents: read - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540 + # `secrets: inherit` is required by the callee's contract + # (secret-scanner-reusable.yml@da2c748): without it the inner + # `secrets.GITHUB_TOKEN` reference resolves empty and gitleaks falls back + # to anonymous mode (rate-limited; misses some PRs). secrets: inherit