Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
46 changes: 33 additions & 13 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -12,8 +12,10 @@ workflows:
- 'actions/deploy-pages@v5.0.1'
- 'actions/upload-pages-artifact@v5.0.0'
- 'haskell-actions/setup@v2.12.1'
'.github/workflows/governance.yml': []
'.github/workflows/hypatia-scan.yml': []
'.github/workflows/governance.yml':
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
'.github/workflows/hypatia-scan.yml':
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
'.github/workflows/instant-sync.yml':
- 'peter-evans/repository-dispatch@v4.0.1'
'.github/workflows/journal-theme-php-standards.yml':
Expand All @@ -27,7 +29,8 @@ workflows:
- 'dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87'
'.github/workflows/label-triage.yml': []
'.github/workflows/labels.yml': []
'.github/workflows/mirror.yml': []
'.github/workflows/mirror.yml':
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
'.github/workflows/pages.yml':
- 'actions/checkout@v7.0.1'
- 'actions/deploy-pages@v5.0.1'
Expand All @@ -41,8 +44,10 @@ workflows:
- 'dtolnay/rust-toolchain@d0592fe69e35bc8f12e3dbaf9ad2694d976cb8e3'
'.github/workflows/push-email-notify.yml':
- 'hyperpolymath/smtp-notify-action@v0.3.0'
'.github/workflows/scorecard.yml': []
'.github/workflows/secret-scanner.yml': []
'.github/workflows/scorecard.yml':
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
'.github/workflows/secret-scanner.yml':
- 'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540'
dependencies:
'actions/cache@v6.1.0':
ref: 'v6.1.0'
Expand Down Expand Up @@ -86,6 +91,21 @@ dependencies:
commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be'
owner_id: 6759885
repo_id: 1352485172
'hyperpolymath/standards@da2c748aad55c1a1dcba00b60fe4a35017bc6540':
ref: 'da2c748aad55c1a1dcba00b60fe4a35017bc6540'
commit: 'sha1-da2c748aad55c1a1dcba00b60fe4a35017bc6540'
owner_id: 6759885
repo_id: 1116521501
uses:
- 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
- 'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
- 'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393'
- 'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124'
- 'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938'
- 'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc'
- 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555'
'peter-evans/repository-dispatch@v4.0.1':
ref: 'v4.0.1'
commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697'
Expand All @@ -106,26 +126,26 @@ dependencies:
commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a'
owner_id: 44036562
repo_id: 192625955
'denoland/setup-deno@22d081ff2d3a40755e97629de92e3bcbfa7cf2ed':
ref: 'v2.0.5'
commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed'
owner_id: 42048915
repo_id: 356423100
'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772':
ref: 'stable'
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'
owner_id: 1940490
repo_id: 260749683
'editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c':
ref: 'v2.2.0'
commit: 'sha1-840e866d93b8e032123c23bac69dece044d4d84c'
'editorconfig-checker/action-editorconfig-checker@51f63319f592f97930c73d9c46184d20bd206393':
ref: '51f63319f592f97930c73d9c46184d20bd206393'
commit: 'sha1-51f63319f592f97930c73d9c46184d20bd206393'
owner_id: 26415196
repo_id: 297874902
'erlef/setup-beam@54075bcc5e249e4758d363f27d099f55d843f124':
ref: 'v1.24.1'
commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124'
owner_id: 47606891
repo_id: 331103973
'github/codeql-action@cdf488f595d80d6e07e03d4674febd5ab45fa938':
ref: 'cdf488f595d80d6e07e03d4674febd5ab45fa938'
commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938'
owner_id: 9919
repo_id: 259445878
'ossf/scorecard-action@2d1146689b8cda280b9bc96326124645441f03bc':
ref: 'v2.4.4'
commit: 'sha1-2d1146689b8cda280b9bc96326124645441f03bc'
Expand Down
15 changes: 10 additions & 5 deletions .github/workflows/governance.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Governance

on:
Expand All @@ -10,14 +9,20 @@ on:
branches: [main, master]
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
actions: read # required by the reusable workflow (staleness check reads workflow runs)
contents: read

jobs:
governance:
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@28f7a2cba34c51ebccbc4e99acd4cb7cbe07c71a
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
# Optional credentialed live-policy audit. governance-reusable@da2c748
# declares HYPATIA_SCAN_PAT (fine-grained PAT, Administration: read) as an
# optional secret: without it the "Live Actions policy (credentialed
# advisory)" job reports a notice instead of running; with it, the live
# check actually executes. Passing an absent secret is a no-op.
secrets:
# Optional credentialed live-policy audit ("Live Actions policy"
# advisory job). Absent secret => advisory notice, not a red run.
HYPATIA_SCAN_PAT: ${{ secrets.HYPATIA_SCAN_PAT }}
13 changes: 10 additions & 3 deletions .github/workflows/hypatia-scan.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Hypatia Security Scan

on:
Expand All @@ -12,11 +11,19 @@ on:
- cron: '0 0 * * 0'
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
actions: read
actions: read # required by the reusable workflow (staleness check reads workflow runs)
contents: read
# MUST be `write`, not `read`. hypatia-scan-reusable.yml declares
# `security-events: write` so it can upload SARIF. A called workflow may
# never request more than its caller grants: if it does, GitHub rejects the
# run at startup, before any job is created — `startup_failure`, zero jobs,
# and `gh run view --log-failed` returns "log not found" (standards#451).
security-events: write

jobs:
hypatia:
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
22 changes: 18 additions & 4 deletions .github/workflows/mirror.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,29 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Mirror to Git Forges
on:
push:
branches: [main]
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: false
permissions:
actions: read
actions: read # required by the reusable workflow (staleness check reads workflow runs)
contents: read
jobs:
mirror:
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d5fe075a50ab3ce4f41614d66ed77f152fda134f
secrets: inherit
uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
# Explicit secrets map — no `secrets: inherit` (Hypatia WH008, alert #131).
# All seven are the callee's complete optional contract (standards
# mirror-reusable.yml@da2c748); behaviour is unchanged, future secrets
# are no longer shared implicitly. Forge selection is per-repo via the
# <FORGE>_MIRROR_ENABLED Actions variables.
secrets:
GITLAB_SSH_KEY: ${{ secrets.GITLAB_SSH_KEY }}
BITBUCKET_SSH_KEY: ${{ secrets.BITBUCKET_SSH_KEY }}
CODEBERG_SSH_KEY: ${{ secrets.CODEBERG_SSH_KEY }}
SOURCEHUT_SSH_KEY: ${{ secrets.SOURCEHUT_SSH_KEY }}
DISROOT_SSH_KEY: ${{ secrets.DISROOT_SSH_KEY }}
GITEA_SSH_KEY: ${{ secrets.GITEA_SSH_KEY }}
RADICLE_KEY: ${{ secrets.RADICLE_KEY }}
18 changes: 12 additions & 6 deletions .github/workflows/scorecard.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,10 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Scorecard

on:
schedule:
- cron: "0 0 * * 0"
- cron: '0 0 * * 0'
push:
branches: [main, master]
workflow_dispatch:
Expand All @@ -15,11 +14,18 @@ concurrency:
cancel-in-progress: true

permissions:
actions: read
actions: read # required by the reusable workflow (staleness check reads workflow runs)
contents: read
security-events: write
id-token: write

jobs:
scorecard:
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
# Reusable called-workflow permissions are CAPPED by the caller's grants;
# without security-events: write here the scorecard SARIF upload fails with
# startup_failure (hypatia WF018). id-token: write enables OIDC publish.
# The reusable's job self-gates on non-pull_request events, so only
# default-branch publication receives OIDC.
permissions:
contents: read
security-events: write
id-token: write
17 changes: 10 additions & 7 deletions .github/workflows/secret-scanner.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,5 @@
# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
name: Secret Scanner
on:
pull_request:
Expand All @@ -14,12 +13,16 @@ permissions:
contents: read
jobs:
scan:
# The pinned reusable (post-standards-#500) needs only `contents: read`:
# its gitleaks job runs a pinned checksum-verified binary and posts no PR
# comments, so the old `pull-requests: write` + `actions: read` caller
# guidance is obsolete (see the PERMISSIONS note in the reusable itself).
# A job-level block REPLACES the workflow-level one for this job.
# The reusable (post-standards-#500) needs only `contents: read` for its
# own scans: its gitleaks job runs a pinned checksum-verified binary and
# posts no PR comments, so the old `pull-requests: write` caller guidance
# is obsolete. This job-level block REPLACES the workflow-level one for
# this job — it is the cap GitHub applies to the called workflow.
permissions:
contents: read
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@84355587cb2a1f86e6882de83514a32db2646e7a
uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@da2c748aad55c1a1dcba00b60fe4a35017bc6540
# `secrets: inherit` is required by the callee's contract
# (secret-scanner-reusable.yml@da2c748): without it the inner
# `secrets.GITHUB_TOKEN` reference resolves empty and gitleaks falls back
# to anonymous mode (rate-limited; misses some PRs).
secrets: inherit
Loading