From eaf5703709cdf3d51de62d4532b85d54b73dcba3 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 7 Aug 2026 12:45:51 +0100 Subject: [PATCH 1/2] chore(ci): SPDX headers on line 1 and Actions lockfile minted MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two estate gates, one change. **SPDX.** `governance / Workflow security linter` checks `head -1 | grep`, so a workflow carrying its identifier below a managed-by comment reports as missing one. Each file's OWN identifier is moved to line 1 — nothing is imposed, because repositories here are variously MPL-2.0, PMPL-1.0-or-later and AGPL-3.0-or-later and a default would mis-declare the minority. Licences seen here: MPL-2.0. **Lockfile.** `gh actions-lock` resolves each symbolic ref to a verified commit plus owner_id, repo_id and the transitive dependencies of composite actions — which is what OSSF Scorecard's Pinned-Dependencies check is asking for, and what an inline SHA cannot express. ⚠ Do NOT additionally SHA-pin inline. The mechanisms are mutually exclusive: `gh actions-lock` refuses a ref no tag or branch contains, so inline pinning REMOVES actions from the lockfile. Measured on hypatia 2026-08-07 — 40 inline pins caused 14 startup_failures and dropped 7 lockfile entries. Verified: all workflows parse, no duplicate identifiers, lockfile verify says "All 22 workflows have complete lockfile coverage.". --- .github/workflows/actions.lock | 145 ++++++++++++++++++ .github/workflows/affine-vscode-publish.yml | 3 +- .github/workflows/casket-pages.yml | 15 +- .github/workflows/ci.yml | 23 +-- .github/workflows/codeql.yml | 7 +- .github/workflows/coq-proof-gate.yml | 3 +- .../workflows/governance-baseline-impl.yml | 3 +- .github/workflows/governance-baseline.yml | 1 + .github/workflows/governance.yml | 3 +- .github/workflows/hypatia-scan.yml | 1 + .github/workflows/instant-sync.yml | 3 +- .github/workflows/mirror.yml | 1 + .github/workflows/pages.yml | 9 +- .github/workflows/panic-attack.yml | 7 +- .github/workflows/publish-jsr.yml | 5 +- .github/workflows/push-email-notify.yml | 3 +- .github/workflows/release.yml | 9 +- .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 3 +- .github/workflows/semgrep.yml | 5 +- .github/workflows/spark-theatre-gate.yml | 1 + .github/workflows/stdlib-naming.yml | 3 +- .github/workflows/workflow-linter.yml | 3 +- 23 files changed, 212 insertions(+), 45 deletions(-) create mode 100644 .github/workflows/actions.lock diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 00000000..23d161d8 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,145 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/affine-vscode-publish.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/casket-pages.yml': + - 'actions/cache@v6.1.0' + - 'actions/checkout@v7.0.1' + - 'actions/configure-pages@v6.0.0' + - 'actions/deploy-pages@v5.0.0' + - 'actions/upload-pages-artifact@v5.0.0' + - 'haskell-actions/setup@v2.11.0' + '.github/workflows/ci.yml': + - 'actions/checkout@v7.0.1' + - 'actions/setup-node@v7.0.0' + - 'actions/upload-artifact@v7.0.1' + '.github/workflows/codeql.yml': + - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.37.4' + '.github/workflows/coq-proof-gate.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/governance-baseline-impl.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/governance.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@v4.0.1' + '.github/workflows/pages.yml': + - 'actions/checkout@v7.0.1' + - 'actions/deploy-pages@v5.0.0' + - 'actions/upload-pages-artifact@v5.0.0' + '.github/workflows/panic-attack.yml': + - 'actions/checkout@v7.0.1' + - 'actions/upload-artifact@v7.0.1' + - 'dtolnay/rust-toolchain@master' + '.github/workflows/publish-jsr.yml': + - 'actions/checkout@v7.0.1' + - 'denoland/setup-deno@v2.0.5' + '.github/workflows/push-email-notify.yml': + - 'dawidd6/action-send-mail@v3.12.0' + '.github/workflows/release.yml': + - 'actions/attest-build-provenance@v4.1.1' + - 'actions/checkout@v7.0.1' + - 'ocaml/setup-ocaml@v3.7.0' + '.github/workflows/secret-scanner.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/semgrep.yml': + - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.37.4' + '.github/workflows/stdlib-naming.yml': + - 'actions/checkout@v7.0.1' + '.github/workflows/workflow-linter.yml': + - 'actions/checkout@v7.0.1' +dependencies: + 'actions/attest-build-provenance@v4.1.1': + ref: 'v4.1.1' + commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373' + owner_id: 44036562 + repo_id: 760702757 + uses: + - 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763' + 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763': + ref: 'v4.1.1' + commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763' + owner_id: 44036562 + repo_id: 760701061 + 'actions/cache@v6.1.0': + ref: 'v6.1.0' + commit: 'sha1-55cc8345863c7cc4c66a329aec7e433d2d1c52a9' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@v6.0.0': + ref: 'v6.0.0' + commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' + owner_id: 44036562 + repo_id: 513659658 + 'actions/deploy-pages@v5.0.0': + ref: 'v5.0.0' + commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + owner_id: 44036562 + repo_id: 438112499 + 'actions/setup-node@v7.0.0': + ref: 'v7.0.0' + commit: 'sha1-820762786026740c76f36085b0efc47a31fe5020' + owner_id: 44036562 + repo_id: 189476904 + 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': + ref: 'v7.0.0' + commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-artifact@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-043fb46d1a93c77aae656e7c1c64a875d1fc6a0a' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@v5.0.0': + ref: 'v5.0.0' + commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + 'dawidd6/action-send-mail@v3.12.0': + ref: 'v3.12.0' + commit: 'sha1-2e600f3776677e493bf0da7aaec39a586d19a5ed' + owner_id: 9713907 + repo_id: 222439721 + 'denoland/setup-deno@v2.0.5': + ref: 'v2.0.5' + commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed' + owner_id: 42048915 + repo_id: 356423100 + 'dtolnay/rust-toolchain@master': + ref: 'master' + commit: 'sha1-2c7215f132e9ebf062739d9130488b56d53c060c' + owner_id: 1940490 + repo_id: 260749683 + 'github/codeql-action@v4.37.4': + ref: 'v4.37.4' + commit: 'sha1-f205ea1c3313d32999d8d6a48b4f6530d4437b38' + owner_id: 9919 + repo_id: 259445878 + 'haskell-actions/setup@v2.11.0': + ref: 'v2.11.0' + commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' + owner_id: 75048950 + repo_id: 623796603 + 'ocaml/setup-ocaml@v3.7.0': + ref: 'v3.7.0' + commit: 'sha1-15d660006c1d3110d77c34b7faa3bddefe8b82f0' + owner_id: 1841483 + repo_id: 220799100 + 'peter-evans/repository-dispatch@v4.0.1': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' + owner_id: 18365890 + repo_id: 220359305 diff --git a/.github/workflows/affine-vscode-publish.yml b/.github/workflows/affine-vscode-publish.yml index 805ceeb6..92513051 100644 --- a/.github/workflows/affine-vscode-publish.yml +++ b/.github/workflows/affine-vscode-publish.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Publishes @hyperpolymath/affine-vscode to npm on a scoped tag push. # @@ -33,7 +34,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Verify tag matches package version working-directory: packages/affine-vscode run: | diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 23bfa849..acdd6fa5 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: GitHub Pages on: @@ -49,19 +50,19 @@ jobs: timeout-minutes: 10 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout casket-ssg - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/casket-ssg path: .casket-ssg - name: Setup GHCup - uses: haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553 # v2 + uses: haskell-actions/setup@v2.11.0 with: ghc-version: '9.8.2' cabal-version: '3.10' - name: Cache Cabal - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v4 + uses: actions/cache@v6.1.0 with: path: | ~/.cabal/packages @@ -102,7 +103,7 @@ jobs: fi cd .casket-ssg && cabal run casket-ssg -- build ../site ../_site - name: Setup Pages - uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0 + uses: actions/configure-pages@v6.0.0 with: # Self-provision Pages on first run instead of failing with # 404 ("Get Pages site failed"). The repo had Pages disabled @@ -113,7 +114,7 @@ jobs: # this. enablement: true - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -127,4 +128,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 + uses: actions/deploy-pages@v5.0.0 diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 71946834..b6302688 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Standalone CI: no dependency on third-party actions or external-repo @@ -34,7 +35,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: # Full history so the soundness-ledger gate (property 4) can resolve # :ground-truth-sha: and diff soundness paths against it. A shallow @@ -51,7 +52,7 @@ jobs: || opam switch create . ocaml-base-compiler.4.14.2 --no-install --yes opam exec -- ocaml -version - name: Set up Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v4 + uses: actions/setup-node@v7.0.0 with: node-version: "20" - name: Install dependencies @@ -117,7 +118,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up OCaml toolchain (self-hosted; replaces ocaml/setup-ocaml) run: | sudo apt-get update @@ -146,7 +147,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up OCaml toolchain (self-hosted; replaces ocaml/setup-ocaml) run: | sudo apt-get update @@ -182,7 +183,7 @@ jobs: } >> "$GITHUB_STEP_SUMMARY" - name: Upload bench log if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4 + uses: actions/upload-artifact@v7.0.1 with: name: bench-output path: bench-output.log @@ -196,7 +197,7 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up OCaml toolchain (self-hosted; replaces ocaml/setup-ocaml) run: | sudo apt-get update @@ -231,7 +232,7 @@ jobs: } >> "$GITHUB_STEP_SUMMARY" - name: Upload coverage HTML if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v4 + uses: actions/upload-artifact@v7.0.1 with: name: coverage-html path: _coverage @@ -256,9 +257,9 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v4 + uses: actions/setup-node@v7.0.0 with: node-version: "20" - name: Install test runner dependencies @@ -301,9 +302,9 @@ jobs: steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up Node.js - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v4 + uses: actions/setup-node@v7.0.0 with: node-version: "20" - name: Install tree-sitter CLI diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 672e4579..ca12c986 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: CodeQL Security Analysis on: @@ -35,13 +36,13 @@ jobs: build-mode: none steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/init@v4.37.4 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/analyze@v4.37.4 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/coq-proof-gate.yml b/.github/workflows/coq-proof-gate.yml index 88fb8c65..0f3f4fab 100644 --- a/.github/workflows/coq-proof-gate.yml +++ b/.github/workflows/coq-proof-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Coq/Rocq proof gate for the `formal/` mechanised-metatheory track (issue #513). # @@ -42,7 +43,7 @@ jobs: image: coqorg/coq@sha256:e50d77c4c5a9aa0d76ae1b343d79c5f922da3a75054b79c5dc635895438e4674 options: --user root steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 # The coqorg images install Coq into an opam switch owned by the `coq` # user and put it on PATH via an ENTRYPOINT wrapper. GitHub Actions diff --git a/.github/workflows/governance-baseline-impl.yml b/.github/workflows/governance-baseline-impl.yml index 79bcf2d5..53050fac 100644 --- a/.github/workflows/governance-baseline-impl.yml +++ b/.github/workflows/governance-baseline-impl.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Local reusable backing `governance-baseline.yml`. Its single job is named @@ -25,7 +26,7 @@ jobs: timeout-minutes: 5 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Validate .hypatia-baseline.json (if present) run: | set -euo pipefail diff --git a/.github/workflows/governance-baseline.yml b/.github/workflows/governance-baseline.yml index 0fda2d02..4652cc61 100644 --- a/.github/workflows/governance-baseline.yml +++ b/.github/workflows/governance-baseline.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Required-check bridge: re-emits the estate-standard governance check context diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 89f55342..f0358e07 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Standalone governance gate. Previously a thin caller of @@ -26,7 +27,7 @@ jobs: timeout-minutes: 5 steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: fetch-depth: 0 - name: Fetch base ref (DOC-FORMAT delta) diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index e1fdc61c..bd977435 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. # See standards#191 for the reusable's purpose and design. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index c5e99b75..2271b2c1 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync @@ -22,7 +23,7 @@ jobs: if: ${{ vars.FARM_DISPATCH_ENABLED == 'true' }} steps: - name: Trigger Propagation - uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3 + uses: peter-evans/repository-dispatch@v4.0.1 with: token: ${{ secrets.FARM_DISPATCH_TOKEN }} repository: hyperpolymath/.git-private-farm diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 6bd847da..77f087ac 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Mirror to Git Forges on: diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index a1a1aa3c..c8d313a9 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: GitHub Pages (Ddraig SSG) on: @@ -19,9 +20,9 @@ jobs: image: ghcr.io/stefan-hoeck/idris2-pack@sha256:f0758996a931fb35d9ecb1de273c4d59dabe2a09b433afc7e357f65a08b7e1ff steps: - name: Checkout Site - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Checkout Ddraig SSG - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: repository: hyperpolymath/ddraig-ssg path: .ddraig-ssg @@ -38,7 +39,7 @@ jobs: fi ./.ddraig-ssg/build/exec/ddraig build src _site https://hyperpolymath.github.io/${GITHUB_REPOSITORY#*/} - name: Upload artifact - uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0 + uses: actions/upload-pages-artifact@v5.0.0 with: path: '_site' deploy: @@ -51,4 +52,4 @@ jobs: steps: - name: Deploy to GitHub Pages id: deployment - uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0 + uses: actions/deploy-pages@v5.0.0 diff --git a/.github/workflows/panic-attack.yml b/.github/workflows/panic-attack.yml index 4badd466..2efd5166 100644 --- a/.github/workflows/panic-attack.yml +++ b/.github/workflows/panic-attack.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # panic-attack.yml — estate compliance scanner, weekly schedule. # @@ -31,11 +32,11 @@ jobs: timeout-minutes: 10 steps: - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 with: persist-credentials: false - name: Install Rust toolchain (stable) - uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # stable + uses: dtolnay/rust-toolchain@master with: toolchain: stable - name: Install panic-attacker @@ -78,7 +79,7 @@ jobs: } >> "$GITHUB_STEP_SUMMARY" - name: Upload log artifact if: always() - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + uses: actions/upload-artifact@v7.0.1 with: name: panic-attack-log path: panic-attack.log diff --git a/.github/workflows/publish-jsr.yml b/.github/workflows/publish-jsr.yml index 9f39b08e..8c9b1d0c 100644 --- a/.github/workflows/publish-jsr.yml +++ b/.github/workflows/publish-jsr.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # INT-04 (#181): publish the JS runtime packages to JSR (Deno/JSR-first # per CLAUDE.md). Scaffolded by packaging prep — it is **manual-only** @@ -39,8 +40,8 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - - uses: denoland/setup-deno@v2 + - uses: actions/checkout@v7.0.1 + - uses: denoland/setup-deno@v2.0.5 with: deno-version: v2.x - name: Resolve package directory diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 3421eddd..0160dc25 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; @@ -15,7 +16,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Send push notification email - uses: dawidd6/action-send-mail@2e600f3776677e493bf0da7aaec39a586d19a5ed # pinned + uses: dawidd6/action-send-mail@v3.12.0 with: server_address: ${{ secrets.SMTP_HOST }} server_port: ${{ secrets.SMTP_PORT }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 26932c32..fabd7ea9 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Release (ADR-019 / #260 S2). On a `v*` tag: build the AffineScript @@ -33,7 +34,7 @@ jobs: timeout-minutes: 10 steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Create the release as a draft (idempotent) # Immutable releases (enabled on this repo) forbid adding assets to a # *published* release — the v0.2.0 build legs hit "HTTP 422: Cannot @@ -70,9 +71,9 @@ jobs: timeout-minutes: 10 steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Set up OCaml - uses: ocaml/setup-ocaml@15d660006c1d3110d77c34b7faa3bddefe8b82f0 # v3 + uses: ocaml/setup-ocaml@v3.7.0 with: ocaml-compiler: "5.1" - name: Install dependencies @@ -103,7 +104,7 @@ jobs: install -m 0755 _build/default/bin/main.exe \ "affinescript-${{ matrix.target }}" - name: Attest build provenance - uses: actions/attest-build-provenance@0f67c3f4856b2e3261c31976d6725780e5e4c373 # v4.1.1 + uses: actions/attest-build-provenance@v4.1.1 with: subject-path: 'affinescript-${{ matrix.target }}' - name: Upload the binary to the release diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 64ac2acf..abc2058b 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Scorecards supply-chain security diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 9d2a6e03..ea279d19 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # # Standalone secret scan. Previously a thin caller of @@ -24,6 +25,6 @@ jobs: timeout-minutes: 5 steps: - name: Checkout code - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + uses: actions/checkout@v7.0.1 - name: Run standalone secret scan run: ./tools/ci/secret-scan-standalone.sh diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index b81df9db..b38e6f23 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 name: Semgrep SAST on: @@ -24,13 +25,13 @@ jobs: container: image: semgrep/semgrep steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Run Semgrep run: semgrep scan --sarif --output=semgrep.sarif --config=auto . env: SEMGREP_APP_TOKEN: ${{ secrets.SEMGREP_APP_TOKEN }} - name: Upload SARIF - uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4 + uses: github/codeql-action/upload-sarif@v4.37.4 with: sarif_file: semgrep.sarif if: always() diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index cf4e758c..857da25b 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Estate SPARK Theatre Gate — thin caller of the reusable workflow in # hyperpolymath/standards (#135 / #141). Pinned by commit SHA per the diff --git a/.github/workflows/stdlib-naming.yml b/.github/workflows/stdlib-naming.yml index 919bc26b..c120eff4 100644 --- a/.github/workflows/stdlib-naming.yml +++ b/.github/workflows/stdlib-naming.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Stdlib naming convention check # @@ -27,7 +28,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Enforce lowercase .affine filenames in stdlib/ run: | BAD=$(find stdlib -maxdepth 1 -type f -name '*.affine' | grep -E '/stdlib/[A-Z]' || true) diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 6e8f6253..31493927 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,3 +1,4 @@ +# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter @@ -19,7 +20,7 @@ jobs: runs-on: ubuntu-latest timeout-minutes: 10 steps: - - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - uses: actions/checkout@v7.0.1 - name: Check SPDX headers run: | errors=0 From f93263dc7d4dbd6b1b9d217a5532c933094d076d Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 7 Aug 2026 13:22:25 +0100 Subject: [PATCH 2/2] fix(ci): SPDX identifier back to line 1, after the lockfile step MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `gh actions-lock` inserts `# This workflow is managed by gh actions-lock.` at line 1, which displaced the SPDX identifier moved there earlier in this branch. The linter greps `head -1` only, so the header read as missing again. Each file's OWN identifier is moved back to line 1 — nothing imposed. Files already correct are untouched, and any file carrying two identifiers aborts the change rather than guessing. --- .github/workflows/affine-vscode-publish.yml | 2 +- .github/workflows/casket-pages.yml | 2 +- .github/workflows/ci.yml | 2 +- .github/workflows/codeql.yml | 2 +- .github/workflows/coq-proof-gate.yml | 2 +- .github/workflows/governance-baseline-impl.yml | 2 +- .github/workflows/governance-baseline.yml | 2 +- .github/workflows/governance.yml | 2 +- .github/workflows/hypatia-scan.yml | 2 +- .github/workflows/instant-sync.yml | 2 +- .github/workflows/mirror.yml | 2 +- .github/workflows/pages.yml | 2 +- .github/workflows/panic-attack.yml | 2 +- .github/workflows/publish-jsr.yml | 2 +- .github/workflows/push-email-notify.yml | 2 +- .github/workflows/release.yml | 2 +- .github/workflows/scorecard.yml | 2 +- .github/workflows/secret-scanner.yml | 2 +- .github/workflows/semgrep.yml | 2 +- .github/workflows/spark-theatre-gate.yml | 2 +- .github/workflows/stdlib-naming.yml | 2 +- .github/workflows/workflow-linter.yml | 2 +- 22 files changed, 22 insertions(+), 22 deletions(-) diff --git a/.github/workflows/affine-vscode-publish.yml b/.github/workflows/affine-vscode-publish.yml index 92513051..92e397d7 100644 --- a/.github/workflows/affine-vscode-publish.yml +++ b/.github/workflows/affine-vscode-publish.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Publishes @hyperpolymath/affine-vscode to npm on a scoped tag push. # # This repo is Deno-first (see CLAUDE.md). The npm publish here is a diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index acdd6fa5..34410f8c 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages on: push: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b6302688..30390d71 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Standalone CI: no dependency on third-party actions or external-repo # reusable workflows. The OCaml toolchain is self-hosted via apt + opam diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index ca12c986..92b7a21c 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: push: diff --git a/.github/workflows/coq-proof-gate.yml b/.github/workflows/coq-proof-gate.yml index 0f3f4fab..d661b765 100644 --- a/.github/workflows/coq-proof-gate.yml +++ b/.github/workflows/coq-proof-gate.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Coq/Rocq proof gate for the `formal/` mechanised-metatheory track (issue #513). # # This gate is deliberately FAIL-CLOSED. It does NOT probe for the prover and diff --git a/.github/workflows/governance-baseline-impl.yml b/.github/workflows/governance-baseline-impl.yml index 53050fac..bb318dc1 100644 --- a/.github/workflows/governance-baseline-impl.yml +++ b/.github/workflows/governance-baseline-impl.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Local reusable backing `governance-baseline.yml`. Its single job is named # "Validate Hypatia baseline" so that, when called from a job with id diff --git a/.github/workflows/governance-baseline.yml b/.github/workflows/governance-baseline.yml index 4652cc61..36ae7130 100644 --- a/.github/workflows/governance-baseline.yml +++ b/.github/workflows/governance-baseline.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Required-check bridge: re-emits the estate-standard governance check context # `governance / Validate Hypatia baseline` on EVERY pull request. diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index f0358e07..c7cbcf49 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Standalone governance gate. Previously a thin caller of # `hyperpolymath/standards/.github/workflows/governance-reusable.yml@main`; diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index bd977435..29ff39c4 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. # See standards#191 for the reusable's purpose and design. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 2271b2c1..16846261 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync on: diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 77f087ac..46961e07 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: push: diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml index c8d313a9..3be681d6 100644 --- a/.github/workflows/pages.yml +++ b/.github/workflows/pages.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages (Ddraig SSG) on: push: diff --git a/.github/workflows/panic-attack.yml b/.github/workflows/panic-attack.yml index 2efd5166..4963443a 100644 --- a/.github/workflows/panic-attack.yml +++ b/.github/workflows/panic-attack.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # panic-attack.yml — estate compliance scanner, weekly schedule. # # Per docs/standards/PANIC-ATTACK.adoc: diff --git a/.github/workflows/publish-jsr.yml b/.github/workflows/publish-jsr.yml index 8c9b1d0c..54b8eb3f 100644 --- a/.github/workflows/publish-jsr.yml +++ b/.github/workflows/publish-jsr.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # INT-04 (#181): publish the JS runtime packages to JSR (Deno/JSR-first # per CLAUDE.md). Scaffolded by packaging prep — it is **manual-only** # (`workflow_dispatch`) and does NOT run on push/merge. The owner diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 0160dc25..b69c87f3 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index fabd7ea9..ae7f1758 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Release (ADR-019 / #260 S2). On a `v*` tag: build the AffineScript # compiler for each supported platform, attach the raw per-platform diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index abc2058b..7b610583 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Scorecards supply-chain security on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index ea279d19..a44ac3e4 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # # Standalone secret scan. Previously a thin caller of # `hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml` diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index b38e6f23..b334955f 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Semgrep SAST on: push: diff --git a/.github/workflows/spark-theatre-gate.yml b/.github/workflows/spark-theatre-gate.yml index 857da25b..61ca627a 100644 --- a/.github/workflows/spark-theatre-gate.yml +++ b/.github/workflows/spark-theatre-gate.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Estate SPARK Theatre Gate — thin caller of the reusable workflow in # hyperpolymath/standards (#135 / #141). Pinned by commit SHA per the # estate action-pinning policy. Regenerate the pin only when the reusable diff --git a/.github/workflows/stdlib-naming.yml b/.github/workflows/stdlib-naming.yml index c120eff4..cdb22082 100644 --- a/.github/workflows/stdlib-naming.yml +++ b/.github/workflows/stdlib-naming.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Stdlib naming convention check # # Enforces: stdlib/*.affine filenames are lowercase. diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 31493927..b42275c6 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,5 +1,5 @@ -# This workflow is managed by gh actions-lock. # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter on: