Skip to content

fix(ci): adopt Actions dependency lockfile (estate startup_failure remediation) - #91

Merged
hyperpolymath merged 4 commits into
mainfrom
ci/actions-lockfile
Aug 4, 2026
Merged

fix(ci): adopt Actions dependency lockfile (estate startup_failure remediation)#91
hyperpolymath merged 4 commits into
mainfrom
ci/actions-lockfile

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Estate sweep: this repo's every workflow has been startup_failure under GitHub's workflow-lockfile enforcement. Applies the template proven on haec (#46/#48) and echidna (#341): actions.lock, SPDX-first header order, hand-added entries for tool-skipped workflows, standards reusables re-pinned past the standards lockfile boundary (5a597720), illegal timeout-minutes stripped from reusable jobs, lockfile-aware SHA-pin lint.

The PR's own check runs are the test: executing checks (even failures) = enforcement satisfied.

🤖 Generated with Claude Code

…mediation)

Estate-wide sweep applying the haec-proven template (haec#46/#48,
echidna#341): actions.lock via gh actions-lock; SPDX kept on line 1
above the locker marker; hand-added lockfile entries for workflows the
tool skips (reusable-only / zero-dep); standards reusables re-pinned to
fcb8669169b4 (first standards ref carrying its own lockfile);
illegal timeout-minutes stripped from reusable-caller jobs;
SHA-pin lint made lockfile-aware.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gitar-bot

gitar-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Adopts the Actions dependency lockfile across all workflows and re-pins reusable components to satisfy strict workflow enforcement. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Important

Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot
gitar-bot Bot enabled auto-merge (squash) August 4, 2026 04:14
gitar-bot[bot]
gitar-bot Bot previously approved these changes Aug 4, 2026

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Aug 4, 2026
…lint)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
At standards >= fcb8669 the governance/hypatia/mirror/scorecard
reusables declare actions: read (hypatia adds security-events: write;
scorecard adds id-token/security-events write). A reusable requesting
more than its caller grants is a startup_failure — the third
enforcement layer after the lockfile and the caller entries.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
auto-merge was automatically disabled August 4, 2026 04:34

Pull request was closed

@hyperpolymath hyperpolymath reopened this Aug 4, 2026
@hyperpolymath
hyperpolymath enabled auto-merge (squash) August 4, 2026 04:53
…ermission union

Computed from each called reusable's workflow+job permissions at
bd0df9e — the previous pass only covered four wrapper names and missed
e.g. spark-theatre-gate (requests actions: read).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit 275946b into main Aug 4, 2026
35 of 46 checks passed
@hyperpolymath
hyperpolymath deleted the ci/actions-lockfile branch August 4, 2026 09:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant