Skip to content

governance / Workflow security linter fails on main: .github/workflows/actions.lock flagged as unpinned action #221

Description

@hyperpolymath

The non-required check governance / Workflow security linter fails on main (4341d6e) and on every PR, independent of the PR's diff (seen on #219).

Output: ERROR: Found unpinned actions: -> .github/workflows/actions.lock:59: uses:. The linter greps every file under .github/workflows/, including the actions.lock file, which is not a workflow.

Acceptance criteria

  • Either restrict the linter's grep to *.yml/*.yaml workflow files, or fix the entry at actions.lock:59.
  • governance / Workflow security linter passes on main.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaves incorrectlycicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatesgovernancePolicy, rulesets, standards, compliance, and their enforcement

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions