Skip to content

Commit 41b0217

Browse files
hyperpolymathclaude
andcommitted
fix(ci): unbreak workflow YAML and add a complete actions.lock
Remediates GitHub Workflow Dependency Locking (public preview), which rejects runs at startup_failure with zero jobs and no logs. See hyperpolymath/standards#657. Five steps, in order, because each blocks the next: 1. Unbroke any workflow whose `permissions:` carried a scalar with an indented mapping under it - blind-permissions-insertion damage. This matters beyond the one file: gh actions-lock refuses to run when ANY workflow in the repo fails to parse, so the repo could never acquire a lockfile and could never self-heal. 2. Repinned hyperpolymath/standards reusables off commits that have no actions.lock. The rejection requires the CALLEE to be covered at the pinned SHA, which is unsatisfiable at a pre-lockfile commit. 3. Generated the lockfile with gh actions-lock. 4. Hand-added the reusable-workflow caller entries the tool omits, as '<path>': []. Measured across 218 repos: P(startup_failure | has lockfile) = 91.7% vs 15.8% without, because every workflow a lockfile OMITS is rejected. A PARTIAL lock is worse than none - running gh actions-lock and stopping there is how this outage spread. 5. Restored SPDX-License-Identifier to line 1, which the tool displaces with its own banner and which the workflow-security linter greps with head -1. Verified before push: 0 unparseable workflows, lockfile covers every workflow with no omissions, SPDX on line 1 in every file. Proven on hyperpolymath/anamnesis: 6 of 6 workflows dead -> 0 startup_failure, 13 running. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
1 parent c0627cf commit 41b0217

16 files changed

Lines changed: 36 additions & 18 deletions

.github/workflows/actions.lock

Lines changed: 17 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ workflows:
1010
- 'google/clusterfuzzlite@v1'
1111
'.github/workflows/codeql.yml':
1212
- 'actions/checkout@v7.0.1'
13-
- 'github/codeql-action@v4.37.3'
13+
- 'github/codeql-action@v4.37.7'
1414
'.github/workflows/deno-ci.yml': []
1515
'.github/workflows/governance.yml': []
1616
'.github/workflows/hypatia-scan.yml': []
@@ -24,27 +24,27 @@ workflows:
2424
'.github/workflows/proofs.yml':
2525
- 'actions/checkout@v7.0.1'
2626
'.github/workflows/publish-container.yml':
27-
- 'actions/attest-build-provenance@v4.1.1'
27+
- 'actions/attest-build-provenance@v4.2.2'
2828
- 'actions/checkout@v7.0.1'
2929
- 'docker/build-push-action@v7.3.0'
30-
- 'docker/login-action@v4.5.2'
30+
- 'docker/login-action@v4.6.0'
3131
- 'docker/metadata-action@v6.2.0'
3232
'.github/workflows/push-email-notify.yml':
3333
- 'dawidd6/action-send-mail@v3.12.0'
3434
'.github/workflows/rust-ci.yml': []
3535
'.github/workflows/scorecard.yml': []
3636
'.github/workflows/secret-scanner.yml': []
3737
dependencies:
38-
'actions/attest-build-provenance@v4.1.1':
39-
ref: 'v4.1.1'
40-
commit: 'sha1-0f67c3f4856b2e3261c31976d6725780e5e4c373'
38+
'actions/attest-build-provenance@v4.2.2':
39+
ref: 'v4.2.2'
40+
commit: 'sha1-4d101475d8b20a2381f78447822ac1eab6504dd8'
4141
owner_id: 44036562
4242
repo_id: 760702757
4343
uses:
44-
- 'actions/attest@a1948c3f048ba23858d222213b7c278aabede763'
45-
'actions/attest@a1948c3f048ba23858d222213b7c278aabede763':
46-
ref: 'v4.1.1'
47-
commit: 'sha1-a1948c3f048ba23858d222213b7c278aabede763'
44+
- 'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d'
45+
'actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d':
46+
ref: 'v4.2.1'
47+
commit: 'sha1-508db95dd578ae2727ebd6217d5ba78e4fbda05d'
4848
owner_id: 44036562
4949
repo_id: 760701061
5050
'actions/checkout@v7.0.1':
@@ -71,27 +71,27 @@ dependencies:
7171
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
7272
'dawidd6/action-send-mail@v3.12.0':
7373
ref: 'v3.12.0'
74-
commit: 'sha1-12335b969ae3fb71bee5f2c6b829744261aec34c'
74+
commit: 'sha1-94de994a9f6fffee200243214e17002e2920bb59'
7575
owner_id: 9713907
7676
repo_id: 222439721
7777
'docker/build-push-action@v7.3.0':
7878
ref: 'v7.3.0'
7979
commit: 'sha1-53b7df96c91f9c12dcc8a07bcb9ccacbed38856a'
8080
owner_id: 5429470
8181
repo_id: 241092383
82-
'docker/login-action@v4.5.2':
83-
ref: 'v4.5.2'
84-
commit: 'sha1-371161bbe7024a29a25c5e19bfcbc0804fe9ad2c'
82+
'docker/login-action@v4.6.0':
83+
ref: 'v4.6.0'
84+
commit: 'sha1-dbcb813823bdd20940b903addbd779551569679f'
8585
owner_id: 5429470
8686
repo_id: 287743349
8787
'docker/metadata-action@v6.2.0':
8888
ref: 'v6.2.0'
8989
commit: 'sha1-dc802804100637a589fabce1cb79ff13a1411302'
9090
owner_id: 5429470
9191
repo_id: 306769011
92-
'github/codeql-action@v4.37.3':
93-
ref: 'v4.37.3'
94-
commit: 'sha1-e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81'
92+
'github/codeql-action@v4.37.7':
93+
ref: 'v4.37.7'
94+
commit: 'sha1-ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd'
9595
owner_id: 9919
9696
repo_id: 259445878
9797
'google/clusterfuzzlite@v1':

.github/workflows/cflite_batch.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: ClusterFuzzLite batch fuzzing
45
on:
56
schedule:

.github/workflows/cflite_pr.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: ClusterFuzzLite PR fuzzing
45
on:
56
pull_request:

.github/workflows/codeql.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: CodeQL Security Analysis
45

56
on:

.github/workflows/deno-ci.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
# Thin wrapper around the estate-wide reusable Deno CI bundle.
45
# See: hyperpolymath/standards/.github/workflows/deno-ci-reusable.yml
56
name: Deno CI
@@ -14,6 +15,7 @@ concurrency:
1415
cancel-in-progress: true
1516

1617
permissions:
18+
actions: read
1719
contents: read
1820

1921
jobs:

.github/workflows/governance.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
# governance.yml — single wrapper calling the shared estate governance bundle
45
# in hyperpolymath/standards instead of carrying per-repo copies.
56
#

.github/workflows/hypatia-scan.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
# Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml.
45
# See standards#191 for the reusable's purpose and design.
56

.github/workflows/language-policy.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: Language Policy Enforcement
45
on:
56
push:

.github/workflows/mirror.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: Mirror to Git Forges
45

56
on:

.github/workflows/pages.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
# SPDX-License-Identifier: MPL-2.0
22
# This workflow is managed by gh actions-lock.
3+
# This workflow is managed by gh actions-lock.
34
name: GitHub Pages (Ddraig SSG)
45
on:
56
push:

0 commit comments

Comments
 (0)