From a30f2ce9381a0aad0633bf6bf94f08f04b119428 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:01:53 +0100 Subject: [PATCH 1/2] fix(ci): bump Security Scan callee to SHA-pinned scan-and-report echidna sets sha_pinning_required, so the panic-attack reusable it called at 27b3d93 was refused at startup: that callee's steps were tag refs. The callee now pins its steps by SHA (hyperpolymath/panic-attack#209, merged as 5ee2565). Refs #310 Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8 --- .github/workflows/security-scan.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/security-scan.yml b/.github/workflows/security-scan.yml index 01a43325..57da9683 100644 --- a/.github/workflows/security-scan.yml +++ b/.github/workflows/security-scan.yml @@ -24,6 +24,6 @@ permissions: jobs: scan: - uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@27b3d93b11fbfc03cee695e791904d741ce2b24b # main 2026-07-07 (skip dispatch without VERISIMDB_PAT) + uses: hyperpolymath/panic-attack/.github/workflows/scan-and-report.yml@5ee25658c9f3ef54beaa911e77fbb0c823b358fc # main 2026-10-01 panic-attack#209: SHA-pinned steps (skip dispatch without VERISIMDB_PAT) secrets: VERISIMDB_PAT: ${{ secrets.VERISIMDB_PAT }} From cf51b64b62521d807d84530c12b52dfcc35b4990 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 1 Oct 2026 12:01:53 +0100 Subject: [PATCH 2/2] fix(ci): re-key codeql.yml lock entry to v4.38.1 codeql.yml uses github/codeql-action@v4.38.1, but its actions.lock entry still pinned v4.38.0, so every CodeQL run died at startup. Re-keyed by hand to the dereferenced tag commit 1c5b6756 (gh actions-lock write mode de-pins). --no-fix findings for codeql.yml: 3 -> 0; all other findings unchanged. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8 --- .github/workflows/actions.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index bef74047..a8bd4490 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -27,7 +27,7 @@ workflows: - 'swatinem/rust-cache@v2.9.2' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' + - 'github/codeql-action@v4.38.1' '.github/workflows/container-ci.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dogfood-gate.yml': @@ -144,9 +144,9 @@ dependencies: commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de' owner_id: 1940490 repo_id: 260749683 - 'github/codeql-action@v4.38.0': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@v4.38.1': + ref: 'v4.38.1' + commit: 'sha1-1c5b675653bb5c22dbe9b12b556ec555138e09fd' owner_id: 9919 repo_id: 259445878 'google/clusterfuzzlite@v1':