From 4d1dc1fa5b3c47dc77abe88bd8829d7a209a495d Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 15:35:36 +0100 Subject: [PATCH] chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate The governance "Actions lockfile verify" gate requires .github/workflows/actions.lock from 2026-10-01. Every ref here is already SHA-pinned; `gh actions-lock --no-narrow` (v0.1.6) records those same SHAs and their transitive composite deps, with no ref rewritten. The tool's "managed by gh actions-lock" banner is placed on line 2 so SPDX stays on line 1. Verified locally: the gate script at the pinned standards SHA passes with LOCK_TODAY=2026-10-01. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_019aa9y32JcBuZ85KXe2jb8R --- .github/workflows/actions.lock | 93 +++++++++++++++++++++++++ .github/workflows/boj-build.yml | 1 + .github/workflows/casket-pages.yml | 1 + .github/workflows/codeql.yml | 1 + .github/workflows/dogfood-gate.yml | 1 + .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/instant-sync.yml | 1 + .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/mirror.yml | 1 + .github/workflows/push-email-notify.yml | 1 + .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + 14 files changed, 106 insertions(+) create mode 100644 .github/workflows/actions.lock diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 0000000..fad7400 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,93 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/boj-build.yml': + - 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' + '.github/workflows/casket-pages.yml': + - 'actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d' + - 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + - 'actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b' + - 'haskell-actions/setup@f9150cb1d140e9a9271700670baa38991e6fa25c' + '.github/workflows/codeql.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745' + '.github/workflows/dogfood-gate.yml': + - 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5' + - 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + - 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562' + '.github/workflows/instant-sync.yml': + - 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697' + '.github/workflows/push-email-notify.yml': + - 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' +dependencies: + 'actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7': + ref: 'v5.0.4' + commit: 'sha1-668228422ae6a00e4ad889ee87cd7109ec5666a7' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5': + ref: 'v4.3.1' + commit: 'sha1-34e114876b0b11c390a56381ad16ebd13914f8d5' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d': + ref: 'v6.0.0' + commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' + owner_id: 44036562 + repo_id: 513659658 + 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128': + ref: 'v5.0.0' + commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + owner_id: 44036562 + repo_id: 438112499 + 'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02': + ref: 'v4.6.2' + commit: 'sha1-ea165f8d65b6e75b540449e92b4886f43607fa02' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@7b1f4a764d45c48632c6b24a0339c27f5614fb0b': + ref: 'v4.0.0' + commit: 'sha1-7b1f4a764d45c48632c6b24a0339c27f5614fb0b' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02' + 'github/codeql-action@c6f931105cb2c34c8f901cc885ba1e2e259cf745': + ref: 'v4.34.0' + commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745' + owner_id: 9919 + repo_id: 259445878 + 'haskell-actions/setup@f9150cb1d140e9a9271700670baa38991e6fa25c': + ref: 'v2.10.3' + commit: 'sha1-f9150cb1d140e9a9271700670baa38991e6fa25c' + owner_id: 75048950 + repo_id: 623796603 + 'hyperpolymath/deed-ecosystem@aa4b836bd969df2bc58128cb8e3d20bbc88d5e79': + ref: 'main' + commit: 'sha1-aa4b836bd969df2bc58128cb8e3d20bbc88d5e79' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@89f3c2702f4f650a92aa7411502f38da06abd562': + ref: 'main' + commit: 'sha1-89f3c2702f4f650a92aa7411502f38da06abd562' + owner_id: 6759885 + repo_id: 1275650185 + 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7': + ref: 'v0.2.0' + commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + owner_id: 6759885 + repo_id: 1352485172 + 'peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697': + ref: 'v4.0.1' + commit: 'sha1-28959ce8df70de7be546dd1250a005dd32156697' + owner_id: 18365890 + repo_id: 220359305 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index 9e927a9..f3141ca 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: BoJ Server Build Trigger on: push: diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 67069a9..0e5701c 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages on: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 92b8d7d..bf067ac 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 07b3242..d27a558 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) # # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 89ee17c..a299ac1 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # governance.yml — single wrapper calling the shared estate governance bundle # in hyperpolymath/standards instead of carrying per-repo copies. # diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 86dabd8..3042367 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Thin wrapper around hyperpolymath/standards hypatia-scan-reusable.yml. # See standards#191 for the reusable's purpose and design. diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 0f86f6c..a1909e2 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..fc79947 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Label Triage # Classify newly-filed issues against the estate label taxonomy. diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..af34c6b 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Labels # Applies the canonical estate label set from .github/labels.json. diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 07f0d6a..709fc91 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 0689291..80c6942 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index f3ee831..bfd0967 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Scorecards supply-chain security on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index e5d29b2..efac235 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Secret Scanner on: