Skip to content

Workflow security linter red on main: actions.lock pins haskell-actions/setup v2.12.0, casket-pages.yml uses v2.12.1 #113

Description

@hyperpolymath

governance / Workflow security linter fails on main (and so on every PR) because of the lockfile, not the PR's code. gh actions-lock --no-fix reports:

  • casket-pages.yml uses haskell-actions/setup@v2.12.1, but actions.lock pins v2.12.0. This looks like a dependency bump that didn't refresh the lockfile.
  • Unused lockfile entries: haskell-actions/setup@v2.12.0, and github/codeql-action@b96794f… (in codeql.yml and hypatia-scan.yml).

Why it wasn't fixed in #112: running gh actions-lock (fix mode) also rewrites codeql.yml and hypatia-scan.yml. It replaces the deliberately held SHA pin github/codeql-action/...@2892aa5… # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with the tag @v4.38.2, which removes the hold and its comment (see #100, #104). That's an owner decision, not a drive-by change.

Acceptance criteria

  • gh actions-lock --no-fix reports no errors on main.
  • The CodeQL pin stays as the owner intends: either the held SHA with its comment preserved (refresh only the haskell entry), or an explicit decision to move to v4.38.2.
  • governance / Workflow security linter is green on main.

Surfaced while preparing #112.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions