governance / Workflow security linter fails on main (and so on every PR) because of the lockfile, not the PR's code. gh actions-lock --no-fix reports:
casket-pages.yml uses haskell-actions/setup@v2.12.1, but actions.lock pins v2.12.0. This looks like a dependency bump that didn't refresh the lockfile.
- Unused lockfile entries:
haskell-actions/setup@v2.12.0, and github/codeql-action@b96794f… (in codeql.yml and hypatia-scan.yml).
Why it wasn't fixed in #112: running gh actions-lock (fix mode) also rewrites codeql.yml and hypatia-scan.yml. It replaces the deliberately held SHA pin github/codeql-action/...@2892aa5… # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) with the tag @v4.38.2, which removes the hold and its comment (see #100, #104). That's an owner decision, not a drive-by change.
Acceptance criteria
Surfaced while preparing #112.
governance / Workflow security linterfails onmain(and so on every PR) because of the lockfile, not the PR's code.gh actions-lock --no-fixreports:casket-pages.ymluseshaskell-actions/setup@v2.12.1, butactions.lockpinsv2.12.0. This looks like a dependency bump that didn't refresh the lockfile.haskell-actions/setup@v2.12.0, andgithub/codeql-action@b96794f…(incodeql.ymlandhypatia-scan.yml).Why it wasn't fixed in #112: running
gh actions-lock(fix mode) also rewritescodeql.ymlandhypatia-scan.yml. It replaces the deliberately held SHA pingithub/codeql-action/...@2892aa5… # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)with the tag@v4.38.2, which removes the hold and its comment (see #100, #104). That's an owner decision, not a drive-by change.Acceptance criteria
gh actions-lock --no-fixreports no errors onmain.v4.38.2.governance / Workflow security linteris green onmain.Surfaced while preparing #112.