Commit 5ee2565
fix(ci): SHA-pin scan-and-report steps so sha_pinning callers can start it (#209)
## Why
`hyperpolymath/echidna` has `sha_pinning_required: true`. Its **Security
Scan** calls this reusable and has ended in `startup_failure` since the
pinning rule landed. The run page for echidna run 36185528155 says:
> The actions actions/checkout@v4.3.1, dtolnay/rust-toolchain@v1, and
swatinem/rust-cache@v2.8.2 are not allowed in hyperpolymath/echidna …
`actions/checkout` is GitHub-owned, and echidna has
`github_owned_allowed: true`. So the allow-list is not the cause; the
tag refs are.
A caller's own `actions.lock` does not cover a cross-repo callee's
steps, so the callee has to carry commit SHAs itself.
**Positive control:** echidna's Scorecard and Secret Scanner succeed
through `standards/*-reusable.yml@571cc73`, whose steps are written
`@<sha> # vX`.
#201 had pinned these steps. #203's `gh actions-lock` rewrite turned
them back into tags.
## Change
- Pins the three steps:
- `actions/checkout@3d3c42e5` (v7.0.1)
- `dtolnay/rust-toolchain@02cb101e` (v1)
- `Swatinem/rust-cache@6323deb1` (v2.9.2)
- Updates the `actions.lock` entry by hand to match, because `gh
actions-lock` write mode de-pins the steps again.
- Changes `toolchain: v1` to `stable`. `v1` is the action's tag, not a
Rust toolchain.
- Leaves one "managed by gh actions-lock" line after SPDX, instead of
three.
## Verification
`gh actions-lock --no-fix --json`:
- This file: 0 errors, and 3 `sha-as-ref` warnings (the same advisory
the standards reusables carry).
- Repo total: 67 findings on main, 66 with this change, none new. The
rest of the lock was already stale on main; that is out of scope here.
## Also: unblocks CodeQL (second commit)
`codeql.yml` was bumped to `checkout@v7.0.1` / `codeql-action@v4.38.2`,
but its `actions.lock` entry still pinned v6.0.2 / v4.34.0. So every
CodeQL run since `5e75753` died at startup with "Invalid lockfile".
CodeQL is main's only required check, so no PR could merge.
The second commit re-keys that entry, using commit SHAs resolved from
the tags. On this head, CodeQL goes from `startup_failure` to `success`.
`--no-fix` repo errors go from 64 to 58.
## Pre-existing reds (deferred)
These contexts are red identically on `main` `5e75753`. This PR
introduces none of them. They are deferred to #211: `chapel-ci`,
`Dogfood Gate`, `Dependency Review`, `bridge-gate`, `cargo-audit.yml`,
`coverage.yml`, `release.yml`, `Governance` (Workflow security linter,
Actions lockfile verify), `Secret Scanner` (gitleaks), `Rust CI`
(clippy, fmt).
The failing check contexts are each deferred to #211: `scan / gitleaks`
(#211), `rust-ci / Cargo check + clippy + fmt` (#211), `governance /
Workflow security linter` (#211), `governance / Actions lockfile verify`
(#211).
## Follow-up
echidna's `security-scan.yml` has to bump its callee pin to this merge
commit (echidna#310).
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>1 parent 5e75753 commit 5ee2565
2 files changed
Lines changed: 22 additions & 14 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
28 | | - | |
| 27 | + | |
| 28 | + | |
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
64 | | - | |
65 | | - | |
66 | | - | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
| |||
102 | 102 | | |
103 | 103 | | |
104 | 104 | | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
105 | 110 | | |
106 | 111 | | |
107 | 112 | | |
| |||
144 | 149 | | |
145 | 150 | | |
146 | 151 | | |
147 | | - | |
148 | | - | |
149 | | - | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
150 | 155 | | |
151 | 156 | | |
152 | 157 | | |
| |||
199 | 204 | | |
200 | 205 | | |
201 | 206 | | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
202 | 212 | | |
203 | 213 | | |
204 | 214 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | 1 | | |
3 | 2 | | |
4 | | - | |
5 | 3 | | |
6 | 4 | | |
7 | 5 | | |
| |||
38 | 36 | | |
39 | 37 | | |
40 | 38 | | |
41 | | - | |
| 39 | + | |
42 | 40 | | |
43 | 41 | | |
44 | | - | |
| 42 | + | |
45 | 43 | | |
46 | | - | |
| 44 | + | |
47 | 45 | | |
48 | 46 | | |
49 | | - | |
| 47 | + | |
50 | 48 | | |
51 | 49 | | |
52 | 50 | | |
| |||
0 commit comments