Skip to content

Commit 5ee2565

Browse files
fix(ci): SHA-pin scan-and-report steps so sha_pinning callers can start it (#209)
## Why `hyperpolymath/echidna` has `sha_pinning_required: true`. Its **Security Scan** calls this reusable and has ended in `startup_failure` since the pinning rule landed. The run page for echidna run 36185528155 says: > The actions actions/checkout@v4.3.1, dtolnay/rust-toolchain@v1, and swatinem/rust-cache@v2.8.2 are not allowed in hyperpolymath/echidna … `actions/checkout` is GitHub-owned, and echidna has `github_owned_allowed: true`. So the allow-list is not the cause; the tag refs are. A caller's own `actions.lock` does not cover a cross-repo callee's steps, so the callee has to carry commit SHAs itself. **Positive control:** echidna's Scorecard and Secret Scanner succeed through `standards/*-reusable.yml@571cc73`, whose steps are written `@<sha> # vX`. #201 had pinned these steps. #203's `gh actions-lock` rewrite turned them back into tags. ## Change - Pins the three steps: - `actions/checkout@3d3c42e5` (v7.0.1) - `dtolnay/rust-toolchain@02cb101e` (v1) - `Swatinem/rust-cache@6323deb1` (v2.9.2) - Updates the `actions.lock` entry by hand to match, because `gh actions-lock` write mode de-pins the steps again. - Changes `toolchain: v1` to `stable`. `v1` is the action's tag, not a Rust toolchain. - Leaves one "managed by gh actions-lock" line after SPDX, instead of three. ## Verification `gh actions-lock --no-fix --json`: - This file: 0 errors, and 3 `sha-as-ref` warnings (the same advisory the standards reusables carry). - Repo total: 67 findings on main, 66 with this change, none new. The rest of the lock was already stale on main; that is out of scope here. ## Also: unblocks CodeQL (second commit) `codeql.yml` was bumped to `checkout@v7.0.1` / `codeql-action@v4.38.2`, but its `actions.lock` entry still pinned v6.0.2 / v4.34.0. So every CodeQL run since `5e75753` died at startup with "Invalid lockfile". CodeQL is main's only required check, so no PR could merge. The second commit re-keys that entry, using commit SHAs resolved from the tags. On this head, CodeQL goes from `startup_failure` to `success`. `--no-fix` repo errors go from 64 to 58. ## Pre-existing reds (deferred) These contexts are red identically on `main` `5e75753`. This PR introduces none of them. They are deferred to #211: `chapel-ci`, `Dogfood Gate`, `Dependency Review`, `bridge-gate`, `cargo-audit.yml`, `coverage.yml`, `release.yml`, `Governance` (Workflow security linter, Actions lockfile verify), `Secret Scanner` (gitleaks), `Rust CI` (clippy, fmt). The failing check contexts are each deferred to #211: `scan / gitleaks` (#211), `rust-ci / Cargo check + clippy + fmt` (#211), `governance / Workflow security linter` (#211), `governance / Actions lockfile verify` (#211). ## Follow-up echidna's `security-scan.yml` has to bump its callee pin to this merge commit (echidna#310). 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01SJGZgoR9ArMgxKcqG7ChW8 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
1 parent 5e75753 commit 5ee2565

2 files changed

Lines changed: 22 additions & 14 deletions

File tree

‎.github/workflows/actions.lock‎

Lines changed: 18 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -24,8 +24,8 @@ workflows:
2424
- 'actions/upload-artifact@v4.6.2'
2525
- 'dtolnay/rust-toolchain@v1'
2626
'.github/workflows/codeql.yml':
27-
- 'actions/checkout@v6.0.2'
28-
- 'github/codeql-action@v4.34.0'
27+
- 'actions/checkout@v7.0.1'
28+
- 'github/codeql-action@v4.38.2'
2929
'.github/workflows/coverage.yml':
3030
- 'actions/checkout@v5.0.1'
3131
- 'dtolnay/rust-toolchain@v1'
@@ -61,9 +61,9 @@ workflows:
6161
- 'swatinem/rust-cache@v2.8.2'
6262
'.github/workflows/rust-ci.yml': []
6363
'.github/workflows/scan-and-report.yml':
64-
- 'actions/checkout@v4.3.1'
65-
- 'dtolnay/rust-toolchain@v1'
66-
- 'swatinem/rust-cache@v2.8.2'
64+
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
65+
- 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
66+
- 'Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6'
6767
'.github/workflows/scorecard.yml': []
6868
'.github/workflows/secret-scanner.yml': []
6969
dependencies:
@@ -102,6 +102,11 @@ dependencies:
102102
commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd'
103103
owner_id: 44036562
104104
repo_id: 197814629
105+
'actions/checkout@v7.0.1':
106+
ref: 'v7.0.1'
107+
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
108+
owner_id: 44036562
109+
repo_id: 197814629
105110
'actions/configure-pages@v5.0.0':
106111
ref: 'v5.0.0'
107112
commit: 'sha1-983d7736d9b0ae728b81ab479565c72886d7745b'
@@ -144,9 +149,9 @@ dependencies:
144149
commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
145150
owner_id: 1940490
146151
repo_id: 260749683
147-
'github/codeql-action@v4.34.0':
148-
ref: 'v4.34.0'
149-
commit: 'sha1-c6f931105cb2c34c8f901cc885ba1e2e259cf745'
152+
'github/codeql-action@v4.38.2':
153+
ref: 'v4.38.2'
154+
commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2'
150155
owner_id: 9919
151156
repo_id: 259445878
152157
'haskell-actions/setup@v2.7.5':
@@ -199,6 +204,11 @@ dependencies:
199204
commit: 'sha1-65c4c4a1ddee5b72f698fdd19549f0f0fb45cf08'
200205
owner_id: 44036562
201206
repo_id: 192625955
207+
'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de':
208+
ref: 'v1'
209+
commit: 'sha1-02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
210+
owner_id: 1940490
211+
repo_id: 260749683
202212
'dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772':
203213
ref: 'stable'
204214
commit: 'sha1-6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772'

‎.github/workflows/scan-and-report.yml‎

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,5 @@
1-
# This workflow is managed by gh actions-lock.
21
# SPDX-License-Identifier: MPL-2.0
32
# This workflow is managed by gh actions-lock.
4-
# This workflow is managed by gh actions-lock.
53

64
name: Scan and Report to VeriSimDB
75

@@ -38,15 +36,15 @@ jobs:
3836
runs-on: ubuntu-latest
3937
timeout-minutes: 20
4038
steps:
41-
- uses: actions/checkout@v7.0.1
39+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
4240

4341
- name: Install Rust
44-
uses: dtolnay/rust-toolchain@v1
42+
uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # v1
4543
with:
46-
toolchain: v1
44+
toolchain: stable
4745

4846
- name: Cache Rust dependencies
49-
uses: Swatinem/rust-cache@v2.9.2
47+
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
5048

5149
- name: Install panic-attack
5250
run: |

0 commit comments

Comments
 (0)