Repository navigation
fix(ci): reconcile actions.lock so the lockfile validates - #123
Merged
Merged
Conversation
…s here fail at creation with 'The lockfile could not be validated. Regenerate it by running gh actions-lock' (or 'Workflow must use a lockfile'). This runs the official extension, completes the workflows: map so every onboarded file has an entry (the shape healthy repos carry), and adds the SHA-form transitive pins reached through called reusables. Every workflow re-parses before commit; gh actions-lock --verify is rc=0.
5 of 13 tasks
hyperpolymath
added a commit
that referenced
this pull request
Oct 8, 2026
) ## Summary Removes the GitGuardian job from `ci-benchmarks.yml` and relocks `actions.lock`. - `GitGuardian/ggshield-action` is in neither standards allowlist canon, so governance / Allowlist Preflight cannot pass while the job exists. The repo also has no `GITGUARDIAN_API_KEY` secret (the only Actions secret is `FARM_DISPATCH_TOKEN`), so the job could not have scanned anything. Secret scanning is already covered by `secret-scanner.yml` (standards `secret-scanner-reusable.yml`). Owner ruling, 2026-10-08. The same change landed in knot-rider (hyperpolymath/knot-rider#78). - No other job `needs:` `gitguardian`. The header comment and job numbering are renumbered to match. - `actions.lock` was already `valid:false` on `main`: Dependabot moved `sonarqube-scan-action` to v8.3.0 and `codeql-action` to v4.38.2 without a relock. The lock is now regenerated with standards `scripts/update-actions-lock.sh`. The regeneration dropped the eight SHA-form transitive entries that #123 pinned for the called standards reusables (`actions/cache@55cc834…`, `ossf/scorecard-action@2d11466…`, `webfactory/ssh-agent@e838748…`, …), so they are carried over byte for byte. Closes: no issue. ## Type of change - [ ] 🐛 Bug fix — n/a - [ ] ✨ New feature — n/a - [ ] 💥 Breaking change — n/a - [ ] 🕳️ Soundness fix — n/a - [ ] 📖 Documentation — n/a - [ ] 🧹 Refactor / tech debt — n/a - [ ] ⚡ Performance — n/a - [x] 🔧 Build / CI / tooling ## 📌 New pins Head SHA: **`9d5cd8acb3783a9e42308acfde26e0ea5ffdf42c`** Changed in `actions.lock` (Dependabot already made these changes in the workflows; this PR only records them in the lock): - **`sonarsource/sonarqube-scan-action@v8.3.0` → `d209202bc7d53ff1cc128f7f907dac145c9d6ae9`** (was v8.2.2 `ba9859e`) - **`github/codeql-action@v4.38.2` → `2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`** (was v4.38.0 `b96794f`) Removed: `gitguardian/ggshield-action@v1.54.0` (`7059aef`). No workflow `uses:` line changed. ## How has this been verified? - `gh actions-lock --verify-local --json=valid,findings` → `valid:true`. The only finding is the advisory `sha-as-ref` on `julia-actions/setup-julia@fa02766…`, which was already there. On `main` the result is `valid:false`, with 7 findings. - Every `uses:` across `.github/workflows/*.yml` is byte-identical before and after the relock (sorted diff, empty). - The two new commit SHAs match the ones already in hyperpolymath/knot-rider's lock for the same tags. - standards `scripts/check-allowed-actions.sh` with `rhodium-standard-repositories/actions-allowlist/allowed-actions.json`: "checked 20 `uses:` refs — 0 not covered". - `yq` parses `ci-benchmarks.yml`. ## Checklist - [x] My commits are **signed** (`git commit -S`): `%G?` = `G`. - [x] I ran the project's own checks locally: only the lock and allowlist checks above apply. No code changed, so no tests were run. - [ ] New files carry the correct SPDX header — n/a: no new files. - [x] Docs are updated: the workflow's header comment no longer lists GitGuardian. - [x] I have not introduced a soundness hole. This removes one secret scanner whose key was never set; the estate scanner still runs. ## Notes for reviewers Any future `gh actions-lock` regeneration will drop the eight SHA-form reusable edges again. Re-append them, or regenerate with a tool that follows reusables. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Workflows fail at creation with
The lockfile could not be validated. Regenerate it by running gh actions-lock/Workflow must use a lockfile. This regenerates the manifest with the official extension (github/gh-actions-lock), completes theworkflows:map so every workflow file has an entry, and pins the SHA-form transitive deps reached via called reusables. Proof before push: every workflow re-parses,gh actions-lock --verifyrc=0, and everyuses:ref resolves to a pin.