Skip to content

fix(ci): reconcile actions.lock so the lockfile validates - #123

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/lockfile-reconcile
Sep 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/lockfile-reconcile

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Workflows fail at creation with The lockfile could not be validated. Regenerate it by running gh actions-lock / Workflow must use a lockfile. This regenerates the manifest with the official extension (github/gh-actions-lock), completes the workflows: map so every workflow file has an entry, and pins the SHA-form transitive deps reached via called reusables. Proof before push: every workflow re-parses, gh actions-lock --verify rc=0, and every uses: ref resolves to a pin.

…s here fail at creation with 'The lockfile could not be validated. Regenerate it by running gh actions-lock' (or 'Workflow must use a lockfile'). This runs the official extension, completes the workflows: map so every onboarded file has an entry (the shape healthy repos carry), and adds the SHA-form transitive pins reached through called reusables. Every workflow re-parses before commit; gh actions-lock --verify is rc=0.
@hyperpolymath
hyperpolymath merged commit 5b2b398 into main Sep 21, 2026
1 check passed
@hyperpolymath
hyperpolymath deleted the fix/lockfile-reconcile branch September 21, 2026 12:43
hyperpolymath added a commit that referenced this pull request Oct 8, 2026
)

## Summary

Removes the GitGuardian job from `ci-benchmarks.yml` and relocks
`actions.lock`.

- `GitGuardian/ggshield-action` is in neither standards allowlist canon,
so governance / Allowlist Preflight cannot pass while the job exists.
The repo also has no `GITGUARDIAN_API_KEY` secret (the only Actions
secret is `FARM_DISPATCH_TOKEN`), so the job could not have scanned
anything. Secret scanning is already covered by `secret-scanner.yml`
(standards `secret-scanner-reusable.yml`). Owner ruling, 2026-10-08. The
same change landed in knot-rider (hyperpolymath/knot-rider#78).
- No other job `needs:` `gitguardian`. The header comment and job
numbering are renumbered to match.
- `actions.lock` was already `valid:false` on `main`: Dependabot moved
`sonarqube-scan-action` to v8.3.0 and `codeql-action` to v4.38.2 without
a relock. The lock is now regenerated with standards
`scripts/update-actions-lock.sh`. The regeneration dropped the eight
SHA-form transitive entries that #123 pinned for the called standards
reusables (`actions/cache@55cc834…`, `ossf/scorecard-action@2d11466…`,
`webfactory/ssh-agent@e838748…`, …), so they are carried over byte for
byte.

Closes: no issue.

## Type of change

- [ ] 🐛 Bug fix — n/a
- [ ] ✨ New feature — n/a
- [ ] 💥 Breaking change — n/a
- [ ] 🕳️ Soundness fix — n/a
- [ ] 📖 Documentation — n/a
- [ ] 🧹 Refactor / tech debt — n/a
- [ ] ⚡ Performance — n/a
- [x] 🔧 Build / CI / tooling

## 📌 New pins

Head SHA: **`9d5cd8acb3783a9e42308acfde26e0ea5ffdf42c`**

Changed in `actions.lock` (Dependabot already made these changes in the
workflows; this PR only records them in the lock):
- **`sonarsource/sonarqube-scan-action@v8.3.0` →
`d209202bc7d53ff1cc128f7f907dac145c9d6ae9`** (was v8.2.2 `ba9859e`)
- **`github/codeql-action@v4.38.2` →
`2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`** (was v4.38.0 `b96794f`)

Removed: `gitguardian/ggshield-action@v1.54.0` (`7059aef`). No workflow
`uses:` line changed.

## How has this been verified?

- `gh actions-lock --verify-local --json=valid,findings` → `valid:true`.
The only finding is the advisory `sha-as-ref` on
`julia-actions/setup-julia@fa02766…`, which was already there. On `main`
the result is `valid:false`, with 7 findings.
- Every `uses:` across `.github/workflows/*.yml` is byte-identical
before and after the relock (sorted diff, empty).
- The two new commit SHAs match the ones already in
hyperpolymath/knot-rider's lock for the same tags.
- standards `scripts/check-allowed-actions.sh` with
`rhodium-standard-repositories/actions-allowlist/allowed-actions.json`:
"checked 20 `uses:` refs — 0 not covered".
- `yq` parses `ci-benchmarks.yml`.

## Checklist

- [x] My commits are **signed** (`git commit -S`): `%G?` = `G`.
- [x] I ran the project's own checks locally: only the lock and
allowlist checks above apply. No code changed, so no tests were run.
- [ ] New files carry the correct SPDX header — n/a: no new files.
- [x] Docs are updated: the workflow's header comment no longer lists
GitGuardian.
- [x] I have not introduced a soundness hole. This removes one secret
scanner whose key was never set; the estate scanner still runs.

## Notes for reviewers

Any future `gh actions-lock` regeneration will drop the eight SHA-form
reusable edges again. Re-append them, or regenerate with a tool that
follows reusables.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant