Repository navigation
fix(ci): sync actions.lock with bumped pins; drop manifest-less Dependabot ecosystems - #111
Merged
Merged
Conversation
Dependabot moved three uses: lines to new commits, but actions.lock still named the old ones. The lockfile match is literal on the ref string, so GitHub refused to start the affected workflows: Haskell CI has ended in startup_failure on every run since 2026-10-03. - haskell-actions/setup 6037f336 (v2.12.0) -> 0f8e8c99 (v2.12.1) in haskell.yml and casket-pages.yml - github/codeql-action 1c5b6756 (v4.38.1) -> 2892aa5e (v4.38.2) in codeql.yml The lock is edited by hand on purpose. `gh actions-lock` in fix mode rewrites every workflow's SHA pins into tags, and this repo has sha_pinning_required=true, so that output would itself stop the workflows from starting. Checked as a matched pair on the unchanged workflow bytes: old lock fails `gh actions-lock --no-fix` (rc 1), new lock passes (rc 0). Also corrects the stale version comments beside those two pins (`# v2` and `# v3` -> the tags the SHAs actually carry). Closes #108 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
sanctify-php is a Haskell (cabal) project with no package.json,
Python requirements or Cargo.toml, so the npm, pip and cargo update
jobs failed on every run ("/package.json not found"). Dependabot has
no Haskell ecosystem, so github-actions is the only one it can serve.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Dependabot moved three
uses:lines to new commits, but.github/workflows/actions.lockstill named the old ones. GitHub matches lock entries against the literal ref string, so it refused to start the affected workflows.Haskell CIhas ended instartup_failureon every run since 2026-10-03, andgovernance / Actions lockfile verifyis red onmain.haskell-actions/setup6037f336(v2.12.0)0f8e8c99(v2.12.1)haskell.yml,casket-pages.ymlgithub/codeql-action1c5b6756(v4.38.1)2892aa5e(v4.38.2)codeql.ymlThis also corrects the stale version comments beside those pins: the codeql pins said
# v3beside a v4.38.2 commit.A second commit trims
.github/dependabot.ymltogithub-actionsonly. This is a Haskell (cabal) project with nopackage.json, Python requirements orCargo.toml, so the npm, pip and cargo update jobs failed on every run (/package.json not found). Dependabot has no Haskell ecosystem.Closes #108
Type of change
actions.lock, plus comment-only edits in two workflows.📌 New pins
Head SHA:
33dd482f28f3de4f80952615716350d83dcee60cactions.lockentries changed. The workflowuses:lines are unchanged; only the lock catches up to them:haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d→ tagv2.12.1(alsov2.12,v2), resolved via the GitHub tags API.github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2→ tagv4.38.2(alsov4).How has this been verified?
gh actions-lockin fix mode was tried first. It rewrote all 19 workflows, turning SHA pins into tags (e.g.haskell-actions/setup@v2.12.1) and re-keying the lock to match. This repo hassha_pinning_required: true(gh api repos/hyperpolymath/sanctify-php/actions/permissions), so that output would itself stop the workflows from starting. It was discarded.gh actions-lock --no-fix:3 of 19 workflows failed verification(3Unused lockfile entryfindings), rc 1.owner/repo@shastring that the workflow'suses:names.dependabot.yml: the last runs ofnpm_and_yarnandpipboth failed (2026-08-13; npm again on 2026-10-01:Error during file fetching; aborting: /package.json not found).git ls-filesshowssanctify-php.cabaland no npm, pip or cargo manifest.selected-actionsallow-list, so the allow-list is not the cause of the startup failure.Horizon of this check:
gh actions-lockresolves refs, so its rc 0 alone does not prove GitHub will start the workflows. The literal-string match does, and this PR's ownHaskell CIandCodeQLruns are the real proof. IfHaskell CInow starts and fails, that is a real compile result, the first since the fix in #107.Checklist
git commit -S).git log --format=%G?→G.gh actions-lock --no-fix, rc 0.SPDX-License-Identifier: no new files.uses:stays SHA-pinned.Notes for reviewers
The owner approved hand-writing this lock delta on 2026-10-07, because the generator cannot produce a SHA-keyed lock without de-pinning the workflows.
🤖 Generated with Claude Code
https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw