Skip to content

fix(ci): sync actions.lock with bumped pins; drop manifest-less Dependabot ecosystems - #111

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/actions-lock-haskell-ci
Oct 7, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/actions-lock-haskell-ci

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Dependabot moved three uses: lines to new commits, but .github/workflows/actions.lock still named the old ones. GitHub matches lock entries against the literal ref string, so it refused to start the affected workflows. Haskell CI has ended in startup_failure on every run since 2026-10-03, and governance / Actions lockfile verify is red on main.

Action Old lock entry Now (matches the workflow) Workflows
haskell-actions/setup 6037f336 (v2.12.0) 0f8e8c99 (v2.12.1) haskell.yml, casket-pages.yml
github/codeql-action 1c5b6756 (v4.38.1) 2892aa5e (v4.38.2) codeql.yml

This also corrects the stale version comments beside those pins: the codeql pins said # v3 beside a v4.38.2 commit.

A second commit trims .github/dependabot.yml to github-actions only. This is a Haskell (cabal) project with no package.json, Python requirements or Cargo.toml, so the npm, pip and cargo update jobs failed on every run (/package.json not found). Dependabot has no Haskell ecosystem.

Closes #108

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature: none.
  • 💥 Breaking change: no.
  • 🕳️ Soundness fix: not a checker false-negative.
  • 📖 Documentation: no.
  • 🧹 Refactor: no.
  • ⚡ Performance: no.
  • 🔧 Build / CI / tooling: actions.lock, plus comment-only edits in two workflows.

📌 New pins

Head SHA: 33dd482f28f3de4f80952615716350d83dcee60c

actions.lock entries changed. The workflow uses: lines are unchanged; only the lock catches up to them:

  • haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d → tag v2.12.1 (also v2.12, v2), resolved via the GitHub tags API.
  • github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 → tag v4.38.2 (also v4).

How has this been verified?

  • The lock is hand-edited, deliberately. gh actions-lock in fix mode was tried first. It rewrote all 19 workflows, turning SHA pins into tags (e.g. haskell-actions/setup@v2.12.1) and re-keying the lock to match. This repo has sha_pinning_required: true (gh api repos/hyperpolymath/sanctify-php/actions/permissions), so that output would itself stop the workflows from starting. It was discarded.
  • Matched pair on the unchanged workflow bytes, with gh actions-lock --no-fix:
    • old lock: 3 of 19 workflows failed verification (3 Unused lockfile entry findings), rc 1.
    • new lock: rc 0.
  • Every new lock key is the literal owner/repo@sha string that the workflow's uses: names.
  • dependabot.yml: the last runs of npm_and_yarn and pip both failed (2026-08-13; npm again on 2026-10-01: Error during file fetching; aborting: /package.json not found). git ls-files shows sanctify-php.cabal and no npm, pip or cargo manifest.
  • Both actions are on the repo's selected-actions allow-list, so the allow-list is not the cause of the startup failure.

Horizon of this check: gh actions-lock resolves refs, so its rc 0 alone does not prove GitHub will start the workflows. The literal-string match does, and this PR's own Haskell CI and CodeQL runs are the real proof. If Haskell CI now starts and fails, that is a real compile result, the first since the fix in #107.

Checklist

  • My commits are signed (git commit -S). git log --format=%G? → G.
  • I ran the project's own checks locally: gh actions-lock --no-fix, rc 0.
  • New files carry the correct SPDX-License-Identifier: no new files.
  • Docs are updated: no docs are affected.
  • I have not introduced a soundness hole: no pin is loosened, and every uses: stays SHA-pinned.

Notes for reviewers

The owner approved hand-writing this lock delta on 2026-10-07, because the generator cannot produce a SHA-keyed lock without de-pinning the workflows.

🤖 Generated with Claude Code

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

hyperpolymath and others added 2 commits October 7, 2026 07:28
Dependabot moved three uses: lines to new commits, but actions.lock
still named the old ones. The lockfile match is literal on the ref
string, so GitHub refused to start the affected workflows: Haskell CI
has ended in startup_failure on every run since 2026-10-03.

- haskell-actions/setup 6037f336 (v2.12.0) -> 0f8e8c99 (v2.12.1)
  in haskell.yml and casket-pages.yml
- github/codeql-action 1c5b6756 (v4.38.1) -> 2892aa5e (v4.38.2)
  in codeql.yml

The lock is edited by hand on purpose. `gh actions-lock` in fix mode
rewrites every workflow's SHA pins into tags, and this repo has
sha_pinning_required=true, so that output would itself stop the
workflows from starting. Checked as a matched pair on the unchanged
workflow bytes: old lock fails `gh actions-lock --no-fix` (rc 1),
new lock passes (rc 0).

Also corrects the stale version comments beside those two pins
(`# v2` and `# v3` -> the tags the SHAs actually carry).

Closes #108

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
sanctify-php is a Haskell (cabal) project with no package.json,
Python requirements or Cargo.toml, so the npm, pip and cargo update
jobs failed on every run ("/package.json not found"). Dependabot has
no Haskell ecosystem, so github-actions is the only one it can serve.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1b3992ed-a1da-4f25-b7a7-cfaa5613b174
📥 Commits

Reviewing files that changed from the base of the PR and between 8b08492 and 33dd482.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (3)
  • .github/dependabot.yml
  • .github/workflows/casket-pages.yml
  • .github/workflows/codeql.yml
 ________________________________________________________________
< I like what you did here. I don't like *that* you did it here. >
 ----------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit e9b06a2 into main Oct 7, 2026
35 of 37 checks passed
@hyperpolymath
hyperpolymath deleted the fix/actions-lock-haskell-ci branch October 7, 2026 06:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Actions lockfile verify red on main: 3 stale actions.lock entries

1 participant