From 775d499fbc2e65f178afbf1a02c2d6091b1197ad Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 30 Sep 2026 16:17:43 +0100 Subject: [PATCH] chore(ci): generate actions.lock ahead of the 2026-10-01 lock gate The governance "Actions lockfile verify" gate requires .github/workflows/actions.lock from 2026-10-01. Every ref here is already SHA-pinned; `gh actions-lock --no-narrow` (v0.1.6) records those same SHAs and their transitive composite deps, with no ref rewritten. The tool's "managed by gh actions-lock" banner is placed on line 2 so SPDX stays on line 1. Verified locally: the gate script at the pinned standards SHA passes with LOCK_TODAY=2026-10-01. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_019aa9y32JcBuZ85KXe2jb8R --- .github/workflows/actions.lock | 149 ++++++++++++++++++++++++ .github/workflows/casket-pages.yml | 1 + .github/workflows/ci.yml | 1 + .github/workflows/codeql.yml | 1 + .github/workflows/gleam-ci.yml | 1 + .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 1 + .github/workflows/jekyll-gh-pages.yml | 1 + .github/workflows/label-triage.yml | 1 + .github/workflows/labels.yml | 1 + .github/workflows/language-policy.yml | 1 + .github/workflows/main-estate-audit.yml | 2 + .github/workflows/mirror.yml | 1 + .github/workflows/push-email-notify.yml | 1 + .github/workflows/rescript-deno-ci.yml | 1 + .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + .github/workflows/workflow-linter.yml | 1 + 18 files changed, 167 insertions(+) create mode 100644 .github/workflows/actions.lock diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock new file mode 100644 index 0000000..32030f8 --- /dev/null +++ b/.github/workflows/actions.lock @@ -0,0 +1,149 @@ +# This file is machine-generated by `gh actions-lock`. +# Do not edit by hand; run `gh actions-lock` to update. +# Docs: https://gh.io/actions-lockfile +version: 'v0.0.2' +workflows: + '.github/workflows/casket-pages.yml': + - 'actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d' + - 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + - 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9' + - 'haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' + '.github/workflows/ci.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294' + - 'denoland/setup-deno@909cc5acb0fdd60627fb858598759246509fa755' + - 'github/codeql-action@4bdb89f48054571735e3792627da6195c57459e2' + - 'ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f' + '.github/workflows/codeql.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'github/codeql-action@662472033e021d55d94146f66f6058822b0b39fd' + '.github/workflows/gleam-ci.yml': + - 'actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae' + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451' + '.github/workflows/jekyll-gh-pages.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d' + - 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + - 'actions/jekyll-build-pages@44a6e6beabd48582f863aeeb6cb2151cc1716697' + - 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9' + '.github/workflows/language-policy.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + '.github/workflows/main-estate-audit.yml': + - 'actions/checkout@11d5960a326750d5838078e36cf38b85af677262' + - 'hyperpolymath/cicd-suite@5a10b72e574ef63855fafd4568a4c178657f3294' + '.github/workflows/push-email-notify.yml': + - 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + '.github/workflows/rescript-deno-ci.yml': + - 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd' + - 'denoland/setup-deno@909cc5acb0fdd60627fb858598759246509fa755' + '.github/workflows/workflow-linter.yml': + - 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11' +dependencies: + 'actions/cache@27d5ce7f107fe9357f9df03efb73ab90386fccae': + ref: 'v5.0.5' + commit: 'sha1-27d5ce7f107fe9357f9df03efb73ab90386fccae' + owner_id: 44036562 + repo_id: 215566462 + 'actions/checkout@11d5960a326750d5838078e36cf38b85af677262': + ref: 'v4.4.0' + commit: 'sha1-11d5960a326750d5838078e36cf38b85af677262' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11': + ref: 'v4.1.1' + commit: 'sha1-b4ffde65f46336ab88eb53be808477a3936bae11' + owner_id: 44036562 + repo_id: 197814629 + 'actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd': + ref: 'v6.0.2' + commit: 'sha1-de0fac2e4500dabe0009e67214ff5f5447ce83dd' + owner_id: 44036562 + repo_id: 197814629 + 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d': + ref: 'v6.0.0' + commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' + owner_id: 44036562 + repo_id: 513659658 + 'actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294': + ref: 'v5.0.0' + commit: 'sha1-a1d282b36b6f3519aa1f3fc636f609c47dddb294' + owner_id: 44036562 + repo_id: 476372928 + 'actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128': + ref: 'v5.0.0' + commit: 'sha1-cd2ce8fcbc39b97be8ca5fce6e763baed58fa128' + owner_id: 44036562 + repo_id: 438112499 + 'actions/jekyll-build-pages@44a6e6beabd48582f863aeeb6cb2151cc1716697': + ref: 'v1.0.13' + commit: 'sha1-44a6e6beabd48582f863aeeb6cb2151cc1716697' + owner_id: 44036562 + repo_id: 438323626 + 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f': + ref: 'v7.0.0' + commit: 'sha1-bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + owner_id: 44036562 + repo_id: 192625955 + 'actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9': + ref: 'v5.0.0' + commit: 'sha1-fc324d3547104276b827a68afc52ff2a11cc49c9' + owner_id: 44036562 + repo_id: 496012378 + uses: + - 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f' + 'denoland/setup-deno@909cc5acb0fdd60627fb858598759246509fa755': + ref: 'v2.0.2' + commit: 'sha1-909cc5acb0fdd60627fb858598759246509fa755' + owner_id: 42048915 + repo_id: 356423100 + 'erlef/setup-beam@5304e04ea2b355f03681464e683d92e3b2f18451': + ref: 'v1.18.2' + commit: 'sha1-5304e04ea2b355f03681464e683d92e3b2f18451' + owner_id: 47606891 + repo_id: 331103973 + 'github/codeql-action@4bdb89f48054571735e3792627da6195c57459e2': + ref: 'v3.31.10' + commit: 'sha1-4bdb89f48054571735e3792627da6195c57459e2' + owner_id: 9919 + repo_id: 259445878 + 'github/codeql-action@662472033e021d55d94146f66f6058822b0b39fd': + ref: 'main' + commit: 'sha1-662472033e021d55d94146f66f6058822b0b39fd' + owner_id: 9919 + repo_id: 259445878 + 'haskell-actions/setup@cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553': + ref: 'v2.11.0' + commit: 'sha1-cd0d9bdd65b20557f41bea4dbe43d0b5fbbfe553' + owner_id: 75048950 + repo_id: 623796603 + 'hyperpolymath/cicd-suite@5a10b72e574ef63855fafd4568a4c178657f3294': + ref: 'main' + commit: 'sha1-5a10b72e574ef63855fafd4568a4c178657f3294' + owner_id: 6759885 + repo_id: 1326697643 + uses: + - 'hyperpolymath/deed-ecosystem@f9d999b60cb5f383679ea19912bcdc49c944973a' + - 'hyperpolymath/k9-ecosystem@2155aa26a21758f2ba119f61bc7e0e1981c106fb' + 'hyperpolymath/deed-ecosystem@f9d999b60cb5f383679ea19912bcdc49c944973a': + ref: 'main' + commit: 'sha1-f9d999b60cb5f383679ea19912bcdc49c944973a' + owner_id: 6759885 + repo_id: 1275649586 + 'hyperpolymath/k9-ecosystem@2155aa26a21758f2ba119f61bc7e0e1981c106fb': + ref: 'main' + commit: 'sha1-2155aa26a21758f2ba119f61bc7e0e1981c106fb' + owner_id: 6759885 + repo_id: 1275650185 + 'hyperpolymath/smtp-notify-action@ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7': + ref: 'v0.2.0' + commit: 'sha1-ede1191ef6ff3ac02c4f4d9efdf837ee517e11d7' + owner_id: 6759885 + repo_id: 1352485172 + 'ruby/setup-ruby@afeafc3d1ab54a631816aba4c914a0081c12ff2f': + ref: 'v1.310.0' + commit: 'sha1-afeafc3d1ab54a631816aba4c914a0081c12ff2f' + owner_id: 210414 + repo_id: 231208785 diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index 71c6334..a2474f9 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: GitHub Pages on: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1842c6e..2ff2ff9 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CI/CD Pipeline on: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 0f692e8..33d61b5 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: CodeQL Security Analysis on: diff --git a/.github/workflows/gleam-ci.yml b/.github/workflows/gleam-ci.yml index dbb8462..40b4644 100644 --- a/.github/workflows/gleam-ci.yml +++ b/.github/workflows/gleam-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # SPDX-FileCopyrightText: 2025 Hyperpolymath name: Gleam CI diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 80ad396..bf5aae0 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Governance on: diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index f31f35d..db83654 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Hypatia Security Scan on: diff --git a/.github/workflows/jekyll-gh-pages.yml b/.github/workflows/jekyll-gh-pages.yml index 3d15bce..bc47c54 100644 --- a/.github/workflows/jekyll-gh-pages.yml +++ b/.github/workflows/jekyll-gh-pages.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Sample workflow for building and deploying a Jekyll site to GitHub Pages name: Deploy Jekyll with GitHub Pages dependencies preinstalled diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml index 9886e92..fc79947 100644 --- a/.github/workflows/label-triage.yml +++ b/.github/workflows/label-triage.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Label Triage # Classify newly-filed issues against the estate label taxonomy. diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml index c80b676..af34c6b 100644 --- a/.github/workflows/labels.yml +++ b/.github/workflows/labels.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Labels # Applies the canonical estate label set from .github/labels.json. diff --git a/.github/workflows/language-policy.yml b/.github/workflows/language-policy.yml index cd1c7c2..5efb862 100644 --- a/.github/workflows/language-policy.yml +++ b/.github/workflows/language-policy.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Language Policy Enforcement on: push: diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml index b823677..893db8c 100755 --- a/.github/workflows/main-estate-audit.yml +++ b/.github/workflows/main-estate-audit.yml @@ -1,3 +1,5 @@ +# This workflow is managed by gh actions-lock. + name: Central Estate CI/CD Audit on: diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index cde47d6..ca54d84 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Mirror to Git Forges on: diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 0689291..80c6942 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Dormant push-email notification. ARMED by setting the repo variable # PUSH_EMAIL_ENABLED=true (the single on/off switch). Addresses are pre-filled; # sending needs the org SMTP secrets (SMTP_HOST/PORT/USER/PASS). Inherited by diff --git a/.github/workflows/rescript-deno-ci.yml b/.github/workflows/rescript-deno-ci.yml index 087328f..16be98f 100644 --- a/.github/workflows/rescript-deno-ci.yml +++ b/.github/workflows/rescript-deno-ci.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: AffineScript/Deno CI on: push: diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index 20e7c39..7f495c0 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: OSSF Scorecard on: diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index d2bf155..fc40165 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. name: Secret Scanner on: diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 3bed9c5..758a716 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +# This workflow is managed by gh actions-lock. # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter