Skip to content

fix(ci): relock smtp-notify-action at v0.5.0 (#604) - #605

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/relock-smtp-notify-v0.5.0
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/relock-smtp-notify-v0.5.0

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

This relocks hyperpolymath/smtp-notify-action at v0.5.0 in .github/workflows/actions.lock.

Dependabot #595 (3d9d8bc) bumped the action from v0.3.0 to v0.5.0 in push-email-notify.yml but did not regenerate the lock. Since then three checks have failed on main:

  • actions.lock is in sync with the workflow YAML
  • governance / Actions lockfile verify
  • scorecard / Run Scorecard

The lock was regenerated with the estate tool, hyperpolymath/standards scripts/update-actions-lock.sh (standards origin/main @ 900c42c7, gh-actions-lock v0.1.6), not edited by hand. The diff is 4 lines:

  • the push-email-notify.yml workflow key now lists @v0.5.0;
  • the @v0.3.0 dependency record is replaced by @v0.5.0, resolved to its commit.

No workflow file changed, so no uses: line was rewritten.

Closes #604

Type of change

  • 🐛 Bug fix: a lockfile desync on main that turns three checks red.
  • ✨ New feature: not applicable.
  • 💥 Breaking change: none. The workflow already uses v0.5.0; only the lock catches up.
  • 🕳️ Soundness fix: not applicable.
  • 📖 Documentation: no docs change.
  • 🧹 Refactor / tech debt: not applicable.
  • ⚡ Performance: not applicable.
  • 🔧 Build / CI / tooling: actions.lock regeneration.

📌 New pins

  • PR head SHA: fd91919a269976cbb15f6e975dcc1eacd1842e34
  • actions.lock: hyperpolymath/smtp-notify-action@v0.5.0 → commit c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef. That is refs/tags/v0.5.0^{}, the peeled commit. The annotated tag object is c6a2a6dc…, and the lock does not use it (the fix(ci): lock entry points at the commit, not the tag object #594 class).
  • Removed: hyperpolymath/smtp-notify-action@v0.3.0 (22e7bdb3…).
  • No workflow uses: lines, lockfile records or container digests change beyond these.
  • No transitive entries are needed: action.yml at c1c9fa07 is using: 'composite' with no uses: of its own.

How has this been verified?

All commands were run in the PR worktree at the head above:

  • scripts/check-lock-sync.sh printed "actions.lock is in sync and transitively closed … (0 dangling edges)" and exited 0.
  • Positive control: the same script run on an origin/main (f17965b) export exited 1, printing exactly actions.lock desync on main: #595 bumped smtp-notify-action 0.3.0→0.5.0 without relocking #604's two lines: step-level refs missing from the lockfile: hyperpolymath/smtp-notify-action@v0.5.0 and stale lockfile entries, no uses: references them: hyperpolymath/smtp-notify-action@v0.3.0. So the pass above is not vacuous.
  • update-actions-lock.sh --verify-local exited 0. Afterwards, git status --short lists only .github/workflows/actions.lock, so the verifier mutated no workflow.
  • git ls-remote https://github.com/hyperpolymath/smtp-notify-action 'refs/tags/v0.5.0*' confirms that the recorded SHA is the peeled commit.
  • git log -1 --show-signature reports a good ED25519 signature, as required_signatures on main needs.
  • Not run locally: Scorecard's reconciliation and governance / Actions lockfile verify run only in CI. Their results on this head are the evidence for those two acceptance items.

Checklist

  • My commits are signed: SSH ED25519, verified locally.
  • I ran the project's own checks locally and they pass: check-lock-sync.sh and the estate --verify-local, as above.
  • New files carry the correct SPDX-License-Identifier: no new files. actions.lock is machine-generated ("Do not edit by hand") and carries no header, as before.
  • Docs are updated, and no public claim now overstates what the code does: no doc describes the lock contents.
  • I have not introduced a soundness hole. The pin is to an immutable commit, and no check was muted, demoted or set continue-on-error.

Notes for reviewers

  • This branch supersedes nothing that was pushed. A local, unpushed branch fix/actions-lock-desync relocks v0.3.0 and is stale; it is being triaged separately and has no effect on this PR.

Deferred red checks (not required; also red on main)

🤖 Generated with Claude Code

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Dependabot #595 bumped hyperpolymath/smtp-notify-action from v0.3.0 to
v0.5.0 in push-email-notify.yml without regenerating actions.lock, so
the lock-sync gate, governance's lockfile verify and Scorecard's
reconciliation all failed on main.

Regenerated with hyperpolymath/standards scripts/update-actions-lock.sh
(origin/main 900c42c7, gh-actions-lock v0.1.6). The lock now records
v0.5.0 at its commit c1c9fa07 (the peeled tag, not the tag object
c6a2a6dc) and drops the stale v0.3.0 entry. No workflow file changed.

Closes #604

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration
  • Configuration used: Repository: hyperpolymath/gitbot-fleet/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a5ae5e20-79f9-41bc-8f38-9d76da85fdba

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 8, 2026 18:43
@hyperpolymath
hyperpolymath merged commit 2c6b3d1 into main Oct 8, 2026
53 of 54 checks passed
@hyperpolymath
hyperpolymath deleted the fix/relock-smtp-notify-v0.5.0 branch October 8, 2026 18:47
hyperpolymath added a commit to hyperpolymath/hypatia that referenced this pull request Oct 8, 2026
….38.2 symbolic (#914, #901) (#915)

## Summary

This relocks `.github/workflows/actions.lock` for the refs Dependabot
bumped without regenerating the lock. That desync is the consistent
explanation for the four workflows that die at startup on `main`: `CI`,
`Tests (E2E / Integration / Stress / Bench)`, `Security` and `Build
Gossamer GUI`. While they do, **hypatia CI runs no Elixir test suite at
all**. This PR also fixes the `codeql.yml` startup death (#901).

The lock was regenerated with the estate tool, `hyperpolymath/standards`
`scripts/update-actions-lock.sh` (standards `origin/main` @ `900c42c7`,
`gh-actions-lock` v0.1.6), not edited by hand. The same procedure fixed
gitbot-fleet in hyperpolymath/gitbot-fleet#605.

- `taiki-e/install-action` `v2.87.22` → `v2.87.24`, in
`build-gossamer-gui.yml`, `ci.yml`, `security-policy.yml` and
`tests.yml`.
- `hyperpolymath/smtp-notify-action` `v0.3.0` → `v0.5.0`, in
`push-email-notify.yml`.
- `github/codeql-action`: the tool rewrote the bare-SHA refs
`@2892aa5e…` (5 lines across `codeql.yml` and `security-policy.yml`) to
the symbolic `@v4.38.2` and locked `v4.38.2` → `2892aa5e…`. **This is
the same commit**, so the code that runs does not change. It is the fix
pattern #901 prescribes ("symbolic; the lock carries the SHA"), and it
drops the false `# v4.38.0` label on that commit.

Closes #914
Closes #901

## Type of change

- [x] 🐛 Bug fix: a lockfile desync on `main` that kills 5 workflows at
startup and turns 2 governance checks red.
- [ ] ✨ New feature: not applicable.
- [ ] 💥 Breaking change: none. Every workflow already used the new refs;
only the lock catches up. The codeql commit is unchanged.
- [ ] 🕳️ Soundness fix: not a checker or proof change. It does restore
CI test execution, which was silently absent.
- [ ] 📖 Documentation: no docs change.
- [ ] 🧹 Refactor / tech debt: not applicable.
- [ ] ⚡ Performance: not applicable.
- [x] 🔧 Build / CI / tooling: `actions.lock` regeneration, plus the
tool's codeql ref rewrite.

## 📌 New pins

- **PR head SHA: `ddc77bc2fa8ab0241a8367ab2f53344eb9316071`**
- **`actions.lock`: `taiki-e/install-action@v2.87.24` → commit
`e407f7bafb71fd004bc5c2da3032e5470cbb6ef0`.** It replaces `@v2.87.22`
(`83ac0ad6…`).
- **`actions.lock`: `hyperpolymath/smtp-notify-action@v0.5.0` → commit
`c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef`.** It replaces `@v0.3.0`
(`22e7bdb3…`).
- **`actions.lock`: new `github/codeql-action@v4.38.2` → commit
`2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`**, now listed under
`codeql.yml` and `security-policy.yml`.
- **Workflow `uses:`**:
`github/codeql-action/{init,analyze,upload-sarif}@2892aa5e…` →
`@v4.38.2`, on 5 lines. Same commit.
- All three tags were checked with `git ls-remote` against the peeled
commit (`refs/tags/<t>^{}`), not the annotated tag object.
- No other `uses:` line, lockfile record or container digest changes.

## How has this been verified?

All commands were run in the PR worktree at the head above, unless
stated otherwise.

- `update-actions-lock.sh`, update mode: exit **0**. It reports "Pinned
3 actions across 6 workflows", and its built-in `verify_lock_coverage`
pass also succeeded.
- `gh actions-lock --no-fix`: exit **0**.
- **Positive control:** the same `gh actions-lock --no-fix` on a `git
archive origin/main` export exits **1**. It prints 4 × `Ref changed
taiki-e/install-action@v2.87.24`, 4 × `Unused lockfile entry
…@v2.87.22`, `Ref changed hyperpolymath/smtp-notify-action@v0.5.0` and
`Unused lockfile entry …@v0.3.0`, which are exactly #914's findings. So
the pass above is not vacuous.
- `git ls-remote` for each tag: `taiki-e/install-action` `v2.87.24^{}` =
`e407f7ba…`, `github/codeql-action` `v4.38.2^{}` = `2892aa5e…`,
`hyperpolymath/smtp-notify-action` `v0.5.0^{}` = `c1c9fa07…`. All three
match the lock.
- `actionlint` on the two rewritten workflows: 25 findings, all
`[shellcheck]` info-level, **identical** to the same files on
`origin/main` (compared with line numbers stripped). None are
introduced.
- `git log -1 --show-signature` reports a good ED25519 signature, as
`required_signatures` needs.
- **CI on this head confirms it.** GitHub's startup enforcement and the
pinned governance scanner run only in CI. On `ddc77bc2`:
- **`governance / Validate Hypatia Baseline` passes.** So the relock
alone cleared the 5 `unpinned_action` findings, with no inline SHA pins
and no re-ACK.
- The previously dead workflows now start and pass, including `CI
Status`, `Rust Tests`, `Cargo test`, `Integration Tests`, `E2E — Elixir
Scanner Pipeline`, `stress-test`, `CodeQL` and `CodeQL Analysis
(actions)`.
- `Build Gossamer GUI` has a `paths:` filter this PR doesn't match, so
it was run with `workflow_dispatch` on this branch. [Run
37833436482](https://github.com/hyperpolymath/hypatia/actions/runs/37833436482)
succeeded, 3/3 jobs. Its last three runs elsewhere, including `main`,
were all `startup_failure`.
  - `governance / Actions lockfile verify` passes.
- All 4 required contexts pass: `abi-codegen-drift`, `zig build test
(FFI + wire contract)`, `Escript packaging soundness` and `scan /
gitleaks`.

### Red checks, deferred

`security-policy.yml` now runs for the first time since the desync, and
three of its jobs fail. **None of them is caused by this PR**, and none
is required. Root causes and acceptance criteria are in #916:

- `Rust Dependency Audit`: deferred to #916. Two real advisories in
`Cargo.lock`, RUSTSEC-2026-0204 (`crossbeam-epoch`) and
RUSTSEC-2026-0258 (`h2`).
- `Rust License & Ban Check`: deferred to #916. The workflow generates a
`deny.toml` that current cargo-deny cannot parse (`unmaintained =
"warn"`).
- `Security Status`: deferred to #916. The orphan-job self-check reads
the workflow file without a checkout step and crashes with exit 2.

## Checklist

- [x] My commits are **signed**: SSH ED25519, verified locally.
- [x] I ran the project's own checks locally and they pass: the estate
lock tooling, as above. There are no Elixir code changes, so the Elixir
suite is not affected. CI on this head is its first chance to run at
all.
- [x] New files carry the correct `SPDX-License-Identifier`: no new
files. `actions.lock` is machine-generated ("Do not edit by hand") and
carries no header, as before.
- [x] Docs are updated, and no public claim now overstates what the code
does: no doc describes the lock contents.
- [x] I have not introduced a soundness hole. The refs resolve to
immutable commits, and no check was muted, demoted or set
`continue-on-error`.

## Notes for reviewers

- **A correction to #914.** #914 says the `Validate Hypatia Baseline`
failure "is not fixed by a relock". That was wrong.
`lib/rules/workflow_audit.ex:317-333` treats any ref the lock vouches
for as pinned (`ActionsLock.pinned?`), and #908 measured exactly that: 9
× `unpinned_action` cleared with a relock alone. CI on this head
confirms it: the Baseline check passes with no inline SHA pins and no
baseline re-ACK. The same comment records why inline SHA-pinning would
be a **regression** here: on 2026-08-07, inline-pinning 40 refs put 14
workflows into `startup_failure`.
- **`Closes #914` is earned.** All 5 workflows that died at startup now
start on this head. What they found once running is tracked in #916, not
here.
- This repository is where the estate's lock tooling is developed
(#901), so the lock and the workflows now agree again in both
directions.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

actions.lock desync on main: #595 bumped smtp-notify-action 0.3.0→0.5.0 without relocking

1 participant