Repository navigation
fix(ci): relock smtp-notify-action at v0.5.0 (#604) - #605
Merged
Merged
Conversation
Dependabot #595 bumped hyperpolymath/smtp-notify-action from v0.3.0 to v0.5.0 in push-email-notify.yml without regenerating actions.lock, so the lock-sync gate, governance's lockfile verify and Scorecard's reconciliation all failed on main. Regenerated with hyperpolymath/standards scripts/update-actions-lock.sh (origin/main 900c42c7, gh-actions-lock v0.1.6). The lock now records v0.5.0 at its commit c1c9fa07 (the peeled tag, not the tag object c6a2a6dc) and drops the stale v0.3.0 entry. No workflow file changed. Closes #604 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
Contributor
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
enabled auto-merge (squash)
October 8, 2026 18:43
This was referenced Oct 8, 2026
hyperpolymath
added a commit
to hyperpolymath/hypatia
that referenced
this pull request
Oct 8, 2026
….38.2 symbolic (#914, #901) (#915) ## Summary This relocks `.github/workflows/actions.lock` for the refs Dependabot bumped without regenerating the lock. That desync is the consistent explanation for the four workflows that die at startup on `main`: `CI`, `Tests (E2E / Integration / Stress / Bench)`, `Security` and `Build Gossamer GUI`. While they do, **hypatia CI runs no Elixir test suite at all**. This PR also fixes the `codeql.yml` startup death (#901). The lock was regenerated with the estate tool, `hyperpolymath/standards` `scripts/update-actions-lock.sh` (standards `origin/main` @ `900c42c7`, `gh-actions-lock` v0.1.6), not edited by hand. The same procedure fixed gitbot-fleet in hyperpolymath/gitbot-fleet#605. - `taiki-e/install-action` `v2.87.22` → `v2.87.24`, in `build-gossamer-gui.yml`, `ci.yml`, `security-policy.yml` and `tests.yml`. - `hyperpolymath/smtp-notify-action` `v0.3.0` → `v0.5.0`, in `push-email-notify.yml`. - `github/codeql-action`: the tool rewrote the bare-SHA refs `@2892aa5e…` (5 lines across `codeql.yml` and `security-policy.yml`) to the symbolic `@v4.38.2` and locked `v4.38.2` → `2892aa5e…`. **This is the same commit**, so the code that runs does not change. It is the fix pattern #901 prescribes ("symbolic; the lock carries the SHA"), and it drops the false `# v4.38.0` label on that commit. Closes #914 Closes #901 ## Type of change - [x] 🐛 Bug fix: a lockfile desync on `main` that kills 5 workflows at startup and turns 2 governance checks red. - [ ] ✨ New feature: not applicable. - [ ] 💥 Breaking change: none. Every workflow already used the new refs; only the lock catches up. The codeql commit is unchanged. - [ ] 🕳️ Soundness fix: not a checker or proof change. It does restore CI test execution, which was silently absent. - [ ] 📖 Documentation: no docs change. - [ ] 🧹 Refactor / tech debt: not applicable. - [ ] ⚡ Performance: not applicable. - [x] 🔧 Build / CI / tooling: `actions.lock` regeneration, plus the tool's codeql ref rewrite. ## 📌 New pins - **PR head SHA: `ddc77bc2fa8ab0241a8367ab2f53344eb9316071`** - **`actions.lock`: `taiki-e/install-action@v2.87.24` → commit `e407f7bafb71fd004bc5c2da3032e5470cbb6ef0`.** It replaces `@v2.87.22` (`83ac0ad6…`). - **`actions.lock`: `hyperpolymath/smtp-notify-action@v0.5.0` → commit `c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef`.** It replaces `@v0.3.0` (`22e7bdb3…`). - **`actions.lock`: new `github/codeql-action@v4.38.2` → commit `2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`**, now listed under `codeql.yml` and `security-policy.yml`. - **Workflow `uses:`**: `github/codeql-action/{init,analyze,upload-sarif}@2892aa5e…` → `@v4.38.2`, on 5 lines. Same commit. - All three tags were checked with `git ls-remote` against the peeled commit (`refs/tags/<t>^{}`), not the annotated tag object. - No other `uses:` line, lockfile record or container digest changes. ## How has this been verified? All commands were run in the PR worktree at the head above, unless stated otherwise. - `update-actions-lock.sh`, update mode: exit **0**. It reports "Pinned 3 actions across 6 workflows", and its built-in `verify_lock_coverage` pass also succeeded. - `gh actions-lock --no-fix`: exit **0**. - **Positive control:** the same `gh actions-lock --no-fix` on a `git archive origin/main` export exits **1**. It prints 4 × `Ref changed taiki-e/install-action@v2.87.24`, 4 × `Unused lockfile entry …@v2.87.22`, `Ref changed hyperpolymath/smtp-notify-action@v0.5.0` and `Unused lockfile entry …@v0.3.0`, which are exactly #914's findings. So the pass above is not vacuous. - `git ls-remote` for each tag: `taiki-e/install-action` `v2.87.24^{}` = `e407f7ba…`, `github/codeql-action` `v4.38.2^{}` = `2892aa5e…`, `hyperpolymath/smtp-notify-action` `v0.5.0^{}` = `c1c9fa07…`. All three match the lock. - `actionlint` on the two rewritten workflows: 25 findings, all `[shellcheck]` info-level, **identical** to the same files on `origin/main` (compared with line numbers stripped). None are introduced. - `git log -1 --show-signature` reports a good ED25519 signature, as `required_signatures` needs. - **CI on this head confirms it.** GitHub's startup enforcement and the pinned governance scanner run only in CI. On `ddc77bc2`: - **`governance / Validate Hypatia Baseline` passes.** So the relock alone cleared the 5 `unpinned_action` findings, with no inline SHA pins and no re-ACK. - The previously dead workflows now start and pass, including `CI Status`, `Rust Tests`, `Cargo test`, `Integration Tests`, `E2E — Elixir Scanner Pipeline`, `stress-test`, `CodeQL` and `CodeQL Analysis (actions)`. - `Build Gossamer GUI` has a `paths:` filter this PR doesn't match, so it was run with `workflow_dispatch` on this branch. [Run 37833436482](https://github.com/hyperpolymath/hypatia/actions/runs/37833436482) succeeded, 3/3 jobs. Its last three runs elsewhere, including `main`, were all `startup_failure`. - `governance / Actions lockfile verify` passes. - All 4 required contexts pass: `abi-codegen-drift`, `zig build test (FFI + wire contract)`, `Escript packaging soundness` and `scan / gitleaks`. ### Red checks, deferred `security-policy.yml` now runs for the first time since the desync, and three of its jobs fail. **None of them is caused by this PR**, and none is required. Root causes and acceptance criteria are in #916: - `Rust Dependency Audit`: deferred to #916. Two real advisories in `Cargo.lock`, RUSTSEC-2026-0204 (`crossbeam-epoch`) and RUSTSEC-2026-0258 (`h2`). - `Rust License & Ban Check`: deferred to #916. The workflow generates a `deny.toml` that current cargo-deny cannot parse (`unmaintained = "warn"`). - `Security Status`: deferred to #916. The orphan-job self-check reads the workflow file without a checkout step and crashes with exit 2. ## Checklist - [x] My commits are **signed**: SSH ED25519, verified locally. - [x] I ran the project's own checks locally and they pass: the estate lock tooling, as above. There are no Elixir code changes, so the Elixir suite is not affected. CI on this head is its first chance to run at all. - [x] New files carry the correct `SPDX-License-Identifier`: no new files. `actions.lock` is machine-generated ("Do not edit by hand") and carries no header, as before. - [x] Docs are updated, and no public claim now overstates what the code does: no doc describes the lock contents. - [x] I have not introduced a soundness hole. The refs resolve to immutable commits, and no check was muted, demoted or set `continue-on-error`. ## Notes for reviewers - **A correction to #914.** #914 says the `Validate Hypatia Baseline` failure "is not fixed by a relock". That was wrong. `lib/rules/workflow_audit.ex:317-333` treats any ref the lock vouches for as pinned (`ActionsLock.pinned?`), and #908 measured exactly that: 9 × `unpinned_action` cleared with a relock alone. CI on this head confirms it: the Baseline check passes with no inline SHA pins and no baseline re-ACK. The same comment records why inline SHA-pinning would be a **regression** here: on 2026-08-07, inline-pinning 40 refs put 14 workflows into `startup_failure`. - **`Closes #914` is earned.** All 5 workflows that died at startup now start on this head. What they found once running is tracked in #916, not here. - This repository is where the estate's lock tooling is developed (#901), so the lock and the workflows now agree again in both directions. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This relocks
hyperpolymath/smtp-notify-actionat v0.5.0 in.github/workflows/actions.lock.Dependabot #595 (
3d9d8bc) bumped the action from v0.3.0 to v0.5.0 inpush-email-notify.ymlbut did not regenerate the lock. Since then three checks have failed onmain:actions.lock is in sync with the workflow YAMLgovernance / Actions lockfile verifyscorecard / Run ScorecardThe lock was regenerated with the estate tool,
hyperpolymath/standardsscripts/update-actions-lock.sh(standardsorigin/main@900c42c7,gh-actions-lockv0.1.6), not edited by hand. The diff is 4 lines:push-email-notify.ymlworkflow key now lists@v0.5.0;@v0.3.0dependency record is replaced by@v0.5.0, resolved to its commit.No workflow file changed, so no
uses:line was rewritten.Closes #604
Type of change
mainthat turns three checks red.actions.lockregeneration.📌 New pins
fd91919a269976cbb15f6e975dcc1eacd1842e34actions.lock:hyperpolymath/smtp-notify-action@v0.5.0→ commitc1c9fa07992a02c1fd3d67a0dc1b08cccb852aef. That isrefs/tags/v0.5.0^{}, the peeled commit. The annotated tag object isc6a2a6dc…, and the lock does not use it (the fix(ci): lock entry points at the commit, not the tag object #594 class).hyperpolymath/smtp-notify-action@v0.3.0(22e7bdb3…).uses:lines, lockfile records or container digests change beyond these.action.ymlatc1c9fa07isusing: 'composite'with nouses:of its own.How has this been verified?
All commands were run in the PR worktree at the head above:
scripts/check-lock-sync.shprinted "actions.lock is in sync and transitively closed … (0 dangling edges)" and exited 0.origin/main(f17965b) export exited 1, printing exactly actions.lock desync on main: #595 bumped smtp-notify-action 0.3.0→0.5.0 without relocking #604's two lines:step-level refs missing from the lockfile: hyperpolymath/smtp-notify-action@v0.5.0andstale lockfile entries, no uses: references them: hyperpolymath/smtp-notify-action@v0.3.0. So the pass above is not vacuous.update-actions-lock.sh --verify-localexited 0. Afterwards,git status --shortlists only.github/workflows/actions.lock, so the verifier mutated no workflow.git ls-remote https://github.com/hyperpolymath/smtp-notify-action 'refs/tags/v0.5.0*'confirms that the recorded SHA is the peeled commit.git log -1 --show-signaturereports a good ED25519 signature, asrequired_signaturesonmainneeds.governance / Actions lockfile verifyrun only in CI. Their results on this head are the evidence for those two acceptance items.Checklist
check-lock-sync.shand the estate--verify-local, as above.SPDX-License-Identifier: no new files.actions.lockis machine-generated ("Do not edit by hand") and carries no header, as before.continue-on-error.Notes for reviewers
fix/actions-lock-desyncrelocks v0.3.0 and is stale; it is being triaged separately and has no effect on this PR.Deferred red checks (not required; also red on
main)Codeac analyze results(legacy status): deferred to Codeac analyze results fails on main: service cannot analyse the repo #590. The service cannot analyse the repo, and this PR doesn't change that.🤖 Generated with Claude Code
https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML