Skip to content

actions.lock drift on main: dependabot bumps left 4 refs + codeql SHA unlocked (Actions lockfile verify red) #885

Description

@hyperpolymath

Finding

governance / Actions lockfile verify is red on main at 300fd45 (run 36729214094). Dependabot bumped uses: refs without refreshing .github/actions.lock:

action lockfile pins workflows use where
taiki-e/install-action v2.87.18 v2.87.21 build-gossamer-gui, ci, security-policy, tests
haskell-actions/setup v2.12.0 v2.12.1 ci
ruby/setup-ruby v1.324.0 v1.327.0 quality
trufflesecurity/trufflehog v3.97.6 v3.97.9 security-policy
github/codeql-action bare SHA b96794f… (sha-as-ref, stale) — codeql, security-policy

The check is not required on main, so it does not block merges. It is inherited by every open PR, e.g. #884, which touches no workflow file.

Acceptance criteria

  • .github/actions.lock pins exactly the refs the workflows use (the 4 ref-changed rows above), each with its resolved commit SHA (not a tag-object SHA).
  • The codeql-action entries carry a symbolic ref next to the SHA, so no sha-as-ref findings remain.
  • governance / Actions lockfile verify is green on a PR against main, and after merge on main itself.
  • The lock is updated by hand-verified edit or verify-mode only. gh actions-lock rewrite mode is known to de-pin SHAs to tags and corrupt local action refs.
  • Follow-up: dependabot's action bumps refresh the lock in the same PR (or a companion job does), so this drift cannot recur.

🤖 Generated with Claude Code

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Activity

  1. added
    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gates
    tech-debtKnown shortcut, drift, or hygiene owed - includes cleanup
    on Sep 30, 2026
  2. hyperpolymath commented on Oct 8, 2026

    @hyperpolymath
    OwnerAuthor

    Fixed by #908 (1f30497); Actions lockfile verify green on 654ef0c.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cicdCI/CD: workflows, actions, lockfiles, pins, runners, release gatespriority:p0Critical - drop other workscope:repoConfined to this repositorytech-debtKnown shortcut, drift, or hygiene owed - includes cleanup

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions