Skip to content

fix(ci): clear hypatia's red checks (try_update, Dependabot lock entries, rustls, baseline) - #908

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/redci-cleanup
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/redci-cleanup

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

This PR clears four red gates on main (fabe659) in one commit.

Red check Decisive log line Fix
Cargo check + clippy + fmt / Clippy use of deprecated method std::sync::atomic::Atomic::<u32>::fetch_update: renamed to try_update (-D warnings, Rust 1.99) cli/src/app_state.rs:58: fetch_update → try_update. Same semantics; available since Rust 1.95.
governance / Actions lockfile verify ##[error]actions-lock gate: lockfile verification FAILED (exit 1) (ref-changed: Dependabot bumped uses: refs without updating the lock) Re-recorded the four bumped refs in .github/workflows/actions.lock against their commit SHAs, and removed an unreferenced github/codeql-action@b96794f entry.
Dependabot (runs 37471485821, 37471490175) security_update_not_possible for rustls GHSA-2mjx-qc3c-rqvc (alerts #35, #36) Bumped rustls 0.23.40 → 0.23.45 in Cargo.lock and scripts/ci-tools/Cargo.lock. 0.23.45 resolves fine. Transitive bumps: rustls-webpki 0.103.15, aws-lc-rs 1.18.1, aws-lc-sys 0.45.0.
governance / Validate Hypatia Baseline ##[error]Gate failed: 12 unfiltered finding(s) at or above 'info'. 9 × unpinned_action came from the stale lock and clear with the lock fix: the pinned scanner is lockfile-aware. 3 × secret_detected at lib/hypatia/scanner_suppression.ex:360,361,363 were quoted secret: / password = examples in a doc comment; I reworded the comment so it carries no quoted literal. No baseline entry was added and the gate is not weakened.

Not addressed (owner items): mirror-* (standards#950); Codeac (third-party App).

Closes: no issue; found by the 2026-10-06 red-CI census.

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue): the deprecation build break and the stale lockfile
  • ✨ New feature: not applicable
  • 💥 Breaking change: not applicable. try_update is behaviour-identical, and the dependency bumps are patch/minor.
  • 🕳️ Soundness fix: not applicable. No rule logic changed; only a comment in scanner_suppression.ex.
  • 📖 Documentation: the one doc-comment rewording has the same meaning and is listed above as part of the baseline fix.
  • 🧹 Refactor / tech debt: not applicable
  • ⚡ Performance: not applicable
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: 7937dff

.github/workflows/actions.lock. Each commit was checked with gh api repos/O/R/git/commits/<sha> (200). Owner and repo ids are unchanged. None of the new versions has transitive uses:.

  • taiki-e/install-action v2.87.18 → v2.87.22 = 83ac0ad63c0167e6f06796fab0fce28db1bf3db0, in build-gossamer-gui.yml, ci.yml, security-policy.yml and tests.yml
  • haskell-actions/setup v2.12.0 → v2.12.1 = 0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d, in ci.yml (the commit, not tag object 0f7370cc)
  • ruby/setup-ruby v1.324.0 → v1.327.0 = 14594264cd68ce8a2345dd349bc3d138a4ef85c8, in quality.yml
  • trufflesecurity/trufflehog v3.97.6 → v3.97.9 = 4dd8831c5f12599465d4d45c3c447b4018a34c85, in security-policy.yml
  • removed: github/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63, which is no longer referenced by codeql.yml or security-policy.yml

Lockfile records: rustls 0.23.45, rustls-webpki 0.103.15, aws-lc-rs 1.18.1, aws-lc-sys 0.45.0 (Cargo.lock). In scripts/ci-tools/Cargo.lock: rustls 0.23.45 and rustls-webpki 0.103.15.

No uses: lines changed. Dependabot had already bumped them on main.

How has this been verified?

  • cargo +1.99.0 fmt --all -- --check returned rc 0.
  • cargo +1.99.0 clippy --workspace --all-targets --locked -- -D warnings returned rc 0, both before and after the lock bump. Positive control: the same command on the original fetch_update failed with the deprecation error (rc 101).
  • cargo clippy --locked -D warnings for scripts/ci-tools returned rc 0. cargo check --workspace --all-targets --locked finished.
  • gh actions-lock --verify (v0.1.6) on origin/main reported 6 of 32 workflows failed. On this branch it prints only Scanning 32 workflows, with no failures.
  • Baseline gate, reproduced locally with the same pinned scanner the gate uses (hypatia 0e913426, built with mix escript.build), then HYPATIA_FORMAT=json hypatia-cli.sh scan ., path relativisation, and standards scripts/apply-baseline.sh … blocking:
    • origin/main tree: 12 kept findings (the same 9 unpinned_action and 3 secret_detected as CI), rc 1. This is the planted positive.
    • this branch's tree: 0 kept findings, rc 0.
    • With BLOCKING_THRESHOLD=info (CI's threshold), main printed Gate failed: 12 unfiltered finding(s) at or above 'info' (rc 1) and this branch returned rc 0.
  • grep -rn b96794f .github/ finds nothing on this branch, so no uses: line still names the removed codeql-action ref. The positive control grep -c 83ac0ad actions.lock returns 1.
  • Toolchain floor for try_update: there is no rust-toolchain file and no rust-version in any Cargo.toml, and every workflow's dtolnay/rust-toolchain step uses toolchain: stable. No job runs a pre-1.95 compiler.
  • A regex sweep of scanner_suppression.ex for the three form-ambiguous secret patterns now matches only lines the scanner already suppresses: line 275 (inline directive), plus a shell-expansion example, an env-default example and a test- fixture example. Line 275 was never reported.

Checklist

  • My commits are signed (git commit -S). %G? shows G.
  • I ran the project's own checks/tests locally and they pass: fmt, clippy, check, actions-lock verify and the baseline gate, as above. mix test was not run; the only Elixir change is a comment.
  • New files carry the correct SPDX-License-Identifier: not applicable, no new files.
  • Docs are updated, and no public claim now overstates what the code does. The reworded comment states the same rule.
  • I have not introduced a soundness hole. No suppression or baseline entry was added. The secret findings were removed at the source, so any real credential in that file still fails the gate.

Notes for reviewers

  • I edited the lock by hand. gh actions-lock rewrite mode was not used.
  • The baseline gate runs hypatia pinned at 0e913426 (2026-09-06). That version predates the comment-masking logic now on main, which is why a doc comment was reported as critical.

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

- cli/src/app_state.rs: AtomicU32::fetch_update -> try_update. Rust 1.99
  deprecates fetch_update, and `clippy -D warnings` turned the deprecation
  into the Cargo check + clippy + fmt / Clippy failure.
- .github/workflows/actions.lock: Dependabot bumped four `uses:` refs
  without updating the lock (startup-time ref-changed errors). Re-recorded
  taiki-e/install-action v2.87.22, haskell-actions/setup v2.12.1,
  ruby/setup-ruby v1.327.0 and trufflesecurity/trufflehog v3.97.9 against
  their COMMIT shas (each verified via git/commits = 200), and dropped the
  github/codeql-action@b96794f entry that no workflow references any more.
  `gh actions-lock --verify`: 6 of 32 failing -> 0.
- Cargo.lock, scripts/ci-tools/Cargo.lock: rustls 0.23.40 -> 0.23.45
  (GHSA-2mjx-qc3c-rqvc; Dependabot reported security_update_not_possible,
  but 0.23.45 resolves).
- lib/hypatia/scanner_suppression.ex: reword one doc comment so it no longer
  contains quoted `secret:` / `password =` literals. The pinned baseline
  scanner (0e91342) reported them as three critical secret_detected
  findings. With the lock fixed, the nine unpinned_action findings clear too:
  the pinned scanner, run locally, keeps 12 findings on origin/main and 0 on
  this branch.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: d287bcd0-770f-4b2f-b6ea-986199e06a84
📥 Commits

Reviewing files that changed from the base of the PR and between fabe659 and 7937dff.

⛔ Files ignored due to path filters (3)
  • .github/workflows/actions.lock is excluded by !**/*.lock
  • Cargo.lock is excluded by !**/*.lock
  • scripts/ci-tools/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • cli/src/app_state.rs
  • lib/hypatia/scanner_suppression.ex
 ____________________________________________________________
< When you say, “I meant to do that,” I totally believe you. >
 ------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • 🔴 Error committing to branch - (🔄 Check to retry)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 6, 2026 21:03
@hyperpolymath
hyperpolymath merged commit 1f30497 into main Oct 6, 2026
67 of 69 checks passed
@hyperpolymath
hyperpolymath deleted the fix/redci-cleanup branch October 6, 2026 21:05
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autopilot

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

❌ Failed to create Coding Agent finishing-touch task. Please try again.

hyperpolymath added a commit that referenced this pull request Oct 8, 2026
….38.2 symbolic (#914, #901) (#915)

## Summary

This relocks `.github/workflows/actions.lock` for the refs Dependabot
bumped without regenerating the lock. That desync is the consistent
explanation for the four workflows that die at startup on `main`: `CI`,
`Tests (E2E / Integration / Stress / Bench)`, `Security` and `Build
Gossamer GUI`. While they do, **hypatia CI runs no Elixir test suite at
all**. This PR also fixes the `codeql.yml` startup death (#901).

The lock was regenerated with the estate tool, `hyperpolymath/standards`
`scripts/update-actions-lock.sh` (standards `origin/main` @ `900c42c7`,
`gh-actions-lock` v0.1.6), not edited by hand. The same procedure fixed
gitbot-fleet in hyperpolymath/gitbot-fleet#605.

- `taiki-e/install-action` `v2.87.22` → `v2.87.24`, in
`build-gossamer-gui.yml`, `ci.yml`, `security-policy.yml` and
`tests.yml`.
- `hyperpolymath/smtp-notify-action` `v0.3.0` → `v0.5.0`, in
`push-email-notify.yml`.
- `github/codeql-action`: the tool rewrote the bare-SHA refs
`@2892aa5e…` (5 lines across `codeql.yml` and `security-policy.yml`) to
the symbolic `@v4.38.2` and locked `v4.38.2` → `2892aa5e…`. **This is
the same commit**, so the code that runs does not change. It is the fix
pattern #901 prescribes ("symbolic; the lock carries the SHA"), and it
drops the false `# v4.38.0` label on that commit.

Closes #914
Closes #901

## Type of change

- [x] 🐛 Bug fix: a lockfile desync on `main` that kills 5 workflows at
startup and turns 2 governance checks red.
- [ ] ✨ New feature: not applicable.
- [ ] 💥 Breaking change: none. Every workflow already used the new refs;
only the lock catches up. The codeql commit is unchanged.
- [ ] 🕳️ Soundness fix: not a checker or proof change. It does restore
CI test execution, which was silently absent.
- [ ] 📖 Documentation: no docs change.
- [ ] 🧹 Refactor / tech debt: not applicable.
- [ ] ⚡ Performance: not applicable.
- [x] 🔧 Build / CI / tooling: `actions.lock` regeneration, plus the
tool's codeql ref rewrite.

## 📌 New pins

- **PR head SHA: `ddc77bc2fa8ab0241a8367ab2f53344eb9316071`**
- **`actions.lock`: `taiki-e/install-action@v2.87.24` → commit
`e407f7bafb71fd004bc5c2da3032e5470cbb6ef0`.** It replaces `@v2.87.22`
(`83ac0ad6…`).
- **`actions.lock`: `hyperpolymath/smtp-notify-action@v0.5.0` → commit
`c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef`.** It replaces `@v0.3.0`
(`22e7bdb3…`).
- **`actions.lock`: new `github/codeql-action@v4.38.2` → commit
`2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`**, now listed under
`codeql.yml` and `security-policy.yml`.
- **Workflow `uses:`**:
`github/codeql-action/{init,analyze,upload-sarif}@2892aa5e…` →
`@v4.38.2`, on 5 lines. Same commit.
- All three tags were checked with `git ls-remote` against the peeled
commit (`refs/tags/<t>^{}`), not the annotated tag object.
- No other `uses:` line, lockfile record or container digest changes.

## How has this been verified?

All commands were run in the PR worktree at the head above, unless
stated otherwise.

- `update-actions-lock.sh`, update mode: exit **0**. It reports "Pinned
3 actions across 6 workflows", and its built-in `verify_lock_coverage`
pass also succeeded.
- `gh actions-lock --no-fix`: exit **0**.
- **Positive control:** the same `gh actions-lock --no-fix` on a `git
archive origin/main` export exits **1**. It prints 4 × `Ref changed
taiki-e/install-action@v2.87.24`, 4 × `Unused lockfile entry
…@v2.87.22`, `Ref changed hyperpolymath/smtp-notify-action@v0.5.0` and
`Unused lockfile entry …@v0.3.0`, which are exactly #914's findings. So
the pass above is not vacuous.
- `git ls-remote` for each tag: `taiki-e/install-action` `v2.87.24^{}` =
`e407f7ba…`, `github/codeql-action` `v4.38.2^{}` = `2892aa5e…`,
`hyperpolymath/smtp-notify-action` `v0.5.0^{}` = `c1c9fa07…`. All three
match the lock.
- `actionlint` on the two rewritten workflows: 25 findings, all
`[shellcheck]` info-level, **identical** to the same files on
`origin/main` (compared with line numbers stripped). None are
introduced.
- `git log -1 --show-signature` reports a good ED25519 signature, as
`required_signatures` needs.
- **CI on this head confirms it.** GitHub's startup enforcement and the
pinned governance scanner run only in CI. On `ddc77bc2`:
- **`governance / Validate Hypatia Baseline` passes.** So the relock
alone cleared the 5 `unpinned_action` findings, with no inline SHA pins
and no re-ACK.
- The previously dead workflows now start and pass, including `CI
Status`, `Rust Tests`, `Cargo test`, `Integration Tests`, `E2E — Elixir
Scanner Pipeline`, `stress-test`, `CodeQL` and `CodeQL Analysis
(actions)`.
- `Build Gossamer GUI` has a `paths:` filter this PR doesn't match, so
it was run with `workflow_dispatch` on this branch. [Run
37833436482](https://github.com/hyperpolymath/hypatia/actions/runs/37833436482)
succeeded, 3/3 jobs. Its last three runs elsewhere, including `main`,
were all `startup_failure`.
  - `governance / Actions lockfile verify` passes.
- All 4 required contexts pass: `abi-codegen-drift`, `zig build test
(FFI + wire contract)`, `Escript packaging soundness` and `scan /
gitleaks`.

### Red checks, deferred

`security-policy.yml` now runs for the first time since the desync, and
three of its jobs fail. **None of them is caused by this PR**, and none
is required. Root causes and acceptance criteria are in #916:

- `Rust Dependency Audit`: deferred to #916. Two real advisories in
`Cargo.lock`, RUSTSEC-2026-0204 (`crossbeam-epoch`) and
RUSTSEC-2026-0258 (`h2`).
- `Rust License & Ban Check`: deferred to #916. The workflow generates a
`deny.toml` that current cargo-deny cannot parse (`unmaintained =
"warn"`).
- `Security Status`: deferred to #916. The orphan-job self-check reads
the workflow file without a checkout step and crashes with exit 2.

## Checklist

- [x] My commits are **signed**: SSH ED25519, verified locally.
- [x] I ran the project's own checks locally and they pass: the estate
lock tooling, as above. There are no Elixir code changes, so the Elixir
suite is not affected. CI on this head is its first chance to run at
all.
- [x] New files carry the correct `SPDX-License-Identifier`: no new
files. `actions.lock` is machine-generated ("Do not edit by hand") and
carries no header, as before.
- [x] Docs are updated, and no public claim now overstates what the code
does: no doc describes the lock contents.
- [x] I have not introduced a soundness hole. The refs resolve to
immutable commits, and no check was muted, demoted or set
`continue-on-error`.

## Notes for reviewers

- **A correction to #914.** #914 says the `Validate Hypatia Baseline`
failure "is not fixed by a relock". That was wrong.
`lib/rules/workflow_audit.ex:317-333` treats any ref the lock vouches
for as pinned (`ActionsLock.pinned?`), and #908 measured exactly that: 9
× `unpinned_action` cleared with a relock alone. CI on this head
confirms it: the Baseline check passes with no inline SHA pins and no
baseline re-ACK. The same comment records why inline SHA-pinning would
be a **regression** here: on 2026-08-07, inline-pinning 40 refs put 14
workflows into `startup_failure`.
- **`Closes #914` is earned.** All 5 workflows that died at startup now
start on this head. What they found once running is tracked in #916, not
here.
- This repository is where the estate's lock tooling is developed
(#901), so the lock and the workflows now agree again in both
directions.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant