Repository navigation
fix(ci): clear hypatia's red checks (try_update, Dependabot lock entries, rustls, baseline) - #908
Merged
Merged
Conversation
- cli/src/app_state.rs: AtomicU32::fetch_update -> try_update. Rust 1.99 deprecates fetch_update, and `clippy -D warnings` turned the deprecation into the Cargo check + clippy + fmt / Clippy failure. - .github/workflows/actions.lock: Dependabot bumped four `uses:` refs without updating the lock (startup-time ref-changed errors). Re-recorded taiki-e/install-action v2.87.22, haskell-actions/setup v2.12.1, ruby/setup-ruby v1.327.0 and trufflesecurity/trufflehog v3.97.9 against their COMMIT shas (each verified via git/commits = 200), and dropped the github/codeql-action@b96794f entry that no workflow references any more. `gh actions-lock --verify`: 6 of 32 failing -> 0. - Cargo.lock, scripts/ci-tools/Cargo.lock: rustls 0.23.40 -> 0.23.45 (GHSA-2mjx-qc3c-rqvc; Dependabot reported security_update_not_possible, but 0.23.45 resolves). - lib/hypatia/scanner_suppression.ex: reword one doc comment so it no longer contains quoted `secret:` / `password =` literals. The pinned baseline scanner (0e91342) reported them as three critical secret_detected findings. With the lock fixed, the nine unpinned_action findings clear too: the pinned scanner, run locally, keeps 12 findings on origin/main and 0 on this branch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (3)
📒 Files selected for processing (2)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
Add Carrot credits or activate Agent usage billing to use Autopilot |
Contributor
|
❌ Failed to create Coding Agent finishing-touch task. Please try again. |
This was referenced Oct 8, 2026
hyperpolymath
added a commit
that referenced
this pull request
Oct 8, 2026
….38.2 symbolic (#914, #901) (#915) ## Summary This relocks `.github/workflows/actions.lock` for the refs Dependabot bumped without regenerating the lock. That desync is the consistent explanation for the four workflows that die at startup on `main`: `CI`, `Tests (E2E / Integration / Stress / Bench)`, `Security` and `Build Gossamer GUI`. While they do, **hypatia CI runs no Elixir test suite at all**. This PR also fixes the `codeql.yml` startup death (#901). The lock was regenerated with the estate tool, `hyperpolymath/standards` `scripts/update-actions-lock.sh` (standards `origin/main` @ `900c42c7`, `gh-actions-lock` v0.1.6), not edited by hand. The same procedure fixed gitbot-fleet in hyperpolymath/gitbot-fleet#605. - `taiki-e/install-action` `v2.87.22` → `v2.87.24`, in `build-gossamer-gui.yml`, `ci.yml`, `security-policy.yml` and `tests.yml`. - `hyperpolymath/smtp-notify-action` `v0.3.0` → `v0.5.0`, in `push-email-notify.yml`. - `github/codeql-action`: the tool rewrote the bare-SHA refs `@2892aa5e…` (5 lines across `codeql.yml` and `security-policy.yml`) to the symbolic `@v4.38.2` and locked `v4.38.2` → `2892aa5e…`. **This is the same commit**, so the code that runs does not change. It is the fix pattern #901 prescribes ("symbolic; the lock carries the SHA"), and it drops the false `# v4.38.0` label on that commit. Closes #914 Closes #901 ## Type of change - [x] 🐛 Bug fix: a lockfile desync on `main` that kills 5 workflows at startup and turns 2 governance checks red. - [ ] ✨ New feature: not applicable. - [ ] 💥 Breaking change: none. Every workflow already used the new refs; only the lock catches up. The codeql commit is unchanged. - [ ] 🕳️ Soundness fix: not a checker or proof change. It does restore CI test execution, which was silently absent. - [ ] 📖 Documentation: no docs change. - [ ] 🧹 Refactor / tech debt: not applicable. - [ ] ⚡ Performance: not applicable. - [x] 🔧 Build / CI / tooling: `actions.lock` regeneration, plus the tool's codeql ref rewrite. ## 📌 New pins - **PR head SHA: `ddc77bc2fa8ab0241a8367ab2f53344eb9316071`** - **`actions.lock`: `taiki-e/install-action@v2.87.24` → commit `e407f7bafb71fd004bc5c2da3032e5470cbb6ef0`.** It replaces `@v2.87.22` (`83ac0ad6…`). - **`actions.lock`: `hyperpolymath/smtp-notify-action@v0.5.0` → commit `c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef`.** It replaces `@v0.3.0` (`22e7bdb3…`). - **`actions.lock`: new `github/codeql-action@v4.38.2` → commit `2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`**, now listed under `codeql.yml` and `security-policy.yml`. - **Workflow `uses:`**: `github/codeql-action/{init,analyze,upload-sarif}@2892aa5e…` → `@v4.38.2`, on 5 lines. Same commit. - All three tags were checked with `git ls-remote` against the peeled commit (`refs/tags/<t>^{}`), not the annotated tag object. - No other `uses:` line, lockfile record or container digest changes. ## How has this been verified? All commands were run in the PR worktree at the head above, unless stated otherwise. - `update-actions-lock.sh`, update mode: exit **0**. It reports "Pinned 3 actions across 6 workflows", and its built-in `verify_lock_coverage` pass also succeeded. - `gh actions-lock --no-fix`: exit **0**. - **Positive control:** the same `gh actions-lock --no-fix` on a `git archive origin/main` export exits **1**. It prints 4 × `Ref changed taiki-e/install-action@v2.87.24`, 4 × `Unused lockfile entry …@v2.87.22`, `Ref changed hyperpolymath/smtp-notify-action@v0.5.0` and `Unused lockfile entry …@v0.3.0`, which are exactly #914's findings. So the pass above is not vacuous. - `git ls-remote` for each tag: `taiki-e/install-action` `v2.87.24^{}` = `e407f7ba…`, `github/codeql-action` `v4.38.2^{}` = `2892aa5e…`, `hyperpolymath/smtp-notify-action` `v0.5.0^{}` = `c1c9fa07…`. All three match the lock. - `actionlint` on the two rewritten workflows: 25 findings, all `[shellcheck]` info-level, **identical** to the same files on `origin/main` (compared with line numbers stripped). None are introduced. - `git log -1 --show-signature` reports a good ED25519 signature, as `required_signatures` needs. - **CI on this head confirms it.** GitHub's startup enforcement and the pinned governance scanner run only in CI. On `ddc77bc2`: - **`governance / Validate Hypatia Baseline` passes.** So the relock alone cleared the 5 `unpinned_action` findings, with no inline SHA pins and no re-ACK. - The previously dead workflows now start and pass, including `CI Status`, `Rust Tests`, `Cargo test`, `Integration Tests`, `E2E — Elixir Scanner Pipeline`, `stress-test`, `CodeQL` and `CodeQL Analysis (actions)`. - `Build Gossamer GUI` has a `paths:` filter this PR doesn't match, so it was run with `workflow_dispatch` on this branch. [Run 37833436482](https://github.com/hyperpolymath/hypatia/actions/runs/37833436482) succeeded, 3/3 jobs. Its last three runs elsewhere, including `main`, were all `startup_failure`. - `governance / Actions lockfile verify` passes. - All 4 required contexts pass: `abi-codegen-drift`, `zig build test (FFI + wire contract)`, `Escript packaging soundness` and `scan / gitleaks`. ### Red checks, deferred `security-policy.yml` now runs for the first time since the desync, and three of its jobs fail. **None of them is caused by this PR**, and none is required. Root causes and acceptance criteria are in #916: - `Rust Dependency Audit`: deferred to #916. Two real advisories in `Cargo.lock`, RUSTSEC-2026-0204 (`crossbeam-epoch`) and RUSTSEC-2026-0258 (`h2`). - `Rust License & Ban Check`: deferred to #916. The workflow generates a `deny.toml` that current cargo-deny cannot parse (`unmaintained = "warn"`). - `Security Status`: deferred to #916. The orphan-job self-check reads the workflow file without a checkout step and crashes with exit 2. ## Checklist - [x] My commits are **signed**: SSH ED25519, verified locally. - [x] I ran the project's own checks locally and they pass: the estate lock tooling, as above. There are no Elixir code changes, so the Elixir suite is not affected. CI on this head is its first chance to run at all. - [x] New files carry the correct `SPDX-License-Identifier`: no new files. `actions.lock` is machine-generated ("Do not edit by hand") and carries no header, as before. - [x] Docs are updated, and no public claim now overstates what the code does: no doc describes the lock contents. - [x] I have not introduced a soundness hole. The refs resolve to immutable commits, and no check was muted, demoted or set `continue-on-error`. ## Notes for reviewers - **A correction to #914.** #914 says the `Validate Hypatia Baseline` failure "is not fixed by a relock". That was wrong. `lib/rules/workflow_audit.ex:317-333` treats any ref the lock vouches for as pinned (`ActionsLock.pinned?`), and #908 measured exactly that: 9 × `unpinned_action` cleared with a relock alone. CI on this head confirms it: the Baseline check passes with no inline SHA pins and no baseline re-ACK. The same comment records why inline SHA-pinning would be a **regression** here: on 2026-08-07, inline-pinning 40 refs put 14 workflows into `startup_failure`. - **`Closes #914` is earned.** All 5 workflows that died at startup now start on this head. What they found once running is tracked in #916, not here. - This repository is where the estate's lock tooling is developed (#901), so the lock and the workflows now agree again in both directions. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR clears four red gates on
main(fabe659) in one commit.use of deprecated method std::sync::atomic::Atomic::<u32>::fetch_update: renamed to try_update(-D warnings, Rust 1.99)cli/src/app_state.rs:58:fetch_update→try_update. Same semantics; available since Rust 1.95.##[error]actions-lock gate: lockfile verification FAILED (exit 1)(ref-changed: Dependabot bumpeduses:refs without updating the lock).github/workflows/actions.lockagainst their commit SHAs, and removed an unreferencedgithub/codeql-action@b96794fentry.security_update_not_possiblefor rustls GHSA-2mjx-qc3c-rqvc (alerts #35, #36)Cargo.lockandscripts/ci-tools/Cargo.lock. 0.23.45 resolves fine. Transitive bumps: rustls-webpki 0.103.15, aws-lc-rs 1.18.1, aws-lc-sys 0.45.0.##[error]Gate failed: 12 unfiltered finding(s) at or above 'info'.unpinned_actioncame from the stale lock and clear with the lock fix: the pinned scanner is lockfile-aware. 3 ×secret_detectedatlib/hypatia/scanner_suppression.ex:360,361,363were quotedsecret:/password =examples in a doc comment; I reworded the comment so it carries no quoted literal. No baseline entry was added and the gate is not weakened.Not addressed (owner items): mirror-* (standards#950); Codeac (third-party App).
Closes: no issue; found by the 2026-10-06 red-CI census.
Type of change
try_updateis behaviour-identical, and the dependency bumps are patch/minor.scanner_suppression.ex.📌 New pins
Head SHA: 7937dff
.github/workflows/actions.lock. Each commit was checked withgh api repos/O/R/git/commits/<sha>(200). Owner and repo ids are unchanged. None of the new versions has transitiveuses:.taiki-e/install-actionv2.87.18 → v2.87.22 =83ac0ad63c0167e6f06796fab0fce28db1bf3db0, in build-gossamer-gui.yml, ci.yml, security-policy.yml and tests.ymlhaskell-actions/setupv2.12.0 → v2.12.1 =0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d, in ci.yml (the commit, not tag object0f7370cc)ruby/setup-rubyv1.324.0 → v1.327.0 =14594264cd68ce8a2345dd349bc3d138a4ef85c8, in quality.ymltrufflesecurity/trufflehogv3.97.6 → v3.97.9 =4dd8831c5f12599465d4d45c3c447b4018a34c85, in security-policy.ymlgithub/codeql-action@b96794f015dfd88f77b49b1c93e0fa7110f94c63, which is no longer referenced by codeql.yml or security-policy.ymlLockfile records: rustls 0.23.45, rustls-webpki 0.103.15, aws-lc-rs 1.18.1, aws-lc-sys 0.45.0 (Cargo.lock). In scripts/ci-tools/Cargo.lock: rustls 0.23.45 and rustls-webpki 0.103.15.
No
uses:lines changed. Dependabot had already bumped them on main.How has this been verified?
cargo +1.99.0 fmt --all -- --checkreturned rc 0.cargo +1.99.0 clippy --workspace --all-targets --locked -- -D warningsreturned rc 0, both before and after the lock bump. Positive control: the same command on the originalfetch_updatefailed with the deprecation error (rc 101).cargo clippy --locked -D warningsforscripts/ci-toolsreturned rc 0.cargo check --workspace --all-targets --lockedfinished.gh actions-lock --verify(v0.1.6) on origin/main reported6 of 32 workflows failed. On this branch it prints onlyScanning 32 workflows, with no failures.0e913426, built withmix escript.build), thenHYPATIA_FORMAT=json hypatia-cli.sh scan ., path relativisation, and standardsscripts/apply-baseline.sh … blocking:BLOCKING_THRESHOLD=info(CI's threshold), main printedGate failed: 12 unfiltered finding(s) at or above 'info'(rc 1) and this branch returned rc 0.grep -rn b96794f .github/finds nothing on this branch, so nouses:line still names the removed codeql-action ref. The positive controlgrep -c 83ac0ad actions.lockreturns 1.try_update: there is norust-toolchainfile and norust-versionin any Cargo.toml, and every workflow'sdtolnay/rust-toolchainstep usestoolchain: stable. No job runs a pre-1.95 compiler.scanner_suppression.exfor the three form-ambiguous secret patterns now matches only lines the scanner already suppresses: line 275 (inline directive), plus a shell-expansion example, an env-default example and atest-fixture example. Line 275 was never reported.Checklist
git commit -S).%G?showsG.mix testwas not run; the only Elixir change is a comment.SPDX-License-Identifier: not applicable, no new files.Notes for reviewers
gh actions-lockrewrite mode was not used.0e913426(2026-09-06). That version predates the comment-masking logic now on main, which is why a doc comment was reported ascritical.🤖 Generated with Claude Code
https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm