Skip to content

fix(ci): relock actions.lock for Dependabot-bumped refs; codeql to v4.38.2 symbolic (#914, #901) - #915

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/actions-lock-relock-914
Oct 8, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/actions-lock-relock-914

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

This relocks .github/workflows/actions.lock for the refs Dependabot bumped without regenerating the lock. That desync is the consistent explanation for the four workflows that die at startup on main: CI, Tests (E2E / Integration / Stress / Bench), Security and Build Gossamer GUI. While they do, hypatia CI runs no Elixir test suite at all. This PR also fixes the codeql.yml startup death (#901).

The lock was regenerated with the estate tool, hyperpolymath/standards scripts/update-actions-lock.sh (standards origin/main @ 900c42c7, gh-actions-lock v0.1.6), not edited by hand. The same procedure fixed gitbot-fleet in hyperpolymath/gitbot-fleet#605.

  • taiki-e/install-action v2.87.22 → v2.87.24, in build-gossamer-gui.yml, ci.yml, security-policy.yml and tests.yml.
  • hyperpolymath/smtp-notify-action v0.3.0 → v0.5.0, in push-email-notify.yml.
  • github/codeql-action: the tool rewrote the bare-SHA refs @2892aa5e… (5 lines across codeql.yml and security-policy.yml) to the symbolic @v4.38.2 and locked v4.38.2 → 2892aa5e…. This is the same commit, so the code that runs does not change. It is the fix pattern codeql.yml uses a bare commit the lock does not vouch for, and mislabels it as v4.38.0 #901 prescribes ("symbolic; the lock carries the SHA"), and it drops the false # v4.38.0 label on that commit.

Closes #914
Closes #901

Type of change

  • 🐛 Bug fix: a lockfile desync on main that kills 5 workflows at startup and turns 2 governance checks red.
  • ✨ New feature: not applicable.
  • 💥 Breaking change: none. Every workflow already used the new refs; only the lock catches up. The codeql commit is unchanged.
  • 🕳️ Soundness fix: not a checker or proof change. It does restore CI test execution, which was silently absent.
  • 📖 Documentation: no docs change.
  • 🧹 Refactor / tech debt: not applicable.
  • ⚡ Performance: not applicable.
  • 🔧 Build / CI / tooling: actions.lock regeneration, plus the tool's codeql ref rewrite.

📌 New pins

  • PR head SHA: ddc77bc2fa8ab0241a8367ab2f53344eb9316071
  • actions.lock: taiki-e/install-action@v2.87.24 → commit e407f7bafb71fd004bc5c2da3032e5470cbb6ef0. It replaces @v2.87.22 (83ac0ad6…).
  • actions.lock: hyperpolymath/smtp-notify-action@v0.5.0 → commit c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef. It replaces @v0.3.0 (22e7bdb3…).
  • actions.lock: new github/codeql-action@v4.38.2 → commit 2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2, now listed under codeql.yml and security-policy.yml.
  • Workflow uses:: github/codeql-action/{init,analyze,upload-sarif}@2892aa5e… → @v4.38.2, on 5 lines. Same commit.
  • All three tags were checked with git ls-remote against the peeled commit (refs/tags/<t>^{}), not the annotated tag object.
  • No other uses: line, lockfile record or container digest changes.

How has this been verified?

All commands were run in the PR worktree at the head above, unless stated otherwise.

  • update-actions-lock.sh, update mode: exit 0. It reports "Pinned 3 actions across 6 workflows", and its built-in verify_lock_coverage pass also succeeded.
  • gh actions-lock --no-fix: exit 0.
  • Positive control: the same gh actions-lock --no-fix on a git archive origin/main export exits 1. It prints 4 × Ref changed taiki-e/install-action@v2.87.24, 4 × Unused lockfile entry …@v2.87.22, Ref changed hyperpolymath/smtp-notify-action@v0.5.0 and Unused lockfile entry …@v0.3.0, which are exactly actions.lock desync (taiki-e v2.87.24, smtp-notify v0.5.0) turns lockfile-verify and Hypatia Baseline red on main #914's findings. So the pass above is not vacuous.
  • git ls-remote for each tag: taiki-e/install-action v2.87.24^{} = e407f7ba…, github/codeql-action v4.38.2^{} = 2892aa5e…, hyperpolymath/smtp-notify-action v0.5.0^{} = c1c9fa07…. All three match the lock.
  • actionlint on the two rewritten workflows: 25 findings, all [shellcheck] info-level, identical to the same files on origin/main (compared with line numbers stripped). None are introduced.
  • git log -1 --show-signature reports a good ED25519 signature, as required_signatures needs.
  • CI on this head confirms it. GitHub's startup enforcement and the pinned governance scanner run only in CI. On ddc77bc2:
    • governance / Validate Hypatia Baseline passes. So the relock alone cleared the 5 unpinned_action findings, with no inline SHA pins and no re-ACK.
    • The previously dead workflows now start and pass, including CI Status, Rust Tests, Cargo test, Integration Tests, E2E — Elixir Scanner Pipeline, stress-test, CodeQL and CodeQL Analysis (actions).
    • Build Gossamer GUI has a paths: filter this PR doesn't match, so it was run with workflow_dispatch on this branch. Run 37833436482 succeeded, 3/3 jobs. Its last three runs elsewhere, including main, were all startup_failure.
    • governance / Actions lockfile verify passes.
    • All 4 required contexts pass: abi-codegen-drift, zig build test (FFI + wire contract), Escript packaging soundness and scan / gitleaks.

Red checks, deferred

security-policy.yml now runs for the first time since the desync, and three of its jobs fail. None of them is caused by this PR, and none is required. Root causes and acceptance criteria are in #916:

Checklist

  • My commits are signed: SSH ED25519, verified locally.
  • I ran the project's own checks locally and they pass: the estate lock tooling, as above. There are no Elixir code changes, so the Elixir suite is not affected. CI on this head is its first chance to run at all.
  • New files carry the correct SPDX-License-Identifier: no new files. actions.lock is machine-generated ("Do not edit by hand") and carries no header, as before.
  • Docs are updated, and no public claim now overstates what the code does: no doc describes the lock contents.
  • I have not introduced a soundness hole. The refs resolve to immutable commits, and no check was muted, demoted or set continue-on-error.

Notes for reviewers

🤖 Generated with Claude Code

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

….38.2 symbolic

Regenerated with hyperpolymath/standards scripts/update-actions-lock.sh
(standards 900c42c7, gh-actions-lock v0.1.6), not edited by hand:

- taiki-e/install-action v2.87.22 -> v2.87.24 (commit e407f7ba), in
  build-gossamer-gui, ci, security-policy and tests;
- hyperpolymath/smtp-notify-action v0.3.0 -> v0.5.0 (commit c1c9fa07),
  in push-email-notify;
- github/codeql-action: the tool rewrote the bare 2892aa5e refs in
  codeql.yml and security-policy.yml to the symbolic v4.38.2 and locked
  v4.38.2 -> 2892aa5e. Same commit. Drops the false "# v4.38.0" label.

Closes #914
Closes #901

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 37 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5b384f13-94f8-47a5-a523-4da023c830c2
📥 Commits

Reviewing files that changed from the base of the PR and between cce505d and ddc77bc.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (2)
  • .github/workflows/codeql.yml
  • .github/workflows/security-policy.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 69cf5ca into main Oct 8, 2026
90 of 93 checks passed
@hyperpolymath
hyperpolymath deleted the fix/actions-lock-relock-914 branch October 8, 2026 19:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant