From ddc77bc2fa8ab0241a8367ab2f53344eb9316071 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 8 Oct 2026 20:25:20 +0100 Subject: [PATCH] fix(ci): relock actions.lock for Dependabot-bumped refs; codeql to v4.38.2 symbolic Regenerated with hyperpolymath/standards scripts/update-actions-lock.sh (standards 900c42c7, gh-actions-lock v0.1.6), not edited by hand: - taiki-e/install-action v2.87.22 -> v2.87.24 (commit e407f7ba), in build-gossamer-gui, ci, security-policy and tests; - hyperpolymath/smtp-notify-action v0.3.0 -> v0.5.0 (commit c1c9fa07), in push-email-notify; - github/codeql-action: the tool rewrote the bare 2892aa5e refs in codeql.yml and security-policy.yml to the symbolic v4.38.2 and locked v4.38.2 -> 2892aa5e. Same commit. Drops the false "# v4.38.0" label. Closes #914 Closes #901 Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML --- .github/workflows/actions.lock | 29 +++++++++++++++++---------- .github/workflows/codeql.yml | 4 ++-- .github/workflows/security-policy.yml | 6 +++--- 3 files changed, 23 insertions(+), 16 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 0f8a30f9..8a7e849d 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -14,7 +14,7 @@ workflows: - 'actions/setup-node@v7.0.0' - 'actions/upload-artifact@v7.0.1' - 'dtolnay/rust-toolchain@v1' - - 'taiki-e/install-action@v2.87.22' + - 'taiki-e/install-action@v2.87.24' '.github/workflows/ci-health-sweep.yml': - 'actions/checkout@v7.0.1' '.github/workflows/ci.yml': @@ -26,12 +26,13 @@ workflows: - 'haskell-actions/hlint-setup@v2.4.10' - 'haskell-actions/setup@v2.12.1' - 'swatinem/rust-cache@v2.9.2' - - 'taiki-e/install-action@v2.87.22' + - 'taiki-e/install-action@v2.87.24' '.github/workflows/clusterfuzzlite.yml': - 'actions/checkout@v7.0.1' - 'google/clusterfuzzlite@v1' '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' + - 'github/codeql-action@v4.38.2' '.github/workflows/dependabot-automerge.yml': - 'dependabot/fetch-metadata@v3.1.0' '.github/workflows/dogfood-gate.yml': @@ -62,7 +63,7 @@ workflows: - 'actions/deploy-pages@v5.0.1' - 'actions/upload-pages-artifact@v5.0.0' '.github/workflows/push-email-notify.yml': - - 'hyperpolymath/smtp-notify-action@v0.3.0' + - 'hyperpolymath/smtp-notify-action@v0.5.0' '.github/workflows/quality.yml': - 'actions/checkout@v7.0.1' - 'actions/deploy-pages@v5.0.1' @@ -98,8 +99,9 @@ workflows: - 'actions/upload-artifact@v7.0.1' - 'aquasecurity/trivy-action@v0.36.0' - 'dtolnay/rust-toolchain@v1' + - 'github/codeql-action@v4.38.2' - 'gitleaks/gitleaks-action@v3.0.0' - - 'taiki-e/install-action@v2.87.22' + - 'taiki-e/install-action@v2.87.24' - 'trufflesecurity/trufflehog@v3.97.9' '.github/workflows/tests.yml': - 'actions/cache@v6.1.0' @@ -111,7 +113,7 @@ workflows: - 'dtolnay/rust-toolchain@v1' - 'erlef/setup-beam@v1.24.1' - 'swatinem/rust-cache@v2.9.2' - - 'taiki-e/install-action@v2.87.22' + - 'taiki-e/install-action@v2.87.24' '.github/workflows/verify-proofs.yml': - 'actions/cache@v6.1.0' - 'actions/checkout@v7.0.1' @@ -261,6 +263,11 @@ dependencies: commit: 'sha1-54075bcc5e249e4758d363f27d099f55d843f124' owner_id: 47606891 repo_id: 331103973 + 'github/codeql-action@v4.38.2': + ref: 'v4.38.2' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' + owner_id: 9919 + repo_id: 259445878 'gitleaks/gitleaks-action@v3.0.0': ref: 'v3.0.0' commit: 'sha1-e0c47f4f8be36e29cdc102c57e68cb5cbf0e8d1e' @@ -296,9 +303,9 @@ dependencies: commit: 'sha1-c1a34884054fabf0e9de81dbf68f4ba7874e85f1' owner_id: 6759885 repo_id: 1275650185 - 'hyperpolymath/smtp-notify-action@v0.3.0': - ref: 'v0.3.0' - commit: 'sha1-22e7bdb322c430c1d0dac6b3bb307f4bb139d0be' + 'hyperpolymath/smtp-notify-action@v0.5.0': + ref: 'v0.5.0' + commit: 'sha1-c1c9fa07992a02c1fd3d67a0dc1b08cccb852aef' owner_id: 6759885 repo_id: 1352485172 'ruby/setup-ruby@v1.327.0': @@ -316,9 +323,9 @@ dependencies: commit: 'sha1-6323deb102c322ba6fcbdcafc7e3dddab59af2b6' owner_id: 580492 repo_id: 298565987 - 'taiki-e/install-action@v2.87.22': - ref: 'v2.87.22' - commit: 'sha1-83ac0ad63c0167e6f06796fab0fce28db1bf3db0' + 'taiki-e/install-action@v2.87.24': + ref: 'v2.87.24' + commit: 'sha1-e407f7bafb71fd004bc5c2da3032e5470cbb6ef0' owner_id: 43724913 repo_id: 442947557 'trufflesecurity/trufflehog@v3.97.9': diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 46bd4ad8..d08dd13a 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -47,12 +47,12 @@ jobs: persist-credentials: false - name: Initialize CodeQL - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/init@v4.38.2 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/analyze@v4.38.2 with: category: "/language:${{ matrix.language }}" diff --git a/.github/workflows/security-policy.yml b/.github/workflows/security-policy.yml index dd492535..e1483bf6 100644 --- a/.github/workflows/security-policy.yml +++ b/.github/workflows/security-policy.yml @@ -539,13 +539,13 @@ jobs: uses: actions/checkout@v7.0.1 - name: Initialize CodeQL - uses: github/codeql-action/init@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/init@v4.38.2 with: languages: ${{ matrix.language }} queries: security-extended,security-and-quality - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/analyze@v4.38.2 with: category: "/language:${{matrix.language}}" @@ -615,7 +615,7 @@ jobs: ignore-unfixed: true - name: Upload Trivy SARIF results - uses: github/codeql-action/upload-sarif@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2 # v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100) + uses: github/codeql-action/upload-sarif@v4.38.2 if: always() with: sarif_file: 'trivy-${{ steps.image.outputs.name }}.sarif'