Repository navigation
chore(deps): bump the actions group with 4 updates - #140
Merged
Merged
Conversation
Bumps the actions group with 4 updates: [haskell-actions/setup](https://github.com/haskell-actions/setup), [github/codeql-action/upload-sarif](https://github.com/github/codeql-action), [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action). Updates `haskell-actions/setup` from 2.12.0 to 2.12.1 - [Release notes](https://github.com/haskell-actions/setup/releases) - [Commits](haskell-actions/setup@v2.12.0...v2.12.1) Updates `github/codeql-action/upload-sarif` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `github/codeql-action/init` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) Updates `github/codeql-action/analyze` from 4.38.0 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@b96794f...2892aa5) --- updated-dependencies: - dependency-name: haskell-actions/setup dependency-version: 2.12.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/init dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: actions ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
approved these changes
Sep 29, 2026
hyperpolymath
deleted the
dependabot/github_actions/actions-c42d929ac2
branch
September 29, 2026 08:44
6 of 8 tasks
hyperpolymath
added a commit
that referenced
this pull request
Sep 30, 2026
…he freeze bypass — with the sources cured (#141) ## What this sorts out Closes the acceptance criteria of #138 and goes after the three *sources* behind today's reds, in one change set. Each cure carries its inverse (januskey); nothing was muted, demoted, or removed from any required set (standards#994 AC5). ### 1. `lint-workflows` ×2 (issue #138) — determination: **FIXED** Two governors claimed the same byte: `gh actions-lock` inserts `# This workflow is managed by gh actions-lock.` at **line 1** whenever it mints or refreshes a lockfile, while the local `Check SPDX headers` step demanded the SPDX identifier on **line 1**. Every lock refresh re-failed the check. Measured same-commit (`a045f44`): | check | predicate | result on identical files | |---|---|---| | `lint-workflows` (local `workflow-linter.yml`) | SPDX on `head -1` | 🔴 18 of 19 files "missing" headers they all have (including its own file) | | `governance / Workflow security linter` (canonical, `standards@fad242d`) | SPDX in the leading comment block | 🟢 green | The canonical predicate has existed in `hyperpolymath/standards` `governance-reusable.yml` **since 2026-08-07**, with the exact warning recorded: a line-1 test "fights the estate's own tool and re-fails every time a lockfile is refreshed" — it falsely reported 27 hypatia + 13 other workflows and "fixing" it mis-licensed 3 files. The local copy was a stale divergent mutant of the estate's own check. The fix converges the local copy to the canonical form (`scripts/check-workflow-headers.sh`, byte-faithful): SPDX anywhere in the leading comment block (banner- and doc-marker-tolerant) + top-level `permissions:`. Same requirements, correct frame. Job name `lint-workflows` kept; the check stays blocking. **Expected-rejection controls** (`--self-test`, from occupancy-types' gate contract and pons-asinorum's falsifier rule): 3 fixtures that must pass and 2 that must be killed, run *first* in the job. A predicate that cannot kill its own mutant is a Certified Null Operation (absolute-zero) and is not allowed to judge the tree. This promotes PR #137's manual mutation notes into a permanent control. ### 2. The freeze bypass — determination: **FIXED** (gate-enforced) Dependabot #140 moved `github/codeql-action` `b96794f0` (v4.38.0) → `2892aa5e` (a 2026-09-24 `releases/v4` merge, `update-v4.38.2`) **in SHA form while copying the `# v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)` comment verbatim** — the witness of intent survived the rewrite with its meaning inverted. That pin is under an estate freeze (nexia-list#100: v4.38.1+ refused at startup; `standards` main still pins `b96794f0` today). This is the **second** documented bypass of the hold (nexia-list#101: versions-scope; nexia-list#104: unconditional; then this). An ignore rule is a request to a robot; this PR reverts the bump and adds `scripts/check-frozen-pins.sh` — the freeze as a check *this repo owns*, with its own mutants (SHA-form and tag-form bump both killed in self-test). Lifting the freeze becomes a deliberate, reviewable one-line table edit. ### 3. The lock re-desync (standards#968 class) — determination: **FIXED**, source cured #140 bumped `haskell-actions/setup` v2.12.1 and did not regenerate `actions.lock` ("60 of 60 repos have Dependabot AND a lockfile AND no regeneration step — repos appear to go bad again; nobody broke them, the clock did"). Measured on main today: Lock Sync Gate 🔴, `governance / Actions lockfile verify` 🔴, CodeQL + GitHub Pages `startup_failure` (jobs=0), cflite poised to die. The lock is re-synced (`haskell-actions/setup@v2.12.1` peeled via API; all four `check-lock-sync.sh` clauses verified), and `lock-sync-heal.yml` is the source cure: `gh actions-lock` (the sanctioned writer) on every workflow change + weekly backstop, opening one standing refresh PR whose body carries the checker's output as a **receipt** — obtained on the regenerated tree before the PR exists (epistemic-types: transported proof arrives with a sound check of the receiver's claim). Inverse: close the PR. ## Residue list (honest boundary, echo-types/OND) Not claimed, not erased — listed with dates: * `hypatia / Hypatia Neurosymbolic Analysis` — red on `main` since 2026-09-29 (`Build Hypatia scanner`). Cause not established from here (job logs unreachable from the triage sandbox); candidate classes: `hyperpolymath/hypatia` HEAD build-rot or transient hex.pm failure. It is standards#994's class 3; the reusable builds the scanner from a *moving HEAD*, which is the fragile contract. **It is a required context and may block this PR's merge mechanically** — per the stopping rule, nothing is required of a branch that its base does not satisfy. * `mirror / mirror-gitea`, `mirror / mirror-disroot` — red on `main` (infrastructure/credentials). Not measured further. ## Verification - [x] `bash -n` clean on every script and every `run:` block (extracted and parsed) - [x] YAML parse clean on every touched workflow + lockfile - [x] header predicate self-test: 3 accepted, 2 rejected - [x] freeze gate self-test: 1 accepted, 2 rejected (SHA-form + tag-form mutants killed) - [x] both predicates green on the full tree (all 20 workflow files) - [x] `check-lock-sync.sh` clauses 1–4 pass on the repaired lock (verified via a clause-faithful port; gawk is not in the triage sandbox — the gate itself runs the real script on ubuntu-latest) - [ ] `lint-workflows` green on this PR head (both legs) - [ ] Lock Sync Gate green on this PR head ## Theory basis (full map in `docs/ci-guard-cures-2026-09-29.adoc`) pons-asinorum (contradiction taxonomy; negative corpus) · absolute-zero (CNO vacuous gates; OND residue lists) · januskey (inversion metadata; shared core over divergent copies) · echo-types (structured loss; comments that outlive their meaning) · epistemic-types (warrant ≠ knowledge; receipts) · choreographic-types (YAML+lock is one cut) · occupancy-types (expected-rejection controls; rung contracts) · panic-attack (signatures: `TWO-GOVERNORS-ONE-INVARIANT`, `ROBOT-PROMISE-WITHOUT-GATE`, `STATE-CURE-WITHOUT-SOURCE-CURE`). 🤖 Generated with [Claude Code](https://claude.com/claude-code) --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the actions group with 4 updates: haskell-actions/setup, github/codeql-action/upload-sarif, github/codeql-action/init and github/codeql-action/analyze.
Updates
haskell-actions/setupfrom 2.12.0 to 2.12.1Release notes
Sourced from haskell-actions/setup's releases.
Commits
0f8e8c9Add Cabal 3.18.1.0 and Stack 3.11.1Updates
github/codeql-action/upload-sariffrom 4.38.0 to 4.38.2Release notes
Sourced from github/codeql-action/upload-sarif's releases.
Changelog
Sourced from github/codeql-action/upload-sarif's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
github/codeql-action/initfrom 4.38.0 to 4.38.2Release notes
Sourced from github/codeql-action/init's releases.
Changelog
Sourced from github/codeql-action/init's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildUpdates
github/codeql-action/analyzefrom 4.38.0 to 4.38.2Release notes
Sourced from github/codeql-action/analyze's releases.
Changelog
Sourced from github/codeql-action/analyze's changelog.
... (truncated)
Commits
2892aa5Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f8ad03a3Trigger workflows98af865Update changelog for v4.38.2a6ef2c9Merge pull request #4156 from github/mario-campos/fix-validate-cmd1ef28a1Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...26cb08bMerge pull request #4163 from github/mbg/fix-getCommitOid-stubsf035ce3Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...5e4e255Rebuildb13f5f4Bump ruby/setup-rubyc87fe57RebuildDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions