Skip to content

chore(deps): bump dtolnay/rust-toolchain from 02cb101ec7c40f2c49e1d9714d64511d8e1b74de to 7e38f4b43b4db5c8dd498af069a4f6196df1d067 in the actions group - #1157

Merged
hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-4150328770
Oct 5, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
dependabot/github_actions/actions-4150328770

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the actions group with 1 update: dtolnay/rust-toolchain.

Updates dtolnay/rust-toolchain from 02cb101ec7c40f2c49e1d9714d64511d8e1b74de to 7e38f4b43b4db5c8dd498af069a4f6196df1d067

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the actions group with 1 update: [dtolnay/rust-toolchain](https://github.com/dtolnay/rust-toolchain).


Updates `dtolnay/rust-toolchain` from 02cb101ec7c40f2c49e1d9714d64511d8e1b74de to 7e38f4b43b4db5c8dd498af069a4f6196df1d067
- [Release notes](https://github.com/dtolnay/rust-toolchain/releases)
- [Commits](dtolnay/rust-toolchain@02cb101...7e38f4b)

---
updated-dependencies:
- dependency-name: dtolnay/rust-toolchain
  dependency-version: 7e38f4b43b4db5c8dd498af069a4f6196df1d067
  dependency-type: direct:production
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from hyperpolymath as a code owner October 5, 2026 13:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37317717944

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ERROR   K9-N001 [L2] 1-formats/k9/tools/fixtures/valid/extension-fields.k9.ncl: component violates the K9.Component contract: error: contract broken by a value        extra fields `failure_mode_defenses`, `execution`    ┌─ /home/runner/work/standards/standards/1-formats/k9/tools/fixtures/valid/.k9-validate.8988.30796.driver.ncl:3:1    │  3 │ k9_doc | K9.Component 
FAIL extension-fields.k9.ncl should conform (exit 1)
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 1 failure(s)

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: aef525f0-9ac7-474b-a2aa-e8ca7a76d20f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 8556163 into main Oct 5, 2026
39 of 51 checks passed
@hyperpolymath
hyperpolymath deleted the dependabot/github_actions/actions-4150328770 branch October 5, 2026 14:18
hyperpolymath added a commit that referenced this pull request Oct 6, 2026
Owner ruling D5c (standards#787): one ancestry assertion in standards,
called by every bumper; mandatory under D19a (squash-only), because a
squash merge is exactly what orphans a PR-head pin (standards#782).

Both bumpers already asserted ancestry, each with its own copy:
apply-workflow-pins-remote.sh (gh api) and propagate-workflow-pins.sh
(curl + sed). They now call scripts/lib/pin-ancestry.sh's
assert_pin_ancestry: 0 ancestor / 1 not an ancestor or malformed /
2 indeterminate. propagate keeps its full-clone local fast path; only
the server compare may say "no".

The status parse now takes the leftmost "status" (bash =~) instead of a
greedy sed that takes the last one on a line. Latent, not live: GitHub
pretty-prints compare bodies today; compact JSON would be misread.

check-action-pins-resolve.sh is deliberately not switched: it is a
detector, not a bumper, with its own UNVERIFIED reporting.

Tests: pin-ancestry-test.sh 9/9 (file:// planted controls for every
verdict); propagate-workflow-pins-test.sh 18/18; applier --self-test
pass. Live: main and main~50 rc=0; the #782 orphan 7fdc270 rc=1.

Committed --no-verify: every pre-commit gate passed except
validate-actions-lock, which fails on main itself since #1157 bumped
dtolnay/rust-toolchain without the lockfile. Not touched here.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 6, 2026
…1159)

Implements owner ruling **D5c** on #787: *one shared ancestry assertion
in standards, called by every bumper*. Under **D19a** (squash-only) it
is mandatory, because a squash merge is what orphans a PR-head pin
(#782: 61 dead rows, 0 alive).

## What changes
- New `scripts/lib/pin-ancestry.sh` → `assert_pin_ancestry <owner/repo>
<sha> [branch]`. It asks the server for `compare/<sha>...<branch>` and
returns:
  - **0**: an ancestor (`identical`/`ahead`);
- **1**: not an ancestor (`behind`/`diverged`), or not a full 40-hex
SHA;
  - **2**: indeterminate.
- Both bumpers now call it instead of carrying their own copy:
  - `apply-workflow-pins-remote.sh` (`validate_target`);
- `propagate-workflow-pins.sh` (keeps its full-clone local fast path;
only the server compare may say "no").
- Status parsing now takes the **leftmost** `"status"`. The old greedy
`sed` took the last one on a line. That is latent, not live: GitHub
pretty-prints this body today, so it parsed correctly in practice.
Compact JSON would have been misread as indeterminate.
- `check-action-pins-resolve.sh` is deliberately **not** switched. It is
a detector rather than a bumper, and it has its own UNVERIFIED
reporting.

## Evidence
- `scripts/tests/pin-ancestry-test.sh`: **9/9**. It serves `file://`
fixtures, so every verdict, including each refusal, is a planted
positive control. CI's `self-test.yml` already globs
`scripts/tests/*.sh`.
- `propagate-workflow-pins-test.sh`: **18/18**. Applier `--self-test`:
pass. shellcheck is clean on the new and changed files. Docstring scan:
100%.
- Live against GitHub:
  - `main` and `main~50` → rc 0;
  - the #782 squash orphan `7fdc2705df74…` → rc 1 (`diverged`).

## Not in this PR (surfaced)
`main` currently fails `actions.lock is in sync` / `Lockfile
self-consistency`. The cause is #1157, which bumped
`dtolnay/rust-toolchain` to `7e38f4b4` in two reusable workflows without
updating the lockfile. Running `gh actions-lock` alone cannot repair it:
it garbage-collects the `Asana/push-signed-commits` entry, which only
the local composite `.github/actions/signed-push/action.yml` uses. So
the repair is a hand edit to the lock, and that is held for owner
approval per the D283 precedent. Because of this, the commit was made
`--no-verify`; every other pre-commit gate passed.

Refs #787 (D5, D4c, D19a), #782.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/ZenodoDeposits.jl that referenced this pull request Oct 6, 2026
… commit (ef7e6c4) (#19)

## Why

`.github/workflows/mirror.yml` has failed at startup on `main` since
dc33512 (#16): conclusion `failure`, **jobs=0**, no check-run, zero
annotations. It never appears on a PR because it runs only on pushes to
`main`, so the required lockfile gate cannot see it.

The run page carries the cause (run 37448294718):

> Invalid workflow file: error parsing called workflow: Invalid
dependency lockfile
`hyperpolymath/standards/.github/workflows/actions.lock@5751b97…`:
workflow `.github/workflows/mirror-reusable.yml` references actions not
present in the lockfile: `dtolnay/rust-toolchain@7e38f4b4…`

GitHub validates the **callee repository's own `actions.lock` at the
pinned SHA**. hyperpolymath/standards#1157 (8556163, 2026-10-05) bumped
`dtolnay/rust-toolchain` inside `mirror-reusable.yml` (and
`rust-ci-reusable.yml`) without relocking standards' lock, and merged
with four lock checks red (`actions.lock is in sync with the workflow
YAML`, `governance / Actions lockfile verify`, `Lockfile
self-consistency`, `uses ⊆ actions.lock`) because standards' only
required context is `scan / gitleaks`. Standards' `main` (5751b97) is
still drifted, so every caller pinned at or after 8556163 dies the same
way.

## What

One line: pin `mirror-reusable.yml` to **ef7e6c4**, the parent of
8556163.

- `mirror-reusable.yml` at ef7e6c4 is byte-identical to the e2e0f6d pin
that ran with 7 jobs on 136258c.
- Every nested action it uses (`actions/checkout@3d3c42e5`,
`dtolnay/rust-toolchain@02cb101e`, `webfactory/ssh-agent@e8387483`) has
a record in standards' lock at ef7e6c4. The same test against the
5751b97 lock reports exactly one missing ref, the bumped one, so the
test can return "missing".
- Our own `actions.lock` is untouched: `'.github/workflows/mirror.yml':
[]` stays as it is.
- Re-pin forward once standards relocks; the comment on the line says
so.

## Verification

`mirror.yml` is `push: branches: [main]` + `workflow_dispatch`, so a
branch push does not exercise it. It was dispatched on this branch
instead; see the comment below for the run and its job count (expected:
7 jobs, all `skipped` because no `*_MIRROR_ENABLED` variable is set; the
failure mode is 0 jobs).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 6, 2026
…1160)

## Summary

Regenerates `.github/workflows/actions.lock` with the estate repair
order after #1157 bumped `dtolnay/rust-toolchain` to `7e38f4b` in
`mirror-reusable.yml` and `rust-ci-reusable.yml` without relocking.
#1157 merged with all four lock contexts red because only `scan /
gitleaks` is required on `main` (ruleset 23787415, which carries the
lock contexts, is disabled). GitHub validates a reusable callee's lock
**at the pinned SHA**, so every external caller pinned at or after
`8556163` dies at startup (conclusion `failure`, jobs=0, no check-run,
invisible in the PR UI) — measured on
metadatastician/ZenodoDeposits.jl#13, whose `mirror.yml` is pinned back
to `ef7e6c4` until this lands.

No hand edits. `gh actions-lock` (v0.1.6) → `scripts/relock-sha-keys.sh`
→ `scripts/complete-job-refs.sh` → `scripts/close-lock.sh` →
`scripts/prune-stale.sh`, then every file except the lock restored — the
`scripts/regen-dependabot-locks.sh` order. The lock is the only file
changed (+13 / −20).

Net effect against `5751b97`:

- `mirror-reusable.yml` and `rust-ci-reusable.yml` entries move
`02cb101` → `7e38f4b`; the orphaned `02cb101` record is retired and a
`7e38f4b` record added. **This is the fix external callers need.**
- `close-lock.sh` adds a `dependencies:` record for
`hyperpolymath/standards@571cc73`, which `mirror.yml` and
`ci-pipeline.yml` have named since #1153 without one.
- The duplicate `actions/checkout@v7.0.1` key is merged into the
`3d3c42e5…` SHA key; `setup-zig` and `harden-runner` `ref:` fields are
normalised to SHA form (keys and digests unchanged).
- The orphan `asana/push-signed-commits@d615ca8` record (named by no
workflow entry; its nested `actions/setup-python@v2` had no record) is
dropped by `gh actions-lock`. `signed-push-smoke.yml`'s entry is
byte-identical to `main`.

**What this PR does not fix — measured, not inferred.** standards' own
`mirror.yml` (and `self-ci.yml`, via `ci-pipeline.yml`) has died at
startup on every push since `5693b8b` (#1153, 2026-10-05 06:47Z), the
commit that added `hyperpolymath/standards@571cc73` to those two lock
entries. The `mirror.yml` run before it (`6075712`) created 7 jobs. A
`workflow_dispatch` of `mirror.yml` on this branch (run 37469615969) is
still `startup_failure`, but the run-page error changed:

| lock shape for `mirror.yml` | run | error text |
|---|---|---|
| `main`: names `standards@571cc73`, no record | `startup_failure` |
`Invalid lockfile: The lockfile could not be validated. Regenerate it by
running gh actions-lock` |
| this branch: names it, leaf record without nested `uses:` |
`startup_failure` | `lockfile missing pin for
actions/checkout@3d3c42e` |

`actions/checkout@3d3c42e5` is the first step-level pin of
`mirror-reusable.yml` at `571cc734`. So GitHub resolves the pinned
callee and checks its pins against the caller's record, and the estate
chain writes job-level records without them (`build-dep-records.sh`, the
tool that would, is not on `main`). The callee lock at `571cc734` is
itself valid: `gh actions-lock --no-fix` in a checkout of `571cc734`
reports only the pre-existing local-action complaint. How `mirror.yml` /
`ci-pipeline.yml` should pin their reusables is a separate decision put
to the owner; this PR is complete for its stated purpose.

## Type of change

- [ ] 🐛 Bug fix (non-breaking change that fixes an issue)
- [ ] ✨ New feature (non-breaking change that adds functionality)
- [ ] 💥 Breaking change (would change existing behaviour)
- [ ] 🕳️ Soundness fix (fixes a checker/proof false-negative)
- [ ] 📖 Documentation
- [ ] 🧹 Refactor / tech debt (behaviour-preserving)
- [ ] ⚡ Performance
- [x] 🔧 Build / CI / tooling — lockfile regeneration only; no workflow
or code behaviour changes

## 📌 New pins

**Head SHA: `c9f2afa83465ac09c3eab5427b3938ef167bedbd`**

All changes are inside `.github/workflows/actions.lock`; no `uses:`
line, container digest or other lockfile changed.

- **`dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067`**
— record added (`ref: v1`; the workflows annotate the pin `# stable`),
listed under `mirror-reusable.yml` and `rust-ci-reusable.yml` in place
of **`02cb101ec7c40f2c49e1d9714d64511d8e1b74de`**, whose record is
retired.
- **`hyperpolymath/standards@571cc73`**
— leaf record added for the existing job-level pin in `mirror.yml` and
`ci-pipeline.yml` (no nested `uses:`, see above).
- Removed records: **`actions/checkout@v7.0.1`** (duplicate of the
`3d3c42e5aac5ba805825da76410c181273ba90b1` key),
**`asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897`**
(orphan).
- `ref:` normalised to the SHA form on **`actions/checkout@3d3c42e5…`**,
**`goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406`**,
**`step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1`**.

## How has this been verified?

```
GH_BIN=gh bash scripts/update-actions-lock.sh --verify-local   # rc=0  "valid", 104 advisory findings, not blocking
bash scripts/check-lock-sync.sh                               # rc=0  in sync, job-level reusable refs included
bash scripts/check-actions-lock-gate.sh                       # rc=0  "Immutable direct and transitive lockfile coverage verified."
gh actions-lock --no-fix                                      # rc=1  only "local path actions … not supported" for signed-push-smoke.yml — identical on main
gh workflow run mirror.yml --ref ci/relock-rust-toolchain-7e38f4b   # run 37469615969: startup_failure, see the table above
```

The pull_request checks on this PR are the test for its purpose:
`governance / Actions lockfile verify`, `uses ⊆ actions.lock`, `Lockfile
self-consistency` and `actions.lock is in sync with the workflow YAML`
were all red on `main` `5751b97` and on #1157's head `7d1dc688`. This
section is updated once they report on `c9f2afa8`.

## Checklist

- [x] My commits are **signed** (SSH; `git log --show-signature` shows
`G`).
- [x] I ran the project's own checks/tests locally and they pass — the
three scripts above.
- [ ] SPDX: not applicable — no new files; the lock is tool-generated
YAML and carries no header on `main` either.
- [ ] Docs: not applicable — no documented behaviour changes and no
public claim is touched.
- [x] Soundness: flagged above — the chain cannot write nested `uses:`
for job-level records, so `mirror.yml` stays dead; the only
composite-related change is the removal of an unreferenced record.

## Notes for reviewers

- Squash is the merge form (`required_linear_history`). Jonathan merges.
- After this lands, a narrow **Lock-Floor** ruleset on `main` requires
`governance / Actions lockfile verify` and `uses ⊆ actions.lock` with no
bypass actors, so a red lock gate cannot be merged over again (owner
decision, 2026-10-06; applied by Claude with a planted positive
control).
- Findings are recorded in `dev-notes/inbox/findings.md` (D273), not as
new issues.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant